EDBT 2026 Demo / reviewers in the wild / expert
N. Asokan
dblp:39/2508
· DBLP profile ↗
114ranked-venue papers
16as first author
27since 2021 · last 2026
0000-0002-5093-9871ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 69 · 10 first-author · 20 since 2021Systems, architecture and hardware · 16 · 1 first-author · 1 since 2021Computer networks · 13 · 3 first-authorHuman-computer interaction and ubiquitous computing · 7Applied, interdisciplinary, general and emerging computing · 5 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 3 · 2 since 2021Databases, data management, data science and information retrieval · 3Graphics, computer vision, multimedia, augmented reality and games · 3 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Locket: Robust Feature-Locking Technique for Language ModelsabstractChatbot service providers (e.g., OpenAI) rely on tiered subscription plans to generate revenue, offering black-box access to basic models for free users and advanced models to paying subscribers.However, this approach is unprofitable and inflexible.A pay-to-unlock scheme for premium features (e.g., math, coding) offers a more sustainable alternative.Enabling such a scheme requires a feature-locking technique (FLoTE) that is (i) effective in refusing locked features, (ii) utility-preserving for unlocked features, (iii) robust against evasion or unauthorized credential sharing, and (iv) scalable to multiple features and clients.Existing FLoTEs (e.g., password-locked models) fail to meet these criteria.To fill this gap, we present LOCKET, a more robust and scalable FLoTE to enable pay-to-unlock schemes.We develop a framework for adversarial training and merging of feature-locking adapters, which enables LOCKET to selectively disable specific features of a model.Evaluation shows that LOCKET is effective (100% refusal rate), utility-preserving (≤ 7% utility degradation), robust (≤ 5% attack success rate), and scalable to multiple features and clients. Lipeng He, Vasisht Duddu, N. Asokan |
ACL (1) | 3 |
| 2025 | BLACKOUT: Data-Oblivious Computation with Blinded CapabilitiesabstractLack of memory-safety and exposure to side channels are two prominent, persistent challenges for the secure implementation of software. Memory-safe programming languages promise to significantly reduce the prevalence of memory-safety bugs, but make it more difficult to implement side-channel-resistant code. We aim to address both memory-safety and side-channel resistance by augmenting memory-safe hardware with the ability for data-oblivious programming. We describe an extension to the CHERI capability architecture to provide blinded capabilities that allow data-oblivious computation to be carried out by userspace tasks. We also present BLACKOUT, our realization of blinded capabilities on a FPGA softcore based on the speculative out-of-order CHERI-Toooba processor and extend the CHERI-enabled Clang/LLVM compiler and the CheriBSD operating system with support for blinded capabilities. BLACKOUT makes writing side-channel-resistant code easier by making non-data-oblivious operations via blinded capabilities explicitly fault. Through rigorous evaluation we show that BLACKOUT ensures memory operated on through blinded capabilities is securely allocated, used, and reclaimed and demonstrate that, in benchmarks comparable to those used by previous work, BLACKOUT imposes only a small performance degradation (1.5% geometric mean) compared to the baseline CHERI-Toooba processor. Hossam ElAtali, Merve Gülmez, Thomas Nyman, N. Asokan |
CCS | 4 |
| 2025 | Espresso: Robust Concept Filtering in Text-to-Image ModelsabstractDiffusion based text-to-image models are trained on large datasets scraped from the Internet, potentially containing unacceptable concepts (e.g., copyright-infringing or unsafe). We need concept removal techniques (CRTs) which are i) effective in preventing the generation of images with unacceptable concepts, ii) utility-preserving on acceptable concepts, and, iii) robust against evasion with adversarial prompts. No prior CRT satisfies all these requirements simultaneously. We introduce Espresso, the first robust concept filter based on Contrastive Language-Image Pre-Training (CLIP). We identify unacceptable concepts by using the distance between the embedding of a generated image to the text embeddings of both unacceptable and acceptable concepts. This lets us fine-tune for robustness by separating the text embeddings of unacceptable and acceptable concepts while preserving utility. We present a pipeline to evaluate various CRTs to show that Espresso is more effective and robust than prior CRTs, while retaining utility Anudeep Das, Vasisht Duddu, Rui Zhang 0118, N. Asokan |
CODASPY | 4 |
| 2025 | Laminator: Verifiable ML Property Cards using Hardware-assisted AttestationsabstractRegulations increasingly call for various assurances from machine learning (ML) model providers about their training data, training process, and model behavior. For better transparency, industry (e.g., Huggingface and Google) has adopted model cards and datasheets to describe various properties of training datasets and models. In the same vein, we introduce the notion of inference cards to describe the properties of a given inference (e.g., binding of the output to the model and its corresponding input). We coin the term ML property cards to collectively refer to these various types of cards. Vasisht Duddu, Lachlan J. Gunn, N. Asokan |
CODASPY | 3 |
| 2025 | Ariadne: Navigating through the Labyrinth of Data-Driven Customization Inconsistencies in Android
Parjanya Vyas, Haseeb Ur Rehman Faheem, Yousra Aafer, N. Asokan |
USENIX Security Symposium | 4 |
| 2025 | SoK: The Spectre of Surveillance and Censorship in Future Internet ArchitecturesabstractRecent initiatives known as Future Internet Architectures (FIAs) seek to redesign the Internet to improve performance, scalability, and security. However, some governments perceive Internet access as a threat to their political standing and engage in widespread network surveillance and censorship. In this paper, we provide an in-depth analysis of the design principles of prominent FIAs in terms of their packet structure, addressing and naming schemes, and routing protocols to foster discussion on how these new systems interact with censorship and surveillance apparatuses. Further, we assess the extent to which existing surveillance and censorship mechanisms can successfully target FIA users while discussing privacy enhancing technologies to counter these mechanisms. We conclude by providing guidelines for future research into novel FIA-based privacy-enhancing technologies, and recommendations to guide the evaluation of these technologies. Michael Wrana, Diogo Barradas, N. Asokan |
Proc. Priv. Enhancing Technol. | 3 |
| 2024 | SeMalloc: Semantics-Informed Memory Allocator
Ruizhe Wang 0003, Meng Xu 0025, N. Asokan |
CCS | 3 |
| 2024 | S2malloc: Statistically Secure Allocator for Use-After-Free Protection and More
Ruizhe Wang 0003, Meng Xu 0025, N. Asokan |
DIMVA | 3 |
| 2024 | Attesting Distributional Properties of Training Data for Machine Learning
Vasisht Duddu, Anudeep Das, Nora Khayata, Hossein Yalame, Thomas Schneider 0003, N. Asokan |
ESORICS (1) | 6 |
| 2024 | A User-centered Security Evaluation of CopilotabstractCode generation tools driven by artificial intelligence have recently become more popular due to advancements in deep learning and natural language processing that have increased their capabilities. The proliferation of these tools may be a double-edged sword because while they can increase developer productivity by making it easier to write code, research has shown that they can also generate insecure code. In this paper, we perform a user-centered evaluation GitHub's Copilot to better understand its strengths and weaknesses with respect to code security. We conduct a user study where participants solve programming problems (with and without Copilot assistance) that have potentially vulnerable solutions. The main goal of the user study is to determine how the use of Copilot affects participants' security performance. In our set of participants (n=25), we find that access to Copilot accompanies a more secure solution when tackling harder problems. For the easier problem, we observe no effect of Copilot access on the security of solutions. We also observe no disproportionate impact of Copilot use on particular kinds of vulnerabilities. Our results indicate that there are potential security benefits to using Copilot, but more research is warranted on the effects of the use of code generation tools on technically complex problems with security requirements. Owura Asare, Meiyappan Nagappan, N. Asokan |
