Christoph Krauß

dblp:34/4605 · also Christoph Krauss · DBLP profile ↗
← Back
40ranked-venue papers
5as first author
16since 2021 · last 2025
0000-0001-7776-7574ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 32 · 4 first-author · 14 since 2021Computer networks · 3Systems, architecture and hardware · 2 · 1 since 2021Software engineering, systems software and programming languages · 1
YearPublicationVenuePosition
2025 CarDS - Controller Area Network and Automotive Ethernet Realistic Data Set
abstract
Intrusion Detection Systems (IDSs) serve as a crucial defense mechanism against cyberattacks targeting the In-Vehicle Network (IVN) of modern, interconnected vehicles. To develop and test new IDS approaches, researchers require realistic IVN data featuring real attacks on moving vehicles. To this end, this paper presents Controller Area Network and Automotive Ethernet Realistic Data Set (CarDS), a novel dataset targeting both the Controller Area Network (CAN) and Automotive Ethernet (AE) traffic of a modern, multi-domain and multi-protocol IVN. Existing datasets are often simulated or limited to basic IVN architectures consisting of only a single CAN bus. Additionally, there are no realistic datasets for AE, despite its growing importance in high-speed in-vehicle communication. CarDS addresses these limitations by providing a labeled, time-synchronized dataset of CAN and AE traces that includes both comprehensive benign profiles and sophisticated attacks. Our traces are captured from an electric vehicle from 2020 featuring a domain-oriented architecture comprising 10 internal CAN buses and 6 AE buses. Specifically, our dataset covers 9h 07m 09s of real IVN data and features 397,383,125 CAN and 180,604,377 AE messages distributed over different scenarios in 258 traces.
Wouter Hellemans, Jannis Hamborg, Timm Lauser, Md Masoom Rabbani, Bart Preneel, Christoph Krauß, Nele Mentens
ACSAC6
2025 CSCS '25 - Cyber Security in CarS Workshop
abstract
The second Cyber Security in Cars Workshop (CSCS'25) takes place in Taipei, Taiwan, on October 17, 2025, in conjunction with the ACM Conference on Computer and Communications Security (CCS'25). CSCS is the successor of the yearly ACM Computer Science in Cars Symposium, which ran from 2017 to 2023. CSCS'25 aims to bring together researchers, practitioners, developers, and anyone interested in solving the myriad of complex problems of cyber security in modern vehicles. The conference offers a common platform to discuss new developments in vehicle technology and its applications. In addition to presenting current research contributions, the conference offers the opportunity for networking, joint brainstorming on current challenges, and the development of new solutions.
Hans-Joachim Hof, Mario Fritz, Christoph Krauß
CCS3
2025 Towards a Holistic and Multi-modal Vehicle Security Monitoring
Ali Recai Yekta, Dominik Spychalski, Cenk Yekta, Markus Heinrich, Christoph Krauß, Stefan Katzenbeisser 0001
CRITIS5
2024 Attack Analysis and Detection for the Combined Electric Vehicle Charging and Power Grid Domains
abstract
With the steady rising Electric Vehicle (EV) adoption world-wide, a consideration of the Electric Vehicle (EV) charging-related load on power grids is becoming critically important. While strategies to manage this load (e.g., to avoid peaks) exist, they assume that Electric Vehicles (EVs) and charging infrastructure are trustworthy. If this assumption is, however, violated (e.g., by an adversary with control over Electric Vehicle (EV) charging systems), the threat of charging load-based attacks on grid stability arises. An adversary may, for example, try to cause overload situations, by means of a simultaneous increase in charging load coordinated over a large number of EVs. In this paper, we propose an Intrusion Detection System (IDS) that combines regression-based charging load prediction with novelty detection-based anomaly identification. The proposed system considers features from both the Electric Vehicle (EV) charging and power grid domains, which is enabled in this paper by a novel co-simulation concept. We evaluate our Intrusion Detection System (IDS) concept with simulated attacks in real Electric Vehicle (EV) charging data. The results show that the combination of support vector regression with isolation forest-based novelty detection generally provides the best results. Additionally, the evaluation shows that our Intrusion Detection System (IDS) concept, combining grid and charging features, is capable of detecting novel/stealthy attack strategies not covered by related work.
