René Mayrhofer

dblp:34/4020 · also Rene Mayrhofer · DBLP profile ↗
← Back
59ranked-venue papers
11as first author
17since 2021 · last 2026
0000-0003-1566-4646ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 17 · 4 first-author · 11 since 2021Computer networks · 8 · 2 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 5 · 2 first-authorDatabases, data management, data science and information retrieval · 4 · 2 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 first-author · 1 since 2021Systems, architecture and hardware · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 2Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Firmware Transparency: Strengthening Security Guarantees Against Bootloader-Targeting Attacks
Mario Lins, René Mayrhofer, David Zeuthen
ACNS (3)2
2026 Investigating Developers' Usage and Perception of Trusted Execution Environment Features in Android
Abdullah Imran, Güliz Seray Tuncay, René Mayrhofer, Antonio Bianchi
EuroS&P3
2025 Unveiling the Critical Attack Path for Implanting Backdoors in Supply Chains: Practical Experience from XZ
Mario Lins, René Mayrhofer, Michael Roland 0001
CANS2
2025 Attestable Builds: Compiling Verifiable Binaries on Untrusted Systems using Trusted Execution Environments
abstract
In this paper we present attestable builds, a new paradigm to provide strong source-to-binary correspondence in software artifacts. We tackle the challenge of opaque build pipelines that disconnect the trust between source code, which can be understood and audited, and the final binary artifact which is difficult to inspect. Our system uses modern trusted execution environments (TEEs) and sandboxed build containers to provide strong guarantees that a given artifact was correctly built from a specific source code snapshot. As such it complements existing approaches like reproducible builds which typically require time-intensive modifications to existing build configurations and dependencies, and require independent parties to continuously build and verify artifacts. In comparison, an attestable build requires only minimal changes to an existing project, and offers nearly instantaneous verification of the correspondence between a given binary and the source code and build pipeline used to construct it. We evaluate it by building open-source software libraries - focusing on projects which are important to the trust chain and have proven difficult to be built deterministically. The overhead (42 seconds start-up latency and 14% increase in build duration) is small in comparison to the overall build time. Importantly, our prototype can build complex projects such as LLVM Clang without requiring any modifications to their source code and build scripts. Finally, we formally model and verify the attestable build design to demonstrate its security against well-resourced adversaries.
Daniel Hugenroth, Mario Lins, René Mayrhofer, Alastair R. Beresford
CCS3
2024 BioDSSL: A Domain Specific Sensor Language for Global, Distributed, Biometric Identification Systems
abstract
With biometric identification systems becoming increasingly ubiquitous, their complexity is escalating due to the integration of diverse sensors and modalities, aimed at minimizing error rates. The current paradigm for these systems involves hard-coded aggregation instructions, presenting challenges in system maintenance, scalability, and adaptability. These challenges become particularly prominent when deploying new sensors or adjusting security levels to respond to evolving threat models. To address these concerns, this research introduces BioDSSL, a Domain Specific Sensor Language to simplify the integration and dynamic adjustment of security levels in biometric identification systems. Designed to address the increasing complexity due to diverse sensors and modalities, BioDSSL promotes system maintainability and resilience while ensuring a balance between usability and security for specific scenarios. Furthermore, it facilitates decentralization of biometric identification systems, by improving interoperability and abstraction. Decentralization inherently disperses the concentration of sensitive biometric data across various nodes, which could indirectly enhance privacy protection and limit the potential damage from localized security breaches. Therefore, BioDSSL is not just a technical improvement, but a step towards decentralized, resilient, and more secure biometric identification systems. This approach holds the promise of indirectly improving privacy while enhancing the reliability and adaptability of these systems amidst evolving threat landscapes and technological advancements.
Philipp Hofer 0003, Michael Roland 0001, René Mayrhofer
IS3
2024 Honeyquest: Rapidly Measuring the Enticingness of Cyber Deception Techniques with Code-based Questionnaires
abstract
Fooling adversaries with traps such as honeytokens can slow down cyber attacks and create strong indicators of compromise. Unfortunately, cyber deception techniques are often poorly specified. Also, realistically measuring their effectiveness requires a well-exposed software system together with a production-ready implementation of these techniques. This makes rapid prototyping challenging. Our work translates 13 previously researched and 12 self-defined techniques into a high-level, machine-readable specification. Our open-source tool, Honeyquest, allows researchers to quickly evaluate the enticingness of deception techniques without implementing them. We test the enticingness of 25 cyber deception techniques and 19 true security risks in an experiment with 47 humans. We successfully replicate the goals of previous work with many consistent findings, but without a time-consuming implementation of these techniques on real computer systems. We provide valuable insights for the design of enticing deception and also show that the presence of cyber deception can significantly reduce the risk that adversaries will find a true security risk by about 22% on average.
Mario Kahlhofer, Stefan Achleitner, Stefan Rass, René Mayrhofer
RAID4
2024 Threshold Delegatable Anonymous Credentials With Controlled and Fine-Grained Delegation
abstract
Anonymous credential systems allow users to obtain a credential on multiple attributes from an organization and then present it to verifiers in a way that no information beyond what attributes are required to be shown is revealed. Moreover, multiple uses of the credential cannot be linked. Thus they represent an attractive tool to realize fine-grained privacy-friendly authentication and access control. In order to avoid a single point of trust and failure, decentralized AC systems have been proposed. They eliminate the need for a trusted credential issuer, e.g., by relying on a set of credential issuers that issue credentials in a threshold manner (e.g.,$t$out of$n$f). In this paper, we present a novel AC system with such a threshold issuance that additionally provides credential delegation. It represents the first decentralizedanddelegatable AC system. We provide a rigorous formal framework for such threshold delegatable anonymous credentials ($\mathsf {TDAC}$'s). Our concrete approach departs from previous delegatable ACs and is inspired by the concept of functional credentials. More precisely, we propose a threshold delegatable subset predicate encryption ($\mathsf {TDSPE}$) scheme and use$\mathsf {TDSPE}$to construct a$\mathsf {TDAC}$scheme and present a comparison with previous work and performance benchmarks based on a prototype implementation.