ICSE | 3 |
| 2024 | BliMe: Verifiably Secure Outsourced Computation with Hardware-Enforced Taint Tracking
Hossam ElAtali, Lachlan J. Gunn, Hans Liljestrand, N. Asokan |
NDSS | 4 |
| 2024 | SoK: Unintended Interactions among Machine Learning Defenses and RisksabstractMachine learning (ML) models cannot neglect risks to security, privacy, and fairness. Several defenses have been proposed to mitigate such risks. When a defense is effective in mitigating one risk, it may correspond to increased or decreased susceptibility to other risks. Existing research lacks an effective framework to recognize and explain these unintended interactions. We present such a framework, based on the conjecture that overfitting and memorization underlie unintended interactions. We survey existing literature on unintended interactions, accommodating them within our framework. We use our framework to conjecture two previously unexplored interactions, and empirically validate them. Vasisht Duddu, Sebastian Szyller, N. Asokan |
SP | 3 |
| 2024 | GrOVe: Ownership Verification of Graph Neural Networks using EmbeddingsabstractGraph neural networks (GNNs) have emerged as a state-of-the-art approach to model and draw inferences from large scale graph-structured data in various application settings such as social networking. The primary goal of a GNN is to learn an embedding for each graph node in a dataset that encodes both the node features and the local graph structure around the node.Prior work has shown that GNNs are prone to model extraction attacks. Model extraction attacks and defenses have been explored extensively in other non-graph settings. While detecting or preventing model extraction appears to be difficult, deterring them via effective ownership verification techniques offer a potential defense. In non-graph settings, fingerprinting models, or the data used to build them, have shown to be a promising approach toward ownership verification.We present GrOVe, a state-of-the-art GNN model fingerprinting scheme that, given a target model and a suspect model, can reliably determine if the suspect model was trained independently of the target model or if it is a surrogate of the target model obtained via model extraction. We show that GrOVe can distinguish between surrogate and independent models even when the independent model uses the same training dataset and architecture as the original target model.Using six benchmark datasets and three model architectures, we show that GrOVe consistently achieves low falsepositive and false-negative rates. We demonstrate that GrOVe is robust against known fingerprint evasion techniques while remaining computationally efficient. Asim Waheed, Vasisht Duddu, N. Asokan |
SP | 3 |
| 2024 | False Claims against Model Ownership Resolution
Jian Liu 0012, Rui Zhang 0118, Sebastian Szyller, Kui Ren 0001, N. Asokan |
USENIX Security Symposium | 5 |
| 2023 | Conflicting Interactions among Protection Mechanisms for Machine Learning ModelsabstractNowadays, systems based on machine learning (ML) are widely used in different domains. Given their popularity, ML models have become targets for various attacks. As a result, research at the intersection of security/privacy and ML has flourished. Typically such work has focused on individual types of security/privacy concerns and mitigations thereof. However, in real-life deployments, an ML model will need to be protected against several concerns simultaneously. A protection mechanism optimal for a specific security or privacy concern may interact negatively with mechanisms intended to address other concerns. Despite its practical relevance, the potential for such conflicts has not been studied adequately. In this work, we first provide a framework for analyzing such conflicting interactions. We then focus on systematically analyzing pairwise interactions between protection mechanisms for one concern, model and data ownership verification, with two other classes of ML protection mechanisms: differentially private training, and robustness against model evasion. We find that several pairwise interactions result in conflicts. We also explore potential approaches for avoiding such conflicts. First, we study the effect of hyperparameter relaxations, finding that there is no sweet spot balancing the performance of both protection mechanisms. Second, we explore whether modifying one type of protection mechanism (ownership verification) so as to decouple it from factors that may be impacted by a conflicting mechanism (differentially private training or robustness to model evasion) can avoid conflict. We show that this approach can indeed avoid the conflict between ownership verification mechanisms when combined with differentially private training, but has no effect on robustness to model evasion. We conclude by identifying the gaps in the landscape of studying interactions between other types of ML protection mechanisms. Sebastian Szyller, N. Asokan |
AAAI | 2 |
| 2023 | FLARE: Fingerprinting Deep Reinforcement Learning Agents using Universal Adversarial MasksabstractWe propose FLARE, the first fingerprinting mechanism to verify whether a suspected Deep Reinforcement Learning (DRL) policy is an illegitimate copy of another (victim) policy. We first show that it is possible to find non-transferable, universal adversarial masks, i.e., perturbations, to generate adversarial examples that can successfully transfer from a victim policy to its modified versions but not to independently trained policies. FLARE employs these masks as fingerprints to verify the true ownership of stolen DRL policies by measuring an action agreement value over states perturbed by such masks. Our empirical evaluations show that FLARE is effective (100% action agreement on stolen copies) and does not falsely accuse independent policies (no false positives). FLARE is also robust to model modification attacks and cannot be easily evaded by more informed adversaries without negatively impacting agent performance. We also show that not all universal adversarial masks are suitable candidates for fingerprints due to the inherent characteristics of DRL policies. The spatio-temporal dynamics of DRL problems and sequential decision-making process make characterizing the decision boundary of DRL policies more difficult, as well as searching for universal masks that capture the geometry of it. Buse G. A. Tekgul, N. Asokan |
ACSAC | 2 |
| 2023 | Model Stealing Attacks and Defenses: Where Are We Now?abstractThe success of deep learning in many application domains has been nothing short of dramatic. This has brought the spotlight onto security and privacy concerns with machine learning (ML). One such concern is the threat of model theft. I will discuss work on exploring the threat of model theft, especially in the form of “model extraction attacks” — when a model is made available to customers via an inference interface, a malicious customer can use repeated queries to this interface and use the information gained to construct a surrogate model. I will also discuss possible countermeasures, focusing on deterrence mechanisms that allow for model ownership resolution (MOR) based on watermarking or fingerprinting. In particular, I will discuss the robustness of MOR schemes. I will touch on the issue of conflicts that arise when protection mechanisms for multiple different threats need to be applied simultaneously to a given ML model, using MOR techniques as a case study. N. Asokan |
AsiaCCS | 1 |
| 2023 | Not All Data are Created Equal: Data and Pointer Prioritization for Scalable Protection Against Data-Oriented Attacks
Salman Ahmed 0001, Hans Liljestrand, Hani Jamjoom, Matthew Hicks, N. Asokan, Danfeng Yao |
USENIX Security Symposium | 5 |
| 2023 | Auditing Framework APIs via Inferred App-side Security Specifications
Parjanya Vyas, Asim Waheed, Yousra Aafer, N. Asokan |
USENIX Security Symposium | 4 |
| 2023 | Is GitHub's Copilot as bad as humans at introducing vulnerabilities in code?