Dustin Kern, Christoph Krauß, Matthias Hollick
ARES2
2024 Self-sovereign Identity for Electric Vehicle Charging
Adrian Kailus, Dustin Kern, Christoph Krauß
ACNS (3)3
2024 CSCS '24 - Cyber Security in CarS Workshop
abstract
The increasing attack surface of modern cars and the new regulatory requirements for cybersecurity (like UNECE R155) made cybersecurity an important part of car design. The "CSCS'24 Cyber Security in Cars Workshop" is designed to address current topics in the rapidly evolving automotive cybersecurity domain. The goal is to bring together academia and industry to find novel solutions for cybersecurity problems in the automotive domain. CSCS'24 is the first CSCS workshop co-located with ACM CCS. Nonetheless, it is founded on a series of events known as the "ACM Cyber Security in Cars Symposium (CSCS symposium)" that lasted from 2017 until 2023. CSCS'24 welcomes any theoretical or practical contributions to the rich field of automotive cybersecurity, including secure automotive communication, ECU system security, and aspects of Cyber Security Management Systems (CSMS).
Mario Fritz, Christoph Krauß, Hans-Joachim Hof
CCS2
2023 Formal Security Analysis of Vehicle Diagnostic Protocols
abstract
Diagnostic protocols for vehicles are important for maintenance, updates, etc. However, if they are not secure, an attacker can use them as an entry point to the vehicle or even directly access critical functionality. In this paper, we discuss the security of the vehicle diagnostics protocols Diagnostics over IP (DoIP) and Unified Diagnostic Services (UDS). For UDS, we provide a formal analysis of the included security protocols SecurityAccess service and the different variants of the new Authentication service introduced in the year 2020. We present two new vulnerabilities, we identified in our analyses, describe how they can be mitigated and formally verify our mitigations. Furthermore, we give recommendations on how to securely implement UDS and how future standards can be improved.
Timm Lauser, Christoph Krauß
ARES2
2023 QuantumCharge: Post-Quantum Cryptography for Electric Vehicle Charging
Dustin Kern, Christoph Krauß, Timm Lauser, Nouri Alnahawi, Alexander Wiesmaier, Ruben Niederhagen
ACNS2
2023 Remote Attestation with Constrained Disclosure
abstract
Trusted Platform Modules (TPMs) are used for remote attestation to ensure the authenticity and integrity of software running on a computer system. However, measuring software executed as containers or virtual machines can be challenging as it is measured concurrently, resulting in a jumbled measurement log that is difficult to disentangle. Moreover, disclosing the entire measurement log in traditional binary remote attestation raises privacy and intellectual property concerns. To address these issues, we propose a remote attestation method with constrained disclosure, allowing for selective disclosure of entries in the measurement log using a non-interactive zero-knowledge (NIZK) proof with Schnorr signatures. Our approach is evaluated for security and privacy and proven to be correct, sound, and satisfies the properties of a NIZK proof. Formal verification of our solution with ProVerif also supports our claims. Furthermore, the performance evaluation of our proof-of-concept implementation shows that our contribution is feasible, and the overhead introduced is negligible.