Omid Mir, Daniel Slamanig, René Mayrhofer
IEEE Trans. Dependable Secur. Comput.3
2023 Efficient Aggregation of Face Embeddings for Decentralized Face Recognition Deployments
Philipp Hofer 0003, Michael Roland 0001, Philipp Schwarz, René Mayrhofer
ICISSP4
2023 Face to Face with Efficiency: Real-Time Face Recognition Pipelines on Embedded Devices
Philipp Hofer 0003, Michael Roland 0001, Philipp Schwarz, René Mayrhofer
MoMM4
2023 Anonymously Publishing Liveness Signals with Plausible Deniability
Michael Sonntag, René Mayrhofer, Stefan Rass
MoMM2
2023 A Survey on Fingerprinting Technologies for Smartphones Based on Embedded Transducers
abstract
Smartphones are a vital technology, they improve our social interactions, provide us a great deal of information and bring forth the means to control various emerging technologies, like the numerous IoT devices that are controlled via smartphone apps. In this context, smartphone fingerprinting from sensor characteristics is a topic of high interest not only due to privacy implications or potential use in forensics investigations, but also because of various applications in device authentication. In this work we review existing approaches for smartphone fingerprinting based on internal components, focusing mostly on camera sensors, microphones, loudspeakers and accelerometers. Other sensors, i.e., gyroscopes and magnetometers, are also accounted, but they correspond to a smaller body of works. The output of these transducers, which convert one type of energy into another, e.g., mechanical into electrical, leaks through various channels such as mobile apps and cloud services, while there is little user awareness on the privacy risks. Needless to say, miniature physical imperfections from the manufacturing process make each such transducer unique. One of the main intentions of our study is to rank these sensors according to the accuracy they provide in identifying smartphones and to give a clear overview on the amount of research that each of these components triggered so far. We review the features which can be extracted from each type of data and the classification algorithms that have been used. Last but not least, we also point out publicly available datasets which can serve for future investigations.
Adriana Berdich, Bogdan Groza, René Mayrhofer
IEEE Internet Things J.3
2023 Practical Delegatable Anonymous Credentials From Equivalence Class Signatures
abstract
Anonymous credentials (ACs) systems are a powerful cryptographic tool for privacy-preserving applications and provide strong user privacy guarantees for authentication and access control. ACs allow users to prove possession of attributes encoded in a credential without revealing any information beyond them. A delegatable AC (DAC) system is an enhanced AC system that allows the owners of credentials to delegate the obtained credential to other users. This allows to model hierarchies as usually encountered within public-key infrastructures (PKIs). DACs also provide stronger privacy guarantees than traditional AC systems since the identities of issuers and delegators can also be hidden. In this paper we present a novel DAC scheme that supports attributes, provides anonymity for delegations, allows the delegators to restrict further delegations, and also comes with an efficient construction. Our approach builds on a new primitive that we call structure-preserving signatures on equivalence classes on updatable commitments (SPSEQ-UC). The high-level idea is to use a special signature scheme that can sign vectors of set commitments, where signatures can be extended by additional set commitments. Signatures additionally include a user's public key, which can be switched. This allows us to efficiently realize delegation in the DAC. Similar to conventional SPSEQ, the signatures and messages can be publicly randomized and thus allow unlinkable delegation and showings in the DAC system. We present further optimizations such as cross-set commitment aggregation that, in combination, enable efficient selective showing of attributes in the DAC without using costly zero-knowledge proofs. We present an efficient instantiation that is proven to be secure in the generic group model and finally demonstrate the practical efficiency of our DAC by presenting performance benchmarks based on an implementation.
Omid Mir, Daniel Slamanig, Balthazar Bauer, René Mayrhofer
Proc. Priv. Enhancing Technol.4
2023 Sweep-to-Unlock: Fingerprinting Smartphones Based on Loudspeaker Roll-Off Characteristics
abstract
Fingerprinting smartphones based on acoustic characteristics of their loudspeaker may have a number of applications in device-to-device authentication as well as in forensic investigations. In this work we propose an efficient fingerprinting methodology by using the roll-off characteristics of the device speaker, i.e., the transition between the low and high stopbands to the passband segment of the speaker. We extract roll-off characteristics from sweep signals, also know as chirps, that are commonly used in practice to test speaker response. This procedure appears to be more stable against variations of the volume level and allows the use of simple linear approximations, which are intuitive and easy to compute, in order to extract the fingerprint. To increase detection accuracy, on the basis of the proven performance of deep learning techniques, a convolutional and a bi-directional long short term memory neural network are further proposed and their performance demonstrated for authentication purposes. While numerous applications may be envisioned, we specifically focus on the use of speaker characteristics in relation to in-vehicle infotainment units, checking if recordings from these units can be used to fingerprint a specific phone.