Owura Asare, Meiyappan Nagappan, N. Asokan |
Empir. Softw. Eng. | 3 |
| 2022 | Real-Time Adversarial Perturbations Against Deep Reinforcement Learning Policies: Attacks and Defenses
Buse G. A. Tekgul, Shelly Wang, Samuel Marchal, N. Asokan |
ESORICS (3) | 4 |
| 2022 | Parallel and Asynchronous Smart Contract ExecutionabstractToday's blockchains suffer from low throughput and high latency, which impedes their widespread adoption of more complex applications like smart contracts. In this article, we propose a novel paradigm for smart contract execution. It distinguishes between consensus nodes and execution nodes: different groups of execution nodes can execute transactions in parallel; meanwhile, consensus nodes can asynchronously order transactions and process execution results. Moreover, it requires no coordination among execution nodes and can effectively prevent livelocks. We show two ways of applying this paradigm to blockchains. First, we show how we can make Ethereum support parallel and asynchronous contract executionwithout hard-forks. Then, we propose a new public, permissionless blockchain. Our benchmark shows that, with a fast consensus layer, it can provide a high throughput even for complex transactions like Cryptokitties gene mixing. It can also protect simple transactions from being starved by complex transactions. Jian Liu 0012, Peilun Li, Raymond Cheng 0001, N. Asokan, Dawn Song |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2021 | Investigating targeted espionage: Methods, findings, implicationsabstractThe Citizen Lab has been undertaking investigations into targeted espionage for well over a decade. This path-breaking research has uncovered widespread global harms and an alarming spread of authoritarian practices across borders connected to a burgeoning and widely abused commercial surveillance industry. In his keynote, Deibert explains the methods, findings and implications of the Citizen Lab's research for human rights and global security. Ron Deibert, N. Asokan, Thenusha Satsoruban |
ISTAS | 2 |
| 2021 | DAWN: Dynamic Adversarial Watermarking of Neural NetworksabstractTraining machine learning (ML) models is expensive in terms of computational power, amounts of labeled data and human expertise. Thus, ML models constitute business value for their owners. Embedding digital watermarks during model training allows a model owner to later identify their models in case of theft or misuse. However, model functionality can also be stolen via model extraction, where an adversary trains a surrogate model using results returned from a prediction API of the original model. Recent work has shown that model extraction is a realistic threat. Existing watermarking schemes are ineffective against model extraction since it is the adversary who trains the surrogate model. In this paper, we introduce DAWN (Dynamic Adversarial Watermarking of Neural Networks), the first approach to use watermarking to deter model extraction theft. Unlike prior watermarking schemes, DAWN does not impose changes to the training process but operates at the prediction API of the protected model, by dynamically changing the responses for a small subset of queries (e.g., 0.5%) from API clients. This set is a watermark that will be embedded in case a client uses its queries to train a surrogate model. We show that DAWN is resilient against two state-of-the-art model extraction attacks, effectively watermarking all extracted surrogate models, allowing model owners to reliably demonstrate ownership (with confidence greater than 1-2-64), incurring negligible loss of prediction accuracy (0.03-0.5%). Sebastian Szyller, Buse G. A. Tekgul, Samuel Marchal, N. Asokan |
ACM Multimedia | 4 |
| 2021 | WAFFLE: Watermarking in Federated LearningabstractFederated learning is a distributed learning technique where machine learning models are trained on client devices in which the local training data resides. The training is coordinated via a central server which is, typically, controlled by the intended owner of the resulting model. By avoiding the need to transport the training data to the central server, federated learning improves privacy and efficiency. But it raises the risk of model theft by clients because the resulting model is available on every client device. Even if the application software used for local training may attempt to prevent direct access to the model, a malicious client may bypass any such restrictions by reverse engineering the application software. Watermarking is a well-known deterrence method against model theft by providing the means for model owners to demonstrate ownership of their models. Several recent deep neural network (DNN) watermarking techniques use backdooring: training the models with additional mislabeled data. Backdooring requires full access to the training data and control of the training process. This is feasible when a single party trains the model in a centralized manner, but not in a federated learning setting where the training process and training data are distributed among several client devices. In this paper, we present WAFFLE, the first approach to watermark DNN models trained using federated learning. It introduces a retraining step at the server after each aggregation of local models into the global model. We show that WAFFLE efficiently embeds a resilient watermark into models incurring only negligible degradation in test accuracy (-0.17%), and does not require access to training data. We also introduce a novel technique to generate the backdoor used as a watermark. It outperforms prior techniques, imposing no communication, and low computational (+3.2%) overhead11The research report version of this paper is also available in https://arxiv.org/abs/2008.07298, and the code for reproducing our work can be found at https://github.com/ssg-research/WAFFLE. Buse G. A. Tekgul, Yuxi Xia, Samuel Marchal, N. Asokan |
SRDS | 4 |
| 2021 | PACStack: an Authenticated Call Stack
Hans Liljestrand, Thomas Nyman, Lachlan J. Gunn, Jan-Erik Ekberg, N. Asokan |
USENIX Security Symposium | 5 |
| 2021 | Exploitation Techniques for Data-oriented Attacks with Existing and Potential Defense ApproachesabstractData-oriented attacks manipulate non-control data to alter a program’s benign behavior without violating its control-flow integrity. It has been shown that such attacks can cause significant damage even in the presence of control-flow defense mechanisms. However, these threats have not been adequately addressed. In this survey article, we first map data-oriented exploits, including Data-Oriented Programming (DOP) and Block-Oriented Programming (BOP) attacks, to their assumptions/requirements and attack capabilities. Then, we compare known defenses against these attacks, in terms of approach, detection capabilities, overhead, and compatibility. It is generally believed that control flows may not be useful for data-oriented security. However, data-oriented attacks (especially DOP attacks) may generate side effects on control-flow behaviors in multiple dimensions (i.e., incompatible branch behaviors and frequency anomalies). We also characterize control-flow anomalies caused by data-oriented attacks. In the end, we discuss challenges for building deployable data-oriented defenses and open research questions. Long Cheng 0005, Salman Ahmed 0001, Hans Liljestrand, Thomas Nyman, Haipeng Cai, Trent Jaeger, N. Asokan, Danfeng Yao |
