EDBT 2026 Demo / reviewers in the wild / expert
Georgios Gkoktsis
dblp:346/1259
· DBLP profile ↗
4ranked-venue papers
2as first author
4since 2021 · last 2025
0000-0002-1031-5036ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Towards Stateless Post-Quantum Remote Attestation for IoT Using TPM and DICEabstractRemote attestation is a cornerstone of Trusted Computing, ensuring the integrity and trustworthiness of devices in diverse environments, ranging from resource-constrained IoT nodes to cloud-based virtual machines (VMs). The two predominant attestation technologies, the Trusted Platform Module (TPM) and the Device Identifier Composition Engine (DICE), provide strong security guarantees but often rely on stateful challenge-response models. These models introduce scalability challenges, particularly in large-scale Internet of Things (IoT) and smart metering deployments.This paper presents a powerful stateless post-quantum remote attestation approach for IoT devices, leveraging authenticated and encrypted (AEAD) challenges within TPM and DICE-based attestation. The stateless approach effectively limits replay attacks to a short validity window, even in environments where IoT devices lack real-time clocks, and enables robust integrity and trust verification across dynamic network topologies, by avoiding the downsides of other freshness concepts for remote attestation.Furthermore, this paper presents a performance evaluation of suitable post-quantum cryptography (PQC) algorithms across five heterogeneous hardware platforms, ranging from high-end laptops to constrained IoT devices, to present a recommendation to the reader, thereby illustrating the continued utility of remote attestation on IoT devices in the future.Our findings suggest that stateless post-quantum remote attestation can enhance security and scalability in IoT environments, by reducing overhead from storage of nonces making it a compelling alternative to traditional challenge-response models. Michael Eckel, Janik Gorbracht, Georgios Gkoktsis, Tobias Kaupat |
TrustCom | 3 |
| 2025 | Who Appraises the Appraiser? Decentralized Attestation with Partial Appraisal and Aggregated ResultsabstractWe present a decentralized approach to remote attestation that moves evidence appraisal from a central verifier to Trusted Execution Environments (TEEs) at the edge, emitting compact attestation results instead of raw evidence. Our design supports partial appraisal—explicitly encoding unknown or missing evidence—and aggregation of (partial) attestation results across composite systems, anchored in provisioned keys and reference values (RVs). To answer "Who appraises the appraiser?", each edge verifier is itself attested (e. g., Intel SGX/TDX, AMD SEV-SNP, Arm Trust Zone-A/M, RISC-V Keystone and MultiZone®, NVIDIA H100) and its TEE quote is cryptographically bound to the attestation result, enabling relying parties to appraise both the device and the verifier. The approach instantiates cleanly across domains—constrained IoT/smart metering (SMGWs), automotive zonal architectures, cloud/edge multi-tenant stacks, Network Functions Virtualization (NFV) chassis, and power substations—with identical semantics for partial appraisal and aggregation. A prototype using CHAllenge-Response based Remote Attestation with TPM 2.0 (CHARRA) with the verifier inside Intel Software Guard Extensions (SGX) using the Gramine library OS demonstrates reduced network volume and central CPU load with acceptable overheads while preserving conservative security semantics under partially appraised evidence. Michael Eckel, Georgios Gkoktsis, Markus Horn |
TrustCom | 2 |
| 2024 | The Cyber Safe Position: An STPA for Safety, Security, and Resilience Co-Engineering ApproachabstractModel Based Security Engineering (MBSE) is a growing field of research, which is gaining popularity in the domain of Safety, Security, and Resilience Co-Engineering. The System Theoretic Process Analysis (STPA) is a method for systematically analyzing the behavior of complex systems to investigate their failure modes and the Unsafe Control Actions (UCA) that can lead to those failure modes. This paper expands the methodological scope of STPA, by including an iterative Root-Cause Analysis element, which examines the possible emergence of UCAs due to either malfunction, or malicious action. Output of the method are the attributes and constraints of Resilience Modes of system configuration and operation, named ”Cyber Safe Position“ (CSP). The proposed method is applied in the case study of a Photovoltaic Plant connected to a Virtual Power Plant (VPP). Georgios Gkoktsis, Ludger Peters |
ARES | 1 |
| 2023 | Risk Assessments in Virtual Power Plants with NESCOR Criteria, Practical Application, Advantages and DisadvantagesabstractCyber security in the energy sector is paramount to the safe and reliable generation, transmission, and delivery of electrical energy. In the paradigm of the Virtual Power Plant, a structure which aggregates the output of multiple Distributed Energy Resources and connects to the grid as one entity, it is particularly challenging to prioritize those security controls and countermeasures that measurably improve its security posture. Assessing and framing cyber risk is critically important to enable such endeavors. The National Electric Sector Cybersecurity Organization Resource (NESCOR) has published an assessment framework for the energy sector as part of a study on failure scenarios. This paper presents the results of a practical application of this methodology with an adaptation to VPP specifics and illuminates some of the advantages and challenges present in the process. Georgios Gkoktsis, Hagen Lauer, Lukas Jäger |
ARES | 1 |