Adriana Berdich, Bogdan Groza, René Mayrhofer, Efrat Levy, Asaf Shabtai, Yuval Elovici
IEEE Trans. Mob. Comput.3
2022 Decentralized, Privacy-Preserving, Single Sign-On
abstract
In current single sign-on authentication schemes on the web, users are required to interact with identity providers securely to set up authentication data during a registration phase and receive a token (credential) for future access to services and applications. This type of interaction can make authentication schemes challenging in terms of security and availability. From a security perspective, a main threat is theft of authentication reference data stored with identity providers. An adversary could easily abuse such data to mount an offline dictionary attack for obtaining the underlying password or biometric. From a privacy perspective, identity providers are able to track user activity and control sensitive user data. In terms of availability, users rely on trusted third-party servers that need to be available during authentication. We propose a novel decentralized privacy-preserving single sign-on scheme through the Decentralized Anonymous Multi-Factor Authentication (DAMFA), a new authentication scheme where identity providers no longer require sensitive user data and can no longer track individual user activity. Moreover, our protocol eliminates dependence on an always-on identity provider during user authentication, allowing service providers to authenticate users at any time without interacting with the identity provider. Our approach builds on threshold oblivious pseudorandom functions (TOPRF) to improve resistance against offline attacks and uses a distributed transaction ledger to improve availability. We prove the security of DAMFA in the universal composibility (UC) model by defining a UC definition (ideal functionality) for DAMFA and formally proving the security of our scheme via ideal-real simulation. Finally, we demonstrate the practicability of our proposed scheme through a prototype implementation.
Omid Mir, Michael Roland 0001, René Mayrhofer
Secur. Commun. Networks3
2021 Experiences and Recommendations from Operating a Tor Exit Node at a University
Michael Sonntag, René Mayrhofer
ICISSP2
2021 Analyzing inconsistencies in the Tor consensus
abstract
Every distributed system needs some way to list its current participants. The Tor networks consensus is one way of tackling this challenge. But creating a shared list of participants and their properties without a central authority is a challenging task, especially if the system is constantly targeted by nation state attackers. This work carefully examines the Tor consensuses created in the last two years, identifies weaknesses that did already impact users, and proposes improvements to strengthen the Tor consensus in the future. Our results show undocumented voting behavior by directory authorities and suspicious groups of relays that try to conceal the fact that they are all operated by the same entity.
Tobias Höller, Michael Roland 0001, René Mayrhofer
iiWAS3
2021 The Android Platform Security Model
abstract
Android is the most widely deployed end-user focused operating system. With its growing set of use cases encompassing communication, navigation, media consumption, entertainment, finance, health, and access to sensors, actuators, cameras, or microphones, its underlying security model needs to address a host of practical threats in a wide variety of scenarios while being useful to non-security experts. The model needs to strike a difficult balance between security, privacy, and usability for end users, assurances for app developers, and system performance under tight hardware constraints. While many of the underlying design principles have implicitly informed the overall system architecture, access control mechanisms, and mitigation techniques, the Android security model has previously not been formally published. This article aims to both document the abstract model and discuss its implications. Based on a definition of the threat model and Android ecosystem context in which it operates, we analyze how the different security measures in past and current Android implementations work together to mitigate these threats. There are some special cases in applying the security model, and we discuss such deliberate deviations from the abstract model.
René Mayrhofer, Jeffrey Vander Stoep, Chad Brubaker, Nick Kralevich
ACM Trans. Priv. Secur.1
2019 CORMORANT: On Implementing Risk-Aware Multi-Modal Biometric Cross-Device Authentication For Android
abstract
This paper presents the design and open source implementation of Cormorant, an Android authentication framework able to increase usability and security of mobile authentication. It uses transparent behavioral and physiological biometrics like gait, face, voice, and keystrokes dynamics to continuously evaluate the user's identity without explicit interaction. Using signals like location, time of day, and nearby devices to assess the risk of unauthorized access, the required level of confidence in the user's identity is dynamically adjusted. Authentication results are shared securely, end-to-end encrypted using the Signal messaging protocol, with trusted devices to facilitate cross-device authentication for co-located devices, detected using Bluetooth low energy beacons. Cormorant is able to reduce the authentication overhead by up to 97% compared to conventional knowledge-based authentication whilst increasing security at the same time. We share our perspective on some of the successes and shortcomings we encountered implementing and evaluating Cormorant to hope to inform others working on similar projects.
Daniel Hintze, Matthias Füller, Sebastian Scholz, Rainhard Dieter Findling, Muhammad Muaaz, Philipp Kapfer, Wilhelm Nüßer, René Mayrhofer
MoMM8
2019 KinPhy: a kinetic in-band channel for millimetre-wave networks
abstract
We propose a system for enabling auxiliary communication channels in which a node transmits a millimeter (mm) wave signal which is reflected off a deliberately vibrating surface of a second node and then received by the first node. Data sequences can be encoded in the modulation of the surface, and radar sensing techniques can be used to demodulate the reflected signal. Hence our system enables not only conventional sensing in terms of range, velocity, and orientation estimation but also allows for information to be conveyed by the sensed device. We introduce the design of a metasurface driven by an energy-efficient programmable piezo-electric actuator, detail suitable radar processing, and characterize the link performance of the kinetically induced channel at distances up to five meters. As this metasurface could be used for both mobile devices and infrastructure devices, we describe opportunities for enabling novel capabilities including secure device authentication and extended-range wireless sensing across multiple devices.