ACM Trans. Priv. Secur. | 7 |
| 2020 | Effective writing style transfer via combinatorial paraphrasingabstractAbstract Stylometry can be used to profile or deanonymize authors against their will based on writing style. Style transfer provides a defence. Current techniques typically use either encoder-decoder architectures or rule-based algorithms. Crucially, style transfer must reliably retain original semantic content to be actually deployable. We conduct a multifaceted evaluation of three state-of-the-art encoder-decoder style transfer techniques, and show that all fail at semantic retainment. In particular, they do not produce appropriate paraphrases, but only retain original content in the trivial case of exactly reproducing the text. To mitigate this problem we propose ParChoice: a technique based on thecombinatorial application of multiple paraphrasing algorithms. ParChoice strongly outperforms the encoder-decoder baselines in semantic retainment. Additionally, compared to baselines that achieve nonnegligible semantic retainment, ParChoice has superior style transfer performance. We also apply ParChoice to multi-author style imitation (not considered by prior work), where we achieve up to 75% imitation success among five authors. Furthermore, when compared to two state-of-the-art rule-based style transfer techniques, ParChoice has markedly better semantic retainment. Combining ParChoice with the best performing rulebased baseline (Mutant-X [34]) also reaches the highest style transfer success on the Brennan-Greenstadt and Extended-Brennan-Greenstadt corpora, with much less impact on original meaning than when using the rulebased baseline techniques alone. Finally, we highlight a critical problem that afflictsallcurrent style transfer techniques: the adversary can use the same technique for thwarting style transfer viaadversarial training. We show that adding randomness to style transfer helps to mitigate the effectiveness of adversarial training. Tommi Grondahl, N. Asokan |
Proc. Priv. Enhancing Technol. | 2 |
| 2019 | Hardware-assisted Trusted Execution Environments: Look Back, Look AheadabstractOver the last two decades, hardware-based isolated execution environments, commonly known as "trusted execution environments" or TEEs, have become widely deployed [1,2,3,4]. However, concerns about vulnerabilities (like the Foreshadow attacks [5]), and potential for abuse have been persistent and have recently become increasingly pronounced. In this talk, I will discuss the history of (mobile) TEEs [6], what motivated their design and large-scale deployment, and how they have evolved during the last two decades. I will then discuss some of their shortcomings and potential approaches for overcoming them. I will also briefly touch on other types of hardware security primitives that are being rolled out by processor manufacturers and the opportunities they offer for securing computing N. Asokan |
CCS | 1 |
| 2019 | Authenticated Call StackabstractShadow stacks are the go-to solution for perfect backward-edge control-flow integrity (CFI). Software shadow stacks trade off security for performance. Hardware-assisted shadow stacks are efficient and secure, but expensive to deploy. We present authenticated call stack (ACS), a novel mechanism for precise verification of return addresses using aggregated message authentication codes. We show how ACS can be realized using ARMv8.3-A pointer authentication, a new low-overhead mechanism for protecting pointer integrity. Our solution achieves security comparable to hardware-assisted shadow stacks, while incurring negligible performance overhead (< 0.5%) but requiring no additional hardware support. Hans Liljestrand, Thomas Nyman, Jan-Erik Ekberg, N. Asokan |
DAC | 4 |
| 2019 | HardScope: Hardening Embedded Systems Against Data-Oriented AttacksabstractMemory-unsafe programming languages like C and C++ leave many (embedded) systems vulnerable to attacks like control-flow hijacking. However, defenses against control-flow attacks, such as (fine-grained) randomization or control-flow integrity are in-effective against data-oriented attacks and more expressive Data-oriented Programming (DOP) attacks that bypass state-of-the-art defenses. Thomas Nyman, Ghada Dessouky, Shaza Zeitouni, Aaro Lehikoinen, Andrew Paverd, N. Asokan, Ahmad-Reza Sadeghi |
DAC | 6 |
| 2019 | PRADA: Protecting Against DNN Model Stealing AttacksabstractMachine learning (ML) applications are increasingly prevalent. Protecting the confidentiality of ML models becomes paramount for two reasons: (a) a model can be a business advantage to its owner, and (b) an adversary may use a stolen model to find transferable adversarial examples that can evade classification by the original model. Access to the model can be restricted to be only via well-defined prediction APIs. Nevertheless, prediction APIs still provide enough information to allow an adversary to mount model extraction attacks by sending repeated queries via the prediction API. In this paper, we describe new model extraction attacks using novel approaches for generating synthetic queries, and optimizing training hyperparameters. Our attacks outperform state-of-the-art model extraction in terms of transferability of both targeted and non-targeted adversarial examples (up to +29-44 percentage points, pp), and prediction accuracy (up to +46 pp) on two datasets. We provide take-aways on how to perform effective model extraction attacks. We then propose PRADA, the first step towards generic and effective detection of DNN model extraction attacks. It analyzes the distribution of consecutive API queries and raises an alarm when this distribution deviates from benign behavior. We show that PRADA can detect all prior model extraction attacks with no false positives. Mika Juuti, Sebastian Szyller, Samuel Marchal, N. Asokan |
EuroS&P | 4 |
| 2019 | DÏoT: A Federated Self-learning Anomaly Detection System for IoTabstractIoT devices are increasingly deployed in daily life. Many of these devices are, however, vulnerable due to insecure design, implementation, and configuration. As a result, many networks already have vulnerable IoT devices that are easy to compromise. This has led to a new category of malware specifically targeting IoT devices. However, existing intrusion detection techniques are not effective in detecting compromised IoT devices given the massive scale of the problem in terms of the number of different types of devices and manufacturers involved. In this paper, we present DÏoT, an autonomous self-learning distributed system for detecting compromised IoT devices. DÏoT builds effectively on device-type-specific communication profiles without human intervention nor labeled data that are subsequently used to detect anomalous deviations in devices' communication behavior, potentially caused by malicious adversaries. DÏoT utilizes a federated learning approach for aggregating behavior profiles efficiently. To the best of our knowledge, it is the first system to employ a federated learning approach to anomaly-detection-based intrusion detection. Consequently, DÏoT can cope with emerging new and unknown attacks. We systematically and extensively evaluated more than 30 off-the-shelf IoT devices over a long term and show that DÏoT is highly effective (95.6% detection rate) and fast (257 ms) at detecting devices compromised by, for instance, the infamous Mirai malware. DÏoT reported no false alarms when evaluated in a real-world smart home deployment setting. Thien Duc Nguyen, Samuel Marchal, Markus Miettinen, Hossein Fereidooni, N. Asokan, Ahmad-Reza Sadeghi |