Michael Eckel, Dominik Roy George, Björn Grohmann, Christoph Krauß
ACSAC4
2023 Detection of Anomalies in Electric Vehicle Charging Sessions
abstract
Electric Vehicle (EV) charging involves a complex system with cyber-physical components, backend systems, and communication protocols. A potential security incident in this system can open up cyber-physical threats and, for instance, lead to EV battery fires or power grid blackouts. In this paper, we propose a hybrid Intrusion Detection System (IDS) method consisting of regression-based charging session forecasting and anomaly detection. The method considers an EV’s detailed charging behavior throughout a session and we discuss and evaluate different design choices. For anomaly detection, we consider both classification- and novelty-based models as well as an ensemble method to combine both models. We perform evaluations based on real-world EV charging session data with simulated attacks. Our results show that regression-based forecasting provides a significant increase in detection performance for attacks affecting individual reports during a charging session. Additionally, the proposed ensemble method, which combines artificial neural network-based classification and local outlier factor-based novelty detection, can maintain a low false alarm rate while offering good detection performance w.r.t. known attacks as well as generalization to previously unseen attacks. We thus argue that the proposed solution can provide a positive contribution to EV charging security, resilience, and trustworthiness.
Dustin Kern, Christoph Krauß, Matthias Hollick
ACSAC2
2023 Detection of e-Mobility-Based Attacks on the Power Grid
abstract
The increasing use of information and communication technology in power grids and connected e-mobility infrastructures enables cyber attacks. E-mobility infrastructure components such as Charge Points (CPs) or Electric Vehicles (EVs) could be used as attack vector on power grids via False Data Injection (FDI) or Manipulation of demand (Mad) attacks. To detect such attacks, Intrusion Detection Systems (IDSs) which are adapted to the specifics of e-mobility are required. In this paper, we propose a novel hybrid IDS for detecting e-mobility-based attacks on the power grid consisting of a rule-based IDS and an anomaly detection component using regression-based forecasting. The IDS is distributed among different e-mobility-related backend systems, namely Charge Point Operators (CPOs) and grid operators. We implemented our IDS and evaluate it on several data sets while simulating realistic attack scenarios to show the effectiveness of our approach. Our evaluation compares different IDS design choices and regression models. Especially, decision tree regression proved to be an effective base for detection at CPOs. By combining the distributed IDS reports of individual CPOs at the grid operator, the overall detection performance is further improved. The distributed nature of the system allows it to identify large-scale attacks effectively and thus robustly detect realistic threats to power grid operation.
Dustin Kern, Christoph Krauß
DSN2
2023 Evaluation of Decision Tree-Based Rule Derivation for Intrusion Detection in Automotive Ethernet
abstract
The digitization and networking of safety-critical systems also enables attacks that can have devastating consequences. Thus, appropriate security measures are required. In this work, we investigate a novel approach for security monitoring adapted to the requirements and properties of safety-critical systems. In particular, we evaluate and adapt a decision tree-based detection method that is not only explainable in the sense that the software’s internal processes can be explained to the decision maker, but we use the decision tree and the generated rules to understand exactly which attributes of a message are used for identification of the attack. This supports experts in the decision-making process and can also be used for automated countermeasure generation. We demonstrate the detection method on an Automotive Ethernet protocol that is being introduced in modern vehicles to replace or complement currently used bus communication.
Felix Clemens Gail, Roland Rieke, Florian Fenzl, Christoph Krauß
TrustCom4
2022 Decision Tree-Based Rule Derivation for Intrusion Detection in Safety-Critical Automotive Systems
abstract
Intrusion Detection Systems (IDSs) are being introduced into safety-critical systems such as connected vehicles. Since the behavior and effectiveness of measures are validated before approval, the decisions made by an IDS are required to be traceable and the IDS also needs to work efficiently on resource-constrained embedded systems. These requirements complicate the direct use of Machine Learning (ML) approaches in IDS design. In this paper, we propose an approach to using ML to generate rules for an efficient rule-based IDS like Snort. Our approach eases the time-consuming and difficult process of creating a rule set. We use decision trees to generate rules that can be used by experts as a basis for creating a rule set for a specific safety-critical use case. In addition, we use long short-term memory methods to circumvent the problem of limited training data availability, a common limitation in safety-critical systems. Our implementation and evaluation shows the feasibility of our approach to derive specific IDS rules for such systems.