Mohammed Alloulah, Zoran Radivojevic, René Mayrhofer, Howard Huang
SenSys3
2018 Recovery of Encrypted Mobile Device Backups from Partially Trusted Cloud Servers
abstract
Including electronic identities (eIDs), such as passports or driving licenses in smartphones transforms them into a single point of failure: loss, theft, or malfunction would prevent their users even from identifying themselves e.g. during travel. Therefore, a secure backup of such identity data is paramount, and an obvious solution is to store encrypted backups on cloud servers. However, the critical challenge is how a user decrypts the encrypted data backup if the user's device gets lost or stolen and there is no longer a secure storage (e.g. smartphone) to keep the secret key. To address this issue, Password-Protected Secret Sharing (PPSS) schemes have been proposed which allow a user to store a secret key among n servers such that the user can later reconstruct the secret key. Unfortunately, PPSS schemes are not appropriate for some applications. For example, users will be highly unlikely to remember a cryptographically strong password when the smartphone is lost. Also, they still suffer from inefficiency. In this paper, we propose a new secret key reconstruction protocol based recently popular PPSS schemes with a Fuzzy Extractor which allows a client to recover secret keys from an only partially trusted server and an auxiliary device using multiple key shares and a biometric identifier. We prove the security of our proposed protocol in the random oracle model where the parties can be corrupted separately at any time. An initial performance analysis shows that it is efficient for this use case.
Omid Mir, René Mayrhofer, Michael Hölzl
ARES2
2018 Sulong, and Thanks for All the Bugs: Finding Errors in C Programs by Abstracting from the Native Execution Model
abstract
In C, memory errors, such as buffer overflows, are among the most dangerous software errors; as we show, they are still on the rise. Current dynamic bug-finding tools that try to detect such errors are based on the low-level execution model of the underlying machine. They insert additional checks in an ad-hoc fashion, which makes them prone to omitting checks for corner cases. To address this, we devised a novel approach to finding bugs during the execution of a program. At the core of this approach is an interpreter written in a high-level language that performs automatic checks (such as bounds, NULL, and type checks). By mapping data structures in C to those of the high-level language, accesses are automatically checked and bugs discovered. We have implemented this approach and show that our tool (called Safe Sulong) can find bugs that state-of-the-art tools overlook, such as out-of-bounds accesses to the main function arguments.
Manuel Rigger, Roland Schatz, René Mayrhofer, Matthias Grimmer, Hanspeter Mössenböck
ASPLOS3
2018 Mobile Match-on-Card Authentication Using Offline-Simplified Models with Gait and Face Biometrics
abstract
Biometrics have become important for mobile authentication, e.g., to unlock devices before using them. One way to protect biometric information stored on mobile devices from disclosure is using embedded smart cards (SCs) with biometric match-on-card (MOC) approaches. However, computational restrictions of SCs also limit biometric matching procedures. We present a mobile MOC approach that uses offline training to obtain authentication models with a simplistic internal representation in the final trained state, where we adapt features and model representation to enable their usage on SCs. The pre-trained model can be shipped with SCs on mobile devices without requiring retraining to enroll users. We apply our approach to acceleration based mobile gait authentication as well as face authentication and compare authentication accuracy and computation time of 16 and 32 bit Java Card SCs. Using 16 instead of 32 bit SCs has little impact on authentication performance and is faster due to less data transfer and computations on the SC. Results indicate 11.4 and 2.4-5.4 percent EER for gait respectively face authentication, with transmission and computation durations on SCs in the range of 2 s respectively 1 s. To the best of our knowledge, this work represents the first practical approach towards acceleration based gait MOC authentication.
Rainhard Dieter Findling, Michael Hölzl, René Mayrhofer
IEEE Trans. Mob. Comput.3
2017 Traffic Statistics of a High-Bandwidth Tor Exit Node
Michael Sonntag, René Mayrhofer
ICISSP2
2017 ShakeUnlock: Securely Transfer Authentication States Between Mobile Devices
abstract
As users start carrying multiple mobile devices, we propose a novel, token based mobile device unlocking approach. Mobile devices are conjointly shaken to transfer the authentication state from an unlocked token device to another device to unlock it. A common use case features a wrist watch as token device, which remains unlocked as long as it is strapped to the user's wrist, and a locked mobile phone, which is unlocked if both devices are shaken conjointly. Shaking can be done single-handedly, requires little user attention (users don't have to look at the device for unlocking it), and does not cause additional cognitive load on users. In case attackers gain control over the locked phone, forging shaking is difficult, which impedes malicious unlocks. We evaluate our approach using acceleration records from our 29 people sized ShakeUnlock database and discuss influence of its constituent parts on the system performance. We further present a performance study using an Android implementation and live data, which shows the true negative rate of observational attacks to be in the range of 0.8-if an attacker manages to gain control over the locked device and shake it in parallel to the device owner shaking the token device.
Rainhard Dieter Findling, Muhammad Muaaz, Daniel Hintze, René Mayrhofer
IEEE Trans. Mob. Comput.4
2017 Smartphone-Based Gait Recognition: From Authentication to Imitation
abstract
This work evaluates the security strength of a smartphone-based gait recognition system against zero-effort and live minimal-effort impersonation attacks under realistic scenarios. For this purpose, we developed an Android application, which uses a smartphone-based accelerometer to capture gait data continuously in the background, but only when an individual walks. Later, it analyzes the recorded gait data and establishes the identity of an individual. At first, we tested the performance of this system against zero-effort attacks by using a dataset of 35 participants. Later, live impersonation attacks were performed by five professional actors who are specialized in mimicking body movements and body language. These attackers were paired with their physiologically close victims, and they were given live audio and visual feedback about their latest impersonation attempt during the whole experiment. No false positives under impersonation attacks, indicate that mimicry does not improve chances of attackers being accepted by our gait authentication system. In 29 percent of total impersonation attempts, when attackers walked like their chosen victim, they lost regularity between their steps which makes impersonation even harder for attackers.