ICDCS | 5 |
| 2019 | DoubleEcho: Mitigating Context-Manipulation Attacks in Copresence VerificationabstractCopresence verification based on context can improve usability and strengthen security of many authentication and access control systems. By sensing and comparing their surroundings, two or more devices can tell whether they are copresent and use this information to make access control decisions. To the best of our knowledge, all context-based copresence verification mechanisms to date are susceptible to context-manipulation attacks. In such attacks, a distributed adversary replicates the same context at the (different) locations of the victim devices, and induces them to believe that they are copresent. In this paper we propose DoubleEcho, a context-based copresence verification technique that leverages acoustic Room Impulse Response (RIR) to mitigate context-manipulation attacks. In DoubleEcho, one device emits a wide-band audible chirp and all participating devices record reflections of the chirp from the surrounding environment. Since RIR is, by its very nature, dependent on the physical surroundings, it constitutes a unique location signature that is hard for an adversary to replicate. We evaluate DoubleEcho by collecting RIR data with various mobile devices and in a range of different locations. We show that DoubleEcho mitigates context-manipulation attacks whereas all other approaches to date are entirely vulnerable to such attacks. DoubleEcho detects copresence (or lack thereof) in roughly 2 seconds and works on commodity devices. Hien Thi Thu Truong, Juhani Toivonen, Thien Duc Nguyen, Claudio Soriente, Sasu Tarkoma, N. Asokan |
PerCom | 6 |
| 2019 | Making Speculative BFT Resilient with Trusted Monotonic CountersabstractConsensus mechanisms used by popular distributed ledgers are highly scalable but notoriously inefficient. Byzantine fault tolerance (BFT) protocols are efficient but far less scalable. Speculative BFT protocols such as Zyzzyva and Zyzzyva5 are efficient and scalable but require a trade-off: Zyzzyva requires only 3f + 1 replicas to tolerate f faults, but even a single slow replica will make Zyzzyva fall back to more expensive non-speculative operation. Zyzzyva5 does not require a non-speculative fallback, but requires 5f + 1 replicas in order to tolerate f faults. BFT variants using hardware-assisted trusted components can tolerate a greater proportion of faults, but require that every replica have this hardware. We present SACZyzzyva, addressing these concerns: resilience to slow replicas and requiring only 3f + 1 replicas, with only one replica needing an active monotonic counter at any given time. We experimentally evaluate our protocols, demonstrating low latency and high scalability. We prove that SACZyzzyva is optimally robust and that trusted components cannot increase fault tolerance unless they are present in at least two-thirds of replicas. Lachlan J. Gunn, Jian Liu 0012, Bruno Vavala, N. Asokan |
SRDS | 4 |
| 2019 | PAC it up: Towards Pointer Integrity using ARM Pointer Authentication
Hans Liljestrand, Thomas Nyman, Carlos Chinea Perez, Jan-Erik Ekberg, N. Asokan |
USENIX Security Symposium | 6 |
| 2019 | AuDI: Toward Autonomous IoT Device-Type Identification Using Periodic CommunicationabstractIoT devices are being widely deployed. But the huge variance among them in the level of security and requirements for network resources makes it unfeasible to manage IoT networks using a common generic policy. One solution to this challenge is to define policies for classes of devices based on device type. In this paper, we present AuDI, a system for quickly and effectively identifying the type of a device in an IoT network by analyzing their network communications. AuDI models the periodic communication traffic of IoT devices using an unsupervised learning method to perform identification. In contrast to prior work, AuDI operates autonomously after initial setup, learning, without human intervention nor labeled data, to identify previously unseen device types. AuDI can identify the type of a device in any mode of operation or stage of lifecycle of the device. Via systematic experiments using 33 off-the-shelf IoT devices, we show that AuDI is effective (98.2% accuracy). Samuel Marchal, Markus Miettinen, Thien Duc Nguyen, Ahmad-Reza Sadeghi, N. Asokan |
IEEE J. Sel. Areas Commun. | 5 |
| 2019 | Circumventing Cryptographic Deniability with Remote AttestationabstractAbstract Deniable messaging protocols allow two parties to have ‘off-the-record’ conversations without leaving any record that can convince external verifiers about what either of them said during the conversation. Recent events like the Podesta email dump underscore the importance of deniable messaging to politicians, whistleblowers, dissidents and many others. Consequently, messaging protocols like Signal and OTR are designed with cryptographic mechanisms to ensure deniable communication, irrespective of whether the communications partner is trusted. Many commodity devices today support hardware-assisted remote attestation which can be used to convince a remote verifier of some property locally observed on the device. We show how an adversary can use remote attestation to undetectably generate a non-repudiable transcript from any deniable protocol (including messaging protocols) providing sender authentication, proving to skeptical verifiers what was said. We describe a concrete implementation of the technique using the Signal messaging protocol. We then show how to design protocols that are deniable even against an adversary capable of attestation, and in particular how attestation itself can be used to restore deniability by thwarting realistic classes of adversary. Lachlan J. Gunn, Ricardo Vieitez Parra, N. Asokan |
Proc. Priv. Enhancing Technol. | 3 |