Lucas Buschlinger, Sanat Sarda, Christoph Krauß
PDP3
2022 Integrating Privacy into the Electric Vehicle Charging Architecture
abstract
The Electric Vehicle (EV) charging architecture consists of several actors which communicate with different protocols. A serious issue is the lack of adequate privacy-preserving measures that enables the generation of movement profiles or inferring consumer habits by all of the involved actors. In this paper, we propose an extension of a Trusted Platform Module (TPM)-based Direct Anonymous Attestation (DAA) scheme to enable privacy-preserving charging authorization and billing. Our implementation shows that our solution can be easily integrated into existing protocols of the Plug-and-Charge (PnC) EV charging architecture and introduces only minor overhead. The formal analysis using the Tamarin prover shows the security and privacy of our protocol extension.
Dustin Kern, Timm Lauser, Christoph Krauß
Proc. Priv. Enhancing Technol.3
2021 Analyzing and Securing SOME/IP Automotive Services with Formal and Practical Methods
abstract
Automotive Ethernet is increasingly used in modern vehicles and complements or replaces legacy bus systems such as CAN. Ethernet also enables service-oriented communication with the Scalable service-Oriented MiddlewarE over IP (SOME/IP) middleware. In this paper, we present a formal and practical security analysis of Scalable service-Oriented MiddlewarE over IP (SOME/IP), the identified Man-in-the-Middle (MITM) attacks, and propose two security extensions. The attacks are possible even if SOME/IP is used in combination with link layer security mechanisms. The attacker can impersonate a service offering server and a service consuming client. The two most common communication methods, request/response and publish/subscribe, are both vulnerable. In most communication scenarios, we are able to route all messages over the attacker. Our security extensions for authentication and authorization of service provisioning and usage protect against these attacks. We formally analyze the security and evaluate the overhead with practical implementations.
Daniel Zelle, Timm Lauser, Dustin Kern, Christoph Krauß
ARES4
2021 Attack Surface Assessment for Cybersecurity Engineering in the Automotive Domain
abstract
Connected smart cars enable new attacks that may have serious consequences. Thus, the development of new cars must follow a cybersecurity engineering process as defined for example in ISO/SAE 21434. A central part of such a process is the threat and risk assessment including an attack feasibility rating. In this paper, we present an attack surface assessment with focus on the attack feasibility rating compliant to ISO/SAE 21434. We introduce a reference architecture with assets constituting the attack surface, the attack feasibility rating for these assets, and the application of this rating on typical use cases. The attack feasibility rating assigns attacks and assets to an evaluation of the attacker dimensions such as the required knowledge and the feasibility of attacks derived from it. Our application of sample use cases shows how this rating can be used to assess the feasibility of an entire attack path. The attack feasibility rating can be used as a building block in a threat and risk assessment according to ISO/SAE 21434.
Christian Plappert, Daniel Zelle, Henry Gadacz, Roland Rieke, Dirk Scheuermann, Christoph Krauß
PDP6
2020 HIP: HSM-based identities for plug-and-charge
abstract
Plug-and-Charge (PnC) standards such as ISO 15118 enable Electric Vehicle (EV) authentication against Charge Points (CPs) without driver intervention. Credentials are stored in the vehicle itself making methods using RFID cards obsolete. However, credentials are generated in service provider backend systems and provisioned via the Internet and not in a secure Hardware Security Module (HSM) within the vehicle. In this paper, we propose HIP, a backwards compatible protocol extension for ISO 15118 where keys are generated and stored in a Trusted Platform Module (TPM) within the vehicle. Our implementation and evaluation show that our solution is feasible and is a viable option for future editions of ISO 15118.