Muhammad Muaaz, René Mayrhofer
IEEE Trans. Mob. Comput.2
2016 Mobile Gait Match-on-Card Authentication from Acceleration Data with Offline-Simplified Models
Rainhard Dieter Findling, Michael Hölzl, René Mayrhofer
MoMM3
2016 Real-World Identification: Towards a Privacy-Aware Mobile eID for Physical and Offline Verification
Michael Hölzl, Michael Roland 0001, René Mayrhofer
MoMM3
2016 Accelerometer based Gait Recognition using Adapted Gaussian Mixture Models
Muhammad Muaaz, René Mayrhofer
MoMM2
2016 DAMN: A Debugging and Manipulation Tool for Android Applications
Gerald Schoiber, René Mayrhofer, Michael Hölzl
MoMM2
2015 Confidence and Risk Estimation Plugins for Multi-Modal Authentication on Mobile Devices using CORMORANT
abstract
Mobile devices, ubiquitous in modern lifestyle, embody and provide convenient access to our digital lives. Being small and mobile, they are easily lost or stole, therefore require strong authentication to mitigate the risk of unauthorized access. Common knowledge-based mechanism like PIN or pattern, however, fail to scale with the high frequency but short duration of device interactions and ever increasing number of mobile devices carried simultaneously. To overcome these limitations, we present CORMORANT, an extensible framework for risk-aware multi-modal biometric authentication across multiple mobile devices that offers increased security and requires less user interaction.
Daniel Hintze, Muhammad Muaaz, Rainhard Dieter Findling, Sebastian Scholz, Eckhard Koch 0001, René Mayrhofer
MoMM6
2015 Towards device-to-user authentication: protecting against phishing hardware by ensuring mobile device authenticity using vibration patterns
abstract
Users usually authenticate to mobile devices before using them (e.g. PIN, password), but devices do not do the same to users. Revealing the authentication secret to a non-authenticated device potentially enables attackers to obtain the secret, by replacing the device with an identical-looking malicious device. The revealed authentication secret could be transmitted to the attackers immediately, who then conveniently authenticate to the real device. Addressing this attack scenario, we analyze different approaches towards mobile device-to-user (D2U) authentication, for which we provide an overview of advantages/drawbacks, potential risks and device authentication data bandwidth estimations. We further analyze vibration as one D2U feedback channel that is unobtrusive and hard to eavesdrop, including a user study to estimate vibration pattern recognition using a setup of ~7 bits per second (b/s). Study findings indicate that users are able to distinguish vibration patterns with median correctness of 97.5% (without taking training effects into account) -- which indicates that vibration could act as authentication feedback channel and should be investigated further in future research.
Rainhard Dieter Findling, René Mayrhofer
MUM2
2015 Only play in your comfort zone: interaction methods for improving security awareness on mobile devices
Peter Riedl, René Mayrhofer, Andreas Möller, Matthias Kranz, Florian Lettner, Clemens Holzmann, Marion Koelle
Pers. Ubiquitous Comput.2
2015 An architecture for secure mobile devices
abstract
Abstract Mobile devices such as smart phones have become one of the preferred means of accessing digital services, both for consuming and creating content. Unfortunately, securing such mobile devices is inherently difficult for a number of reasons. In this article, we review recent research results, systematically analyze the technical issues of securing mobile device platforms against different threats, and discuss a resulting and currently unsolved problem: How to create an end‐to‐end secure channel between the digital service (e.g., a secure wallet application on an embedded smart card or an infrastructure service connected over wireless media) and the user. Although the problem has been known for years and technical approaches start appearing in products, the user interaction aspects have remained unsolved. We discuss the reasons for this difficulty and suggest potential approaches to create human‐verifiable secure communication with components or services within partially untrusted devices. Copyright © 2014 John Wiley & Sons, Ltd.
René Mayrhofer
Secur. Commun. Networks1
2014 Optimal Derotation of Shared Acceleration Time Series by Determining Relative Spatial Alignment
abstract
Detecting if two or multiple devices are moved together is an interesting problem for different applications. However, these devices may be aligned arbitrarily with regards to each other, and the three dimensions sampled by their respective local accelerometers can therefore not be directly compared. The typical approach is to ignore all angular components and only compare overall acceleration magnitudes --- with the obvious disadvantage of discarding potentially useful information. In this paper, we contribute a method to analytically determine relative spatial alignment of two devices based on their acceleration time series. Our method uses quaternions to compute the optimal rotation with regards to minimizing the mean squared error. The implication is that the reference system of one device can be (locally and independently) aligned with the other, and thus that all three dimensions can consequently be compared for more accurate classification. Based on real-world experimental data from smart phones and smart watches shaken together, we demonstrate the effectiveness of our method with a magnitude squared coherence metric, for which we show an improved EER of 0.16 (when using derotation) over an EER of 0.18 (when not using derotation).
René Mayrhofer, Helmut Hlavacs, Rainhard Dieter Findling
iiWAS1
2014 A Practical Hardware-Assisted Approach to Customize Trusted Boot for Mobile Devices
Javier González 0006, Michael Hölzl, Peter Riedl, Philippe Bonnet, René Mayrhofer
ISC5
2014 ShakeUnlock: Securely Unlock Mobile Devices by Shaking them Together
abstract
The inherent weakness of typical mobile device unlocking approaches (PIN, password, graphic pattern) is that they demand time and attention, leading a majority of end users to disable them, effectively lowering device security.
Rainhard Dieter Findling, Muhammad Muaaz, Daniel Hintze, René Mayrhofer
MoMM4
2014 Mobile Device Usage Characteristics: The Effect of Context and Form Factor on Locked and Unlocked Usage
abstract
Smartphones and tablets are an indispensable part of modern communication and people spend considerable time interacting with their devices every day. While substantial research has been conducted concerning smartphone usage, little is known about how tablets are used. This paper studies mobile device usage characteristics like session length, interaction frequency, and daily usage in locked and unlocked state with respect to location context. Based on logs from 1,585 Android devices (470 years of total usage time), we derive and analyze 23 million usage sessions. We found that devices remain locked for 60% of the interactions and usage at home occurs twice as frequent as at work. With an average of 58 interactions per day, smartphones are used twice as often as tablets, while tablet sessions are 2.5 times longer, resulting in almost equal aggregated daily usage. We conclude that usage session characteristics differ considerably between tablets and smartphones.