| 2019 | SoK: Modular and Efficient Private Decision Tree EvaluationabstractAbstract Decision trees and random forests are widely used classifiers in machine learning. Service providers often host classification models in a cloud service and provide an interface for clients to use the model remotely. While the model is sensitive information of the server, the input query and prediction results are sensitive information of the client. This motivates the need for private decision tree evaluation, where the service provider does not learn the client’s input and the client does not learn the model except for its size and the result. In this work, we identify the three phases of private decision tree evaluation protocols: feature selection, comparison, and path evaluation. We systematize constant-round protocols for each of these phases to identify the best available instantiations using the two main paradigms for secure computation: garbling techniques and homomorphic encryption. There is a natural tradeoff between runtime and communication considering these two paradigms: garbling techniques use fast symmetric-key operations but require a large amount of communication, while homomorphic encryption is computationally heavy but requires little communication. Our contributions are as follows: Firstly, we systematically review and analyse state-of-the-art protocols for the three phases of private decision tree evaluation. Our methodology allows us to identify novel combinations of these protocols that provide better tradeoffs than existing protocols. Thereafter, we empirically evaluate all combinations of these protocols by providing communication and runtime measures, and provide recommendations based on the identified concrete tradeoffs. Ágnes Kiss, Masoud Naderpour, Jian Liu 0012, N. Asokan, Thomas Schneider 0003 |
Proc. Priv. Enhancing Technol. | 4 |
| 2019 | Scalable Byzantine Consensus via Hardware-Assisted Secret SharingabstractThe surging interest in blockchain technology has revitalized the search for effective Byzantine consensus schemes. In particular, the blockchain community has been looking for ways to effectively integrate traditional Byzantine fault-tolerant (BFT) protocols into a blockchain consensus layer allowing various financial institutions to securely agree on the order of transactions. However, existing BFT protocols can only scale to tens of nodes due to their$O(n^2)$message complexity. In this paper, we propose FastBFT, a fast and scalable BFT protocol. At the heart of FastBFT is a novel message aggregation technique that combines hardware-based trusted execution environments (TEEs) with lightweight secret sharing. Combining this technique with several other optimizations (i.e., optimistic execution, tree topology and failure detection), FastBFT achieves low latency and high throughput even for large scale networks. Via systematic analysis and experiments, we demonstrate that FastBFT has better scalability and performance than previous BFT protocols. Jian Liu 0012, Wenting Li 0001, Ghassan Karame, N. Asokan |
IEEE Trans. Computers | 4 |
| 2019 | Sensor-Based Proximity Detection in the Face of Active AdversariesabstractContext-centric sensor-based proximity detection (or, contextual co-presence detection) is a promising approach to defend against relay attacks in many mobile authentication systems, especially against unattended terminals (such as cars parked in unmonitored parking lots, remote gas station pumps, or stolen laptops). Prior work demonstrated the effectiveness of a variety of contextual sensor modalities for this purpose, including audio-radio environment (ambient audio, Wi-Fi, Bluetooth, and GPS, and combinations thereof) and physical environment (temperature, humidity, gas, and altitude, and combinations thereof). In this paper, we present a systematic assessment of such co-presence detection in the presence of a strong, context-manipulating attacker against unattended terminals. First, we show that it is feasible to manipulate, consistently control, and stabilize the readings of different acoustic and physical environment sensors (and even multiple sensors simultaneously) using low-cost, off-the-shelf equipment. Specifically, we show that it is possible to control the temperature using a home-grade hair dryer, affect the gas readings using a smoking cigarette, impact the altitude/pressure with a simple air compressor, or relay audio signals recorded at one end to the other thereby causing both sides to perceive a very similar acoustic environment. Second, based on these capabilities and the strengthened threat model, we show that an attacker who can manipulate the context gains a significant advantage in defeating contextual co-presence detection. For systems that use multiple sensors, we investigate two sensor fusion approaches based on machine learning classification techniques-features-fusion and decisions-fusion, and show that both are vulnerable to context manipulation attacks but the latter approach can be more resistant in some cases. We further consider other defensive approaches that may be used to reduce the impact of even such a strong context-manipulating attacker. Our work represents the first concrete step towards analyzing, extending, and systematizing prior work on contextual co-presence detection under a stronger, but realistic adversarial model. Babins Shrestha, Nitesh Saxena, Hien Thi Thu Truong, N. Asokan |
IEEE Trans. Mob. Comput. | 4 |
| 2018 | Keys in the Clouds: Auditable Multi-device Access to Cryptographic CredentialsabstractPersonal cryptographic keys are the foundation of many secure services, but storing these keys securely is a challenge, especially if they are used from multiple devices. Storing keys in a centralized location, like an Internet-accessible server, raises serious security concerns (e.g. server compromise). Hardware-based Trusted Execution Environments (TEEs) are a well-known solution for protecting sensitive data in untrusted environments, and are now becoming available on commodity server platforms. Arseny Kurnikov, Andrew Paverd, Mohammad Mannan, N. Asokan |
ARES | 4 |
| 2018 | Secure Deduplication of Encrypted Data: Refined Model and New Constructions
Jian Liu 0012, Yong Li 0021, N. Asokan |
CT-RSA | 4 |
| 2018 | Revisiting context-based authentication in IoTabstractThe emergence of IoT poses new challenges towards solutions for authenticating numerous very heterogeneous IoT devices to their respective trust domains. Using passwords or pre-defined keys have drawbacks that limit their use in IoT scenarios. Recent works propose to use contextual information about ambient physical properties of devices' surroundings as a shared secret to mutually authenticate devices that are co-located, e.g., the same room. In this paper, we analyze these context-based authentication solutions with regard to their security and requirements on context quality. We quantify their achievable security based on empirical real-world data from context measurements in typical IoT environments. Markus Miettinen, Thien Duc Nguyen, Ahmad-Reza Sadeghi, N. Asokan |
DAC | 4 |
| 2018 | Migrating SGX Enclaves with Persistent StateabstractHardware-supported security mechanisms like Intel Software Guard Extensions (SGX) provide strong security guarantees, which are particularly relevant in cloud settings. However, their reliance on physical hardware conflicts with cloud practices, like migration of VMs between physical platforms. For instance, the SGX trusted execution environment (enclave) is bound to a single physical CPU. Although prior work has proposed an effective mechanism to migrate an enclave's data memory, it overlooks the migration of persistent state, including sealed data and monotonic counters; the former risks data loss whilst the latter undermines the SGX security guarantees. We show how this can be exploited to mount attacks, and then propose an improved enclave migration approach guaranteeing the consistency of persistent state. Our software-only approach enables migratable sealed data and monotonic counters, maintains all SGX security guarantees, minimizes developer effort, and incurs negligible performance overhead. Fritz Alder, Arseny Kurnikov, Andrew Paverd, N. Asokan |