Andreas Fuchs 0002, Dustin Kern, Christoph Krauß, Maria Zhdanova
ARES3
2020 Post-Quantum TLS on Embedded Systems: Integrating and Evaluating Kyber and SPHINCS+ with mbed TLS
abstract
We present our integration of post-quantum cryptography (PQC), more specifically of the post-quantum KEM scheme Kyber for key establishment and the post-quantum signature scheme SPHINCS+, into the embedded TLS library mbed TLS. We measure the performance of these post-quantum primitives on four different embedded platforms with three different ARM processors and an Xtensa LX6 processor. Furthermore, we compare the performance of our experimental PQC cipher suite to a classical TLS variant using elliptic curve cryptography (ECC). Post-quantum key establishment and signature schemes have been either integrated into TLS or ported to embedded devices before. However, to the best of our knowledge, we are the first to combine TLS, post-quantum schemes, and embedded systems and to measure and evaluate the performance of post-quantum TLS on embedded platforms. Our results show that post-quantum key establishment with Kyber performs well in TLS on embedded devices compared to ECC variants. The use of SPHINCS+ signatures comes with certain challenges in terms of signature size and signing time, which mainly affects the use of embedded systems as PQC-TLS server but does not necessarily prevent embedded systems to act as PQC-TLS clients.
Kevin Bürstinghaus-Steinbach, Christoph Krauß, Ruben Niederhagen, Michael Schneider 0002
AsiaCCS2
2020 Post-Quantum Secure Boot
abstract
A secure boot protocol is fundamental to ensuring the integrity of the trusted computing base of a secure system. The use of digital signature algorithms (DSAs) based on traditional asymmetric cryptography, particularly for secure boot, leaves such systems vulnerable to the threat of quantum computers. This paper presents the first post-quantum secure boot solution, implemented fully as hardware for reasons of security and performance. In particular, this work uses the eXtended Merkle Signature Scheme (XMSS), a hash-based scheme that has been specified as an IETF RFC. The solution has been integrated into a secure SoC platform around RISC-V cores and evaluated on an FPGA and is shown to be orders of magnitude faster compared to corresponding hardware/software implementations and to compare competitively with a fully hardware elliptic curve DSA based solution.
Vinay B. Y. Kumar, Naina Gupta 0001, Anupam Chattopadhyay, Michael Kasper, Christoph Krauß, Ruben Niederhagen
DATE5
2020 SEPAD - Security Evaluation Platform for Autonomous Driving
abstract
The development and evaluation of security solutions for autonomous vehicles is a challenging task. Many researchers have no access to real vehicles to implement and test their solutions. In addition, vehicle E/E architectures of different brands or even model series of one car manufacturer differ significantly. Also, vehicles may be the source of physical hazards, e.g., an exploding airbag. To enable researchers to develop, implement, and evaluate new security solutions for autonomous vehicles, we propose a new security evaluation platform called SEPAD and a dedicated development process for testing security mechanisms with it. SEPAD allows to model realistic E/E architectures where the developed security solutions can be integrated and evaluated without causing safety risks for the researcher or other road users.
Daniel Zelle, Roland Rieke, Christian Plappert, Christoph Krauß, Dmitry Levshun, Andrey Chechulin
PDP4
2020 Securing Electric Vehicle Charging Systems Through Component Binding
Andreas Fuchs 0002, Dustin Kern, Christoph Krauß, Maria Zhdanova
SAFECOMP3
2019 Security Requirements Engineering in Safety-Critical Railway Signalling Networks
abstract
Securing a safety-critical system is a challenging task, because safety requirements have to be considered alongside security controls. We report on our experience to develop a security architecture for railway signalling systems starting from the bare safety-critical system that requires protection. We use a threat-based approach to determine security risk acceptance criteria and derive security requirements. We discuss the executed process and make suggestions for improvements. Based on the security requirements, we develop a security architecture. The architecture is based on a hardware platform that provides the resources required for safety as well as security applications and is able to run these applications of mixed-criticality (safety-critical applications and other applications run on the same device). To achieve this, we apply the MILS approach, a separation-based high-assurance security architecture to simplify the safety case and security case of our approach. We describe the assurance requirements of the separation kernel subcomponent, which represents the key component of the MILS architecture. We further discuss the security measures of our architecture that are included to protect the safety-critical application from cyberattacks.