Daniel Hintze, Rainhard Dieter Findling, Sebastian Scholz, René Mayrhofer
MoMM4
2014 Mobile Application to Java Card Applet Communication using a Password-authenticated Secure Channel
abstract
With the increasing popularity of security and privacy sensitive systems on mobile devices, such as mobile banking, mobile credit cards, mobile ticketing, or mobile digital identities, challenges for the protection of personal and security sensitive data of these use cases emerged. A common approach for the protection of sensitive data is to use additional hardware such as smart cards or secure elements. The communication between such dedicated hardware and back-end management systems uses strong cryptography. However, the data transfer between applications on the mobile device and so-called applets on the dedicated hardware is often either unencrypted (and interceptable by malicious software) or encrypted with static keys stored in applications. To address this issue we present a solution for fine-grained secure application-to-applet communication based on Secure Remote Password (SRP-6a), an authenticated key agreement protocol, with a user-provided password at run-time. By exploiting the Java Card cryptographic API and minor adaptations to the protocol, which do not affect the security, we were able to implement this scheme on Java Cards with reasonable computation time.
Michael Hölzl, Endalkachew Asnake, René Mayrhofer, Michael Roland 0001
MoMM3
2014 Orientation Independent Cell Phone Based Gait Authentication
abstract
Gait authentication using a cell phone based accelerometer sensor offers an unobtrusive, user-friendly, and periodic way of authenticating individuals on their cell phones. In this study, we present an approach to deal with inevitable errors induced by continuously changing sensor orientation and other noise under a realistic scenario (when the phone is placed inside the trouser pockets and the user is walking) by using the magnitude data of tri-axes accelerometer and wavelet based noise elimination modules. This study utilizes a gait data set of 35 participants collected at their respective normal walking pace in two different sessions with an average gap of 25 days between the sessions.
Muhammad Muaaz, René Mayrhofer
MoMM2
2014 Security and trust in context-aware applications
René Mayrhofer, Hedda R. Schmidtke, Stephan Sigg
Pers. Ubiquitous Comput.1
2013 Range Face Segmentation: Face Detection and Segmentation for Authentication in Mobile Device Range Images
abstract
Face detection (finding faces of different perspectives in images) is an important task as prerequisite to face recognition. This is especially difficult in the mobile domain, as bad image quality and illumination conditions lead to overall reduced face detection rates. Background information still present in segmented faces and unequally normalized faces further decrease face recognition rates. We present a novel approach to robust single upright face detection and segmentation from different perspectives based on range information (pixel values corresponding to the camera-object distance). We use range template matching for finding the face's coarse position and gradient vector flow (GVF) snakes for precisely segmenting faces. We further evaluate our approach on range faces from the u'smile face database, then perform face recognition using the segmented faces to evaluate and compare our approach with previous research. Results indicate that range template matching might be a good approach to finding a single face; in our tests we achieved an error free detection rate and average recognition rates above 98%/96% for color/range images.
Rainhard Dieter Findling, Fabian Wenny, Clemens Holzmann, René Mayrhofer
MoMM4
2013 Requirements for an Open Ecosystem for Embedded Tamper Resistant Hardware on Mobile Devices
abstract
Insufficient security and privacy on mobile devices have made it difficult to utilize sensitive systems like mobile banking, mobile credit cards, mobile ticketing or mobile passports. Solving these challenges in security and privacy, could result in better mobility and a higher level of confidence for the end-user services in such systems. Our approach for a higher security and privacy level on mobile devices introduces an open ecosystem for tamper resistant hardware. Big advantages of these modules are the protection against unauthorized access and the on-device cryptographic operations they can perform. In this paper, we analyse the requirements and performance restrictions of these hardware modules and present an interface concept for a tight integration of their security features.
Michael Hölzl, René Mayrhofer, Michael Roland 0001
MoMM2
2013 An Analysis of Different Approaches to Gait Recognition Using Cell Phone Based Accelerometers
abstract
Biometric gait authentication using Personal Mobile Device (PMD) based accelerometer sensors offers a user-friendly, unobtrusive, and periodic way of authenticating individuals on PMD. In this paper, we present a technique for gait cycle extraction by incorporating the Piecewise Linear Approximation (PLA) technique. We also present two new approaches to classify gait features extracted from the cycle-based segmentation by using Support Vector Machines (SVMs); a) pre-computed data matrix, b) pre-computed kernel matrix. In the first approach, we used Dynamic Time Warping (DTW) distance to compute data matrices, and in the later DTW is used for constructing an elastic similarity measure based kernel function called Gaussian Dynamic Time Warp (GDTW) kernel. Both approaches utilize the DTW similarity measure and can be used for classifying equal length gait cycles, as well as different length gait cycles. To evaluate our approaches we used normal walk biometric gait data of 51 participants. This gait data is collected by attaching a PMD to the belt around the waist, on the right-hand side of the hip. Results show that these new approaches need to be studied more, and potentially lead us to design more robust and reliable gait authentication systems using PMD based accelerometer sensor.