DSN | 4 |
| 2018 | Stay On-Topic: Generating Context-Specific Fake Restaurant Reviews
Mika Juuti, Tatsuya Mori 0003, N. Asokan |
ESORICS (1) | 4 |
| 2018 | Get in Line: Ongoing Co-presence Verification of a Vehicle Formation Based on Driving TrajectoriesabstractIntelligent transportation systems and the advent of smart cities have created a renewed research interest in vehicular networks (VANET). These ad-hoc networks are the key technology for new collaborative approaches to increase the efficiency and safety of our roads. In effect, city-scale field trials are being conducted by major high-tech companies to explore the capabilities and limitations of vehicle-to-infrastructure and vehicle-to-vehicle communication. Initial advances have led to safety enhancing applications like the electronic emergency brake light, cooperative collision avoidance and cooperative adaptive cruise control. In IEEE standard 1609.2, security measures to guarantee the integrity and authenticity of VANET messages are specified. However, physical properties like spatial proximity and driving direction are not considered. These become notably important when vehicles make decisions that concern the safety of users for example to avoid a collision. We propose a novel approach to verify the ongoing copresence of two vehicles. Our method is based on the observation that the trajectory through a road network can be used to uniquely define a vehicle's location as well as its driving direction. Our system provides a protocol to authenticate VANET messages for a group of vehicles driving in succession and to de-authenticate vehicles that have left the formation. To demonstrate the feasibility of trajectories as proof for co-presence, we implemented a smartphone application and conducted driving experiments under real-world conditions. We analyze the road network of several major cities from different continents to show the generalizability of our approach. Additionally, we systematically evaluate the security properties of our system by performing city-scale simulations under realistic conditions. Christian Vaas, Mika Juuti, N. Asokan, Ivan Martinovic |
EuroS&P | 3 |
| 2018 | SafeKeeper: Protecting Web Passwords using Trusted Execution EnvironmentsabstractPasswords are by far the most widely-used mechanism for authenticating users on the web, out-performing all competing solutions in terms of deployability (e.g. cost and compatibility). However, two critical security concerns are phishing and theft of password databases. These are exacerbated by users» tendency to reuse passwords across different services. Current solutions typically address only one of the two concerns, and do not protect passwords against rogue servers. Furthermore, they do not provide any verifiable evidence of their (server-side) adoption to users, and they face deployability challenges in terms of ease-of-use for end users, and/or costs for service providers. We present SafeKeeper, a novel and comprehensive solution to ensure secrecy of passwords in web authentication systems. Unlike previous approaches, SafeKeeper protects users» passwords against very strong adversaries, including external phishers as well as corrupted (rogue) servers. It is relatively inexpensive to deploy as it (i) uses widely available hardware-based trusted execution environments like Intel SGX, (ii) requires only minimal changes for integration into popular web platforms like WordPress, and (iii) imposes negligible performance overhead. We discuss several challenges in designing and implementing such a system, and how we overcome them. Via an 86-participant user study, systematic analysis and experiments, we show the usability, security and deployability of SafeKeeper, which is available as open-source. Klaudia Krawiecka, Arseny Kurnikov, Andrew Paverd, Mohammad Mannan, N. Asokan |
WWW | 5 |
| 2018 | Ad-hoc key agreement: A brief history and the challenges ahead
Markus Miettinen, N. Asokan |
Comput. Commun. | 2 |
| 2018 | Toward Linux kernel memory safetyabstractSummary The security of billions of devices worldwide depends on the security and robustness of the mainline Linux kernel. However, the increasing number of kernel‐specific vulnerabilities, especially memory safety vulnerabilities, shows that the kernel is a popular and practically exploitable target. Two major causes of memory safety vulnerabilities are reference counter overflows (temporal memory errors) and lack of pointer bounds checking (spatial memory errors). To succeed in practice, security mechanisms for critical systems like the Linux kernel must also consider performance and deployability as critical design objectives. We present and systematically analyze two such mechanisms for improving memory safety in the Linux kernel, ie, (1) an overflow‐resistant reference counter data structure designed to securely accommodate typical reference counter usage in kernel source code and (2) runtime pointer bounds checking using Intel memory protection extension in the kernel. We have implemented both mechanisms and we analyze their security, performance, and deployability. We also reflect on our experience of engaging with Linux kernel developers and successfully integrating the new reference counter data structure into the mainline Linux kernel. Elena Reshetova, Hans Liljestrand, Andrew Paverd, N. Asokan |
Softw. Pract. Exp. | 4 |
| 2018 | ASSURED: Architecture for Secure Software Update of Realistic Embedded DevicesabstractSecure firmware update is an important stage in the Internet of Things (IoT) device life-cycle. Prior techniques, designed for other computational settings, are not readily suitable for IoT devices, since they do not consider idiosyncrasies of a realistic large-scale IoT deployment. This motivates our design of architecture for secure software update of realistic embedded devices (ASSURED), a secure and scalable update framework for IoT. ASSURED includes all stakeholders in a typical IoT update ecosystem, while providing end-to-end security between manufacturers and devices. To demonstrate its feasibility and practicality, ASSURED is instantiated and experimentally evaluated on two commodity hardware platforms. Results show that ASSURED is considerably faster than current update mechanisms in realistic settings. N. Asokan, Thomas Nyman, Norrathep Rattanavipanon, Ahmad-Reza Sadeghi, Gene Tsudik |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2017 | Oblivious Neural Network Predictions via MiniONN TransformationsabstractMachine learning models hosted in a cloud service are increasingly popular but risk privacy: clients sending prediction requests to the service need to disclose potentially sensitive information. In this paper, we explore the problem of privacy-preserving predictions: after each prediction, the server learns nothing about clients' input and clients learn nothing about the model. Jian Liu 0012, Mika Juuti, N. Asokan |