Markus Heinrich, Tsvetoslava Vateva-Gurova, Tolga Arul, Stefan Katzenbeisser 0001, Neeraj Suri, Henk Birkholz, Andreas Fuchs 0002, Christoph Krauß, Maria Zhdanova, Don Kuzhiyelil, Sergey Tverdyshev, Christian Schlehuber
Secur. Commun. Networks8
2018 The user-centered privacy-aware control system PRICON: An interdisciplinary evaluation
abstract
The advent of connected vehicles has increased the relevance of privacy in cars. While current approaches to increase security and privacy in connected vehicles are mainly driven from technological perspectives, users do not have active control over their personal data. Therefore, the user-centered privacy-aware control system PrivacyController (PRICON) has been developed which incorporates expertise from judicial, technical and user-centered perspectives. PRICON provides users with a user-friendly possibility to define self-determined privacy policies which are applied to the vehicular system. In this paper, we report the evaluation of PRICON from a legal, technical and user-centered point-of-view. The evaluation results are discussed and practical implications are derived.
Jonas Walter, Bettina Abendroth, Thilo Von Pape, Christian Plappert, Daniel Zelle, Christoph Krauß, G. Gagzow, Hendrik Decke
ARES6
2018 Anonymous Charging and Billing of Electric Vehicles
abstract
None of the existing and upcoming Plug-and-Charge (PnC) related standards define privacy-preserving measures for protecting privacy-sensitive charging and billing data to prevent attacks such as the generation of movement profiles. To address this issue, we analyze PnC protocols with respect to privacy, identify requirements for privacy-preserving PnC solutions, and propose a PnC protocol extension enabling users to charge Electric Vehicle (EV) anonymously and service providers to securely bill their customers. Our approach addresses the complete PnC process chain and is based on a Direct Anonymous Attestation (DAA) protocol using a Trusted Platform Module (TPM) in the vehicle. Our analysis shows that our approach effectively protects the customers privacy while introducing only minimal additional protocol overhead.
Daniel Zelle, Markus Springer, Maria Zhdanova, Christoph Krauß
ARES4
2017 On Using TLS to Secure In-Vehicle Networks
abstract
A trend in modern in-vehicle networks is the use of network technologies with higher bandwidth such as Automotive Ethernet. As a result, more sophisticated security technologies may be used to secure the communication. In this paper, we investigate whether the Transport Layer Security Protocol (TLS) is applicable to secure in-vehicle networks. First, we identify the security and performance requirements as well as the communication scenarios which must be supported by the TLS communication. Next, we discuss how these requirements can be realized with TLS. This also includes the discussion of the certificate management. Finally, we present and discuss our prototypical TLS implementation on a typical automotive platform and show that TLS is able to fulfill most performance requirements of the automotive industry.
Daniel Zelle, Christoph Krauß, Hubert Strauß, Karsten Schmidt 0003
ARES2
2017 Runtime Firmware Product Lines Using TPM2.0
Andreas Fuchs 0002, Christoph Krauß, Jürgen Repp
SEC2
2016 Advanced Remote Firmware Upgrades Using TPM 2.0
Andreas Fuchs 0002, Christoph Krauß, Jürgen Repp
SEC2
2015 Mitigation of peer-to-peer overlay attacks in the automatic metering infrastructure of smart grids
abstract
Abstract Measurements gathered by smart metres and collected through the automatic metering infrastructure of smart grids can be accessed by numerous external subjects for different purposes, ranging from billing to grid monitoring. Therefore, to prevent the disclosure of personal information through the analysis of energy consumption patterns, the metering data must be securely handled. Peer‐to‐peer networking is a promising approach for interconnecting communication nodes among the automatic metering infrastructure to efficiently perform data collection while ensuring privacy and confidentiality, but it is also prone to various security attacks. This paper discusses the impact of the most relevant peer‐to‐peer attack scenarios on the performance of a protocol for privacy preserving aggregation of metering data. The protocol relies on communication gateways located in the customers’ households and interconnected by means of a variant of the Chord overlay. We also propose some countermeasures to mitigate the effects of such attacks: we integrate a verifiable secret sharing scheme based on Pedersen commitments in the aggregation protocol, which ensures data integrity, with compliance checks aimed at identifying the injection of altered measurements. Moreover, we introduce Chord auxiliary routing tables to counteract the routing pollution performed by dishonest nodes. The paper evaluates the computational complexity and effectiveness of the proposed solutions through analytical and numerical results. Copyright © 2014 John Wiley & Sons, Ltd.