Muhammad Muaaz, René Mayrhofer
MoMM2
2013 Visualizations and Switching Mechanisms for Security Zones
abstract
The ongoing evolution of mobile phones to "pocket computers" generated a demand for more and more applications to be ported to the mobile phone. Because a full security assessment for a whole mobile operating system would be prohibitively costly, currently security critical applications can not be implemented. We address this challenge by introducing security zones to enable applications with high security demands like driving licenses, health insurance cards, or passports on mobile phones. This zone concept creates the need for visualization of the current zone and a way to switch between zones. In this paper we discuss several possible ways of achieving this.
Peter Riedl, Phillip Koller, René Mayrhofer, Andreas Möller, Marion Koelle, Matthias Kranz
MoMM3
2013 (Ab)using foreign VMs: Running Java Card Applets in non-Java Card Virtual Machines
abstract
Creating Java Card applications for Near Field Communication's card emulation mode requires access to a secure smartcard chip (the secure element). Today, even for development purposes, it is difficult to get access to the secure element in most current smart phones. Therefore, it would be useful to have an environment that emulates a secure element for rapid prototyping and debugging. Our approach to such an environment is emulation of Java Card applets on top of non-Java Card virtual machines (e.g. Android's Dalvik VM). However, providing a Java Card run-time environment on top of another Java virtual machine faces one big problem: The Java Card virtual machine's operation principle is based on persistent memory technology. As a result, the VM and the applications that run on top of it have a significantly different life-cycle compared to other Java VMs. Based on specific scenarios for secure element emulators for the Android platform, we evaluate these differences and their impact on Java VM-based Java Card emulation. Further, we propose possible solutions to the problems that arise from these differences in the life-cycles.
Michael Roland 0001, Josef Langer, René Mayrhofer
MoMM3
2013 UACAP: A Unified Auxiliary Channel Authentication Protocol
abstract
Authenticating spontaneous interactions between devices and users is challenging for several reasons: the wireless (and therefore invisible) nature of device communication, the heterogeneous nature of devices, and lack of appropriate user interfaces in mobile devices, and the requirement for unobtrusive user interaction. The most promising approach that has been proposed in literature involves the exploitation of the so-called auxiliary channels for authentication to bridge the gap between usability and security. This concept has spawned the independent development of various authentication methods and research prototypes, that, unfortunately, remain hard to compare and interchange and are rarely available to potential application developers. We present a novel, unified cryptographic authentication protocol framework (UACAP) to unify these approaches on using auxiliary channels and analyze its security properties. This protocol and a selection of auxiliary channels aimed at authentication of mobile devices has been implemented and released in an open-source ubiquitous authentication toolkit (OpenUAT). We also present an initial user study evaluating four of these channels.
René Mayrhofer, Jürgen Fuß, Iulia Ion
IEEE Trans. Mob. Comput.1
2012 Towards face unlock: on the difficulty of reliably detecting faces on mobile phones
abstract
Currently, reliable face detection and recognition are becoming more important on mobile devices -- e.g. to unlock the screen. However, using only frontal face images for authentication purposes can no longer be considered secure under the assumption of easy availability of frontal snapshots of the respective device owners from social networks or other media. In most current implementations, a sufficiently high-resolution face image displayed on another mobile device will be enough to circumvent security measures. In this paper, we analyze current methods to face detection and recognition regarding their usability in the mobile domain, and then propose an approach to a Face Unlock system on a smart phone intended to be more secure than current approaches while still being convenient to use: we use both frontal and profile face information available during a pan shot around the user's head, by combining camera images and movement sensor data. Current results to face detection are promising, but reliable face recognition needs further research.
Rainhard Dieter Findling, René Mayrhofer
MoMM2
2012 SAPHE: simple accelerometer based wireless pairing with heuristic trees
abstract
Accelerometers provide a good source of entropy for bootstrapping a secure communication channel in autonomous and spontaneous interactions between mobile devices that share a common context but were not previously associated. We propose two simple and efficient key exchange protocols based on accelerometer data that use only simple hash functions combined with heuristic search trees. Using heuristics such as the Euclidean distance proves to be beneficial as it allows a more effective recovery of the shared key. While the first protocol seems to give just some performance improvements, the second, which we call hashed heuristic tree, is more secure than previous proposals since it increases the difference in protocol execution between benign and malicious parties. Nevertheless, the hashed heuristic tree is an entirely new approach which has the advantage of allowing different heuristics in the search, leaving plenty of room for future variants and optimizations.
Bogdan Groza, René Mayrhofer
MoMM2
2011 Private notes: encrypted XML notes synchronization and sharing with untrusted web services
abstract
Personal notes, even when shared with others, often contain highly sensitive information. From a security and privacy point of view, currently available (web) services that upload such personal notes to potentially untrusted third party servers are therefore problematic and we suggest to encrypt all notes before transferring them from the user's personal device. However, synchronization and sharing of encrypted data is a non-trivial issue, because conflict resolution and merging algorithms need to be applied to plain-text content. With Private Notes, we propose an architecture for client-side encryption, merge, and conflict handling of personal notes stored in XML format. We adopt the OpenPGP standard for symmetric and asymmetric encryption and Web-DAV for synchronizing and sharing notes on arbitrary web servers. Specific implementations in the form of a plug-in for the Tomboy desktop note taking application and the Android and iOS mobile platforms demonstrate the ease of use of encrypted notes sharing.
Paul Klingelhuber, René Mayrhofer
iiWAS2
2011 A Critical Review of Applied MDA for Embedded Devices: Identification of Problem Classes and Discussing Porting Efforts in Practice
Michael Lettner, Michael Tschernuth, René Mayrhofer
MoDELS3
2011 Feature interaction analysis in mobile phones: on the borderline between application functionalities and platform components
abstract
With the recent smartphone boom, plenty of mobile phone platforms have emerged which complement simpler platforms that existed before. At the same time, mobile phones today are capable of things that were hardly imaginable a few years ago. This enables new type of applications. From an application developers view, it is challenging to keep up with the latest developments though. The close relation between application features and platform components that realize that feature, is increasingly hard to track. For instance, the requirement to provide SMS functionality requires at least certain input- and output functionalities, and a wireless transmission technology such as GSM or WCDMA.