Cristina Rottondi, Marco Savi, Giacomo Verticale, Christoph Krauß
Secur. Commun. Networks4
2013 A decisional attack to privacy-friendly data aggregation in Smart Grids
abstract
The privacy-preserving management of energy consumption measurements gathered by Smart Meters plays a pivotal role in the Automatic Metering Infrastructure of Smart Grids. Grid users and standardization committees are requiring that utilities and third parties collecting aggregated metering data are prevented from accessing measurements at the household granularity, and data perturbation is a technique used to provide a trade-off between the privacy of individual users and the precision of the aggregated measurements. In this paper, we discuss a decisional attack to aggregation with data-perturbation, showing that a curious entity can exploit the temporal correlation of Smart Grid measurements to detect the presence or absence of individual data generated by a given user inside an aggregate. We also propose a countermeasure to such attack and show its effectiveness using both synthetic and real home energy consumption measurement traces.
Cristina Rottondi, Marco Savi, Daniele Polenghi, Giacomo Verticale, Christoph Krauß
GLOBECOM5
2013 Secure distributed data aggregation in the automatic metering infrastructure of smart grids
abstract
The widespread deployment of Automatic Metering Infrastructures in Smart Grid scenarios rises great concerns about privacy preservation of user-related data, from which detailed information about customer's habits and behaviours can be deduced. Therefore, the users' individual measurements should be aggregated before being provided to External Entities such as utilities, grid managers and third parties. This paper proposes a security architecture for distributed aggregation of smart metering data relying on Gateways placed at the customers' premises, which collect the data generated by local Meters and provide communication and cryptographic capabilities. We propose a secure communication protocol based on multiparty computation aimed at preventing Gateways and External Entities from inferring information about individual data. The routing of information flows can be centralized or it can be performed in a distributed fashion using a protocol similar to Chord.
Cristina Rottondi, Giacomo Verticale, Christoph Krauß
ICC3
2013 Lightweight Attestation and Secure Code Update for Multiple Separated Microkernel Tasks
Steffen Wagner, Christoph Krauß, Claudia Eckert 0001
ISC2
2013 Using Trusted Platform Modules for Location Assurance in Cloud Networking
Christoph Krauß, Volker Fusenig
NSS1
2013 Distributed Privacy-Preserving Aggregation of Metering Data in Smart Grids
abstract
The widespread deployment of Automatic Metering Infrastructures in Smart Grid scenarios rises great concerns about privacy preservation of user-related data, from which detailed information about customer's habits and behaviors can be deduced. Therefore, the users' individual measurements should be aggregated before being provided to External Entities such as utilities, grid managers and third parties. This paper proposes a security architecture for distributed aggregation of additive data, in particular energy consumption metering data, relying on Gateways placed at the customers' premises, which collect the data generated by local Meters and provide communication and cryptographic capabilities. The Gateways communicate with one another and with the External Entities by means of a public data network. We propose a secure communication protocol aimed at preventing Gateways and External Entities from inferring information about individual data, in which privacy-preserving aggregation is performed by means of a cryptographic homomorphic scheme. The routing of information flows can be centralized or it can be performed in a distributed fashion using a protocol inspired by Chord. We compare the performance of both approaches to the optimal solution minimizing the data aggregation delay.
Cristina Rottondi, Giacomo Verticale, Christoph Krauß
IEEE J. Sel. Areas Commun.3
2012 Towards Secure Fieldbus Communication
Felix Wieczorek, Christoph Krauß, Frank Schiller, Claudia Eckert 0001
SAFECOMP2
2011 T-CUP: A TPM-Based Code Update Protocol Enabling Attestations for Sensor Networks
Steffen Wagner, Christoph Krauß, Claudia Eckert 0001
SecureComm2
2009 Short Hash-Based Signatures for Wireless Sensor Networks
Erik Dahmen, Christoph Krauß
CANS2
2008 An Enhanced Scheme to Defend against False-Endorsement-Based DoS Attacks in WSNs
abstract
Node compromise is a serious threat in wireless sensor networks, as it enables an adversary to perform various attacks. Many security schemes exploit the redundancy of many wireless sensor networks to mitigate the impact of node compromise. A report for the base station, generated by one node, must be endorsed by multiple neighboring sensor nodes. However, already proposed schemes are susceptible to False-Endorsement-Based Denial of Service attacks, where a compromised node sends a false endorsement that invalidates the collaboratively generated report. A formerly proposed scheme addresses such an attack, thereby enabling the detection and exclusion of false endorsing nodes. However, a jamming attack can result in a false exclusion of non-compromised nodes. In this paper, we discuss possible solutions to prevent false exclusions of non-compromised nodes and propose an extended scheme.
Christoph Krauß, Markus Schneider 0002, Claudia Eckert 0001
WiMob1
2008 Defending against false-endorsement-based dos attacks in wireless sensor networks
abstract
Node compromise is a serious threat in wireless sensor networks. An adversary can use compromised sensor nodes to inject false data to deceive the base station or he can try to deplete the energy resources of the sensor nodes. One approach to mitigate the impact of node compromise exploits the redundancy property of many wireless sensor networks. If a node initiates a report generation for the base station, then this report must be endorsed by multiple neighboring sensor nodes. Already proposed schemes using this approach introduce a new possible attack, called False-Endorsement-Based Denial of Service attack, where a compromised node sends a false endorsement which invalidates the collaboratively generated report. We propose an extension scheme, which enables the detection and exclusion of false endorsing nodes and is efficient in terms of storage and energy consumption.
Christoph Krauß, Markus Schneider 0002, Claudia Eckert 0001
WISEC1
2008 On handling insider attacks in wireless sensor networks
Christoph Krauß, Markus Schneider 0002, Claudia Eckert 0001
Inf. Secur. Tech. Rep.1
2007 STEF: A Secure Ticket-Based En-route Filtering Scheme for Wireless Sensor Networks
abstract
Node compromise is a serious threat in wireless sensor networks. An adversary can use compromised nodes to inject false data into the network forging events to deceive the base station. Furthermore, an adversary can cause serious damage by injecting a large amount of false messages to deplete the scarce energy resources of the forwarding en-route sensor nodes. In this paper, we propose a Secure Ticket-Based Enroute Filtering Scheme (STEF) that drops false messages enroute. We propose a ticket concept where reply messages are only forwarded if they contain a valid ticket originally issued by the base station. Messages containing no ticket, or an replayed ticket, are immediately filtered out by not compromised sensor nodes. The ticket concept is based on lightweight one-way functions. This enables every en-route node to verify the tickets. Furthermore, our scheme does not need symmetric key sharing between message generating nodes and en-route nodes, which results in a high resiliency against node compromises. Our security and performance analysis shows that STEF provides a high security level and is very efficient in saving energy. Furthermore, the required storage capacity on the sensor nodes is very low.
Christoph Krauß, Markus Schneider 0002, Kpatcha M. Bayarou, Claudia Eckert 0001
ARES1