Michael Lettner, Michael Tschernuth, René Mayrhofer
MoMM3
2010 Air-Writing: a platform for scalable, privacy-preserving, spatial group messaging
abstract
Spatial messaging is a direct extension to text and other multi-media messaging services that have become highly popular with the current pervasiveness of mobile communication. It offers benefits especially to mobile computing, providing localised and therefore potentially more appropriate delivery of nearly arbitrary content. Location is one of the most interesting attributes that can be added to messages in current applications, including gaming, social networking, or advertising services. However, location is also highly critical in terms of privacy. If a spatial messaging platform could collect the location traces of all its users, detailed profiling would be possible -- and, considering commercial value of such profiles, likely. In this paper, we present Air-Writing, an approach to spatial messaging that fully preserves user privacy while offering global scalability, different client interface options, and flexibility in terms of application areas. We contribute both an architecture and a specific implementation of an attribute based messaging platform with special support for spatial messaging and rich clients for J2ME, Google Android, and Apple iPhone. The centralised client/server approach utilises groups for anonymous message retrieval and client caching and filtering as well as randomised queries for obscuring traces. An initial user study with 20 users shows that the overall concept is easily understandable and that it seems useful to end-users. An analysis of real-world and simulated location traces shows that user privacy can be ensured, but with a trade-off between privacy protection and consumed network resources.
René Mayrhofer, Alexander Sommer, Sinan Saral
iiWAS1
2009 Shake Well Before Use: Intuitive and Secure Pairing of Mobile Devices
abstract
A challenge in facilitating spontaneous mobile interactions is to provide pairing methods that are both intuitive and secure. Simultaneous shaking is proposed as a novel and easy-to-use mechanism for pairing of small mobile devices. The underlying principle is to use common movement as a secret that the involved devices share for mutual authentication. We present two concrete methods, ShaVe and ShaCK, in which sensing and analysis of shaking movement is combined with cryptographic protocols for secure authentication. ShaVe is based on initial key exchange followed by exchange and comparison of sensor data for verification of key authenticity. ShaCK, in contrast, is based on matching features extracted from the sensor data to construct a cryptographic key. The classification algorithms used in our approach are shown to robustly separate simultaneous shaking of two devices from other concurrent movement of a pair of devices, with a false negative rate of under 12 percent. A user study confirms that the method is intuitive and easy to use, as users can shake devices in an arbitrary pattern.
René Mayrhofer, Hans-Werner Gellersen
IEEE Trans. Mob. Comput.1
2008 Towards alternative user interfaces for capturing and managing tasks with mobile devices
abstract
Mobile devices, per definition, are supposed to assist in organizing all kinds of things, also tasks of course, because usually such devices are always at hands. But due to the very limited and time consuming possibilities to interact with such devices many fall back to other means to organize their life, like a simple pencil and paper.We developed a collaborative task repository that facilitates collaboration and teamwork, but on the other hand demands that all tasks have to be entered into that system. Therefore a smart and userfriendly interface to that repository is mandatory.This work presents concepts on how to improve the user interface of mobile devices so that capturing tasks on-the-go becomes feasible. We propose to move away from display driven user interfaces to more sophisticated interfaces that utilize all the sensors and actors of current mobile devices.
Harald Radi, René Mayrhofer
MoMM2
2008 Spontaneous mobile device authentication based on sensor data
René Mayrhofer, Hans-Werner Gellersen
Inf. Secur. Tech. Rep.1
2008 Peer-it: Stick-on solutions for networks of things
Alois Ferscha, Manfred Hechinger, Andreas Riener, Marcos dos Santos Rocha, Andreas Zeidler, Marquart Franz, René Mayrhofer
Pervasive Mob. Comput.7
2007 A Human-Verifiable Authentication Protocol Using Visible Laser Light
abstract
Securing wireless channels necessitates authenticating communication partners. For spontaneous interaction, authentication must be efficient and intuitive. One approach to create interaction and authentication methods that scale to using hundreds of services throughout the day is to rely on personal, trusted, mobile devices to interact with the environment. Authenticating the resulting device-to-device interactions requires an out-of-band channel that is verifiable by the user. We present a protocol for creating such an out-of-band channel with visible laser light that is secure against man-in-the-middle attacks even when the laser transmission is not confidential. A prototype implementation shows that an appropriate laser channel can be constructed with simple off-the-shelf components
René Mayrhofer, Martyn Welch
ARES1
2007 Security by Spatial Reference: Using Relative Positioning to Authenticate Devices for Spontaneous Interaction
René Mayrhofer, Hans-Werner Gellersen, Mike Hazas
UbiComp1
2007 On the Security of Ultrasound as Out-of-band Channel
abstract
Ultrasound has been proposed as out-of-band channel for authentication of peer devices in wireless ad hoc networks. Ultrasound can implicitly contribute to secure communication based on inherent limitations in signal propagation, and can additionally be used explicitly by peers to measure and verify their relative positions. In this paper we analyse potential attacks on an ultrasonic communication channel and peer-to-peer ultrasonic sensing, and investigate how potential attacks translate to application-level threats for peers seeking to establish a secure wireless link. Based on our analysis we propose a novel method for authentic communication of short messages over an ultrasonic channel.
René Mayrhofer, Hans-Werner Gellersen
IPDPS1