CCS | 4 |
| 2017 | The Circle Game: Scalable Private Membership Test Using Trusted HardwareabstractMalware checking is changing from being a local service to a cloud-assisted one where users' devices query a cloud server, which hosts a dictionary of malware signatures, to check if particular applications are potentially malware. Whilst such an architecture gains all the benefits of cloud-based services, it opens up a major privacy concern since the cloud service can infer personal traits of the users based on the lists of applications queried by their devices. Private membership test (PMT) schemes can remove this privacy concern. However, known PMT schemes do not scale well to a large number of simultaneous users and high query arrival rates. We propose a simple PMT approach using a carousel: circling the entire dictionary through trusted hardware on the cloud server. Users communicate with the trusted hardware via secure channels. We show how the carousel approach, using different data structures to represent the dictionary, can be realized on two different commercial hardware security architectures (ARM TrustZone and Intel SGX). We highlight subtle aspects of securely implementing seemingly simple PMT schemes on these architectures. Through extensive experimental analysis, we show that for the malware checking scenario our carousel approach surprisingly outperforms Path ORAM on the same hardware by supporting a much higher query arrival rate while guaranteeing acceptable response latency for individual queries. Sandeep Tamrakar, Jian Liu 0012, Andrew Paverd, Jan-Erik Ekberg, Benny Pinkas, N. Asokan |
AsiaCCS | 6 |
| 2017 | LO-FAT: Low-Overhead Control Flow ATtestation in HardwareabstractAttacks targeting software on embedded systems are becoming increasingly prevalent. Remote attestation is a mechanism that allows establishing trust in embedded devices. However, existing attestation schemes are either static and cannot detect control-flow attacks, or require instrumentation of software incurring high performance overheads. To overcome these limitations, we present LO-FAT, the first practical hardware-based approach to control-flow attestation. By leveraging existing processor hardware features and commonly-used IP blocks, our approach enables efficient control-flow attestation without requiring software instrumentation. We show that our proof-of-concept implementation based on a RISC-V SoC incurs no processor stalls and requires reasonable area overhead. Ghada Dessouky, Shaza Zeitouni, Thomas Nyman, Andrew Paverd, Lucas Davi, Patrick Koeberl, N. Asokan, Ahmad-Reza Sadeghi |
DAC | 7 |
| 2017 | IoT SENTINEL: Automated Device-Type Identification for Security Enforcement in IoTabstractWith the rapid growth of the Internet-of-Things (IoT), concerns about the security of IoT devices have become prominent. Several vendors are producing IP-connected devices for home and small office networks that often suffer from flawed security designs and implementations. They also tend to lack mechanisms for firmware updates or patches that can help eliminate security vulnerabilities. Securing networks where the presence of such vulnerable devices is given, requires a brownfield approach: applying necessary protection measures within the network so that potentially vulnerable devices can coexist without endangering the security of other devices in the same network. In this paper, we present IoT Sentinel, a system capable of automatically identifying the types of devices being connected to an IoT network and enabling enforcement of rules for constraining the communications of vulnerable devices so as to minimize damage resulting from their compromise. We show that IoT Sentinel is effective in identifying device types and has minimal performance overhead. Markus Miettinen, Samuel Marchal, Ibbad Hafeez, N. Asokan, Ahmad-Reza Sadeghi, Sasu Tarkoma |
ICDCS | 4 |
| 2017 | IoT Sentinel Demo: Automated Device-Type Identification for Security Enforcement in IoTabstractThe emergence of numerous new manufacturers producing devices for the Internet-of-Things (IoT) has given rise to new security concerns. Many IoT devices exhibit security flaws making them vulnerable for attacks and manufacturers have difficulties in providing appropriate security patches to their products in a timely and user-friendly manner. In this paper, we present our implementation of IoT Sentinel, which is a system aimed at protecting the user's network from vulnerable IoT devices. IoT Sentinel automatically identifies vulnerable devices when they are first introduced to the network and enforces appropriate traffic filtering rules to protect other devices from the threats originating from the vulnerable devices. Markus Miettinen, Samuel Marchal, Ibbad Hafeez, Tommaso Frassetto, N. Asokan, Ahmad-Reza Sadeghi, Sasu Tarkoma |
ICDCS | 5 |
| 2017 | Profiling Users by Modeling Web TransactionsabstractUsers of electronic devices, e.g., laptop, smartphone, etc. have characteristic behaviors while surfing the Web. Profiling this behavior can help identify the person using a given device. In this paper, we introduce a technique to profile users based on their web transactions. We compute several features extracted from a sequence of web transactions and use them with one-class classification techniques to profile a user. We assess the efficacy and speed of our method at differentiating 25 synthetic users on a benchmark dataset (from a major security vendor) representing 6 months of web traffic monitoring from a small enterprise network. Radek Tomsu, Samuel Marchal, N. Asokan |
ICDCS | 3 |
| 2017 | SELint: An SEAndroid Policy Analysis ToolabstractPeer reviewed Elena Reshetova, Filippo Bonazzi, N. Asokan |
ICISSP | 3 |
| 2017 | Randomization Can't Stop BPF JIT Spray
Elena Reshetova, Filippo Bonazzi, N. Asokan |
NSS | 3 |
| 2017 | CFI CaRE: Hardware-Supported Call and Return Enforcement for Commercial Microcontrollers
Thomas Nyman, Jan-Erik Ekberg, Lucas Davi, N. Asokan |
RAID | 4 |
| 2017 | Implementing Prover-Side Proximity Verification for Strengthening Transparent AuthenticationabstractTransparent authentication schemes based on proximity verification over a wireless channel are susceptible to relay attacks. In recent literature several countermeasures have been proposed. However these come with drawbacks in terms of usability and deployability. In this demo, we show a prototype implementation of STASH, a scheme for securing transparent authentication schemes using prover-side proximity verification, presented at SECON 2017. Mika Juuti, Christian Vaas, Hans Liljestrand, Ivo Sluganovic, N. Asokan, Ivan Martinovic |
SECON | 5 |
| 2017 | STASH: Securing Transparent Authentication Schemes Using Prover-Side Proximity VerificationabstractTransparent authentication (TA) schemes are those in which a user's prover device authenticates him to a verifier without requiring explicit user interaction. By doing so, those schemes promise high usability and security simultaneously. Most TA implementations rely on the received signal strength as an indicator of the proximity of a user device (prover). However, such implicit proximity verification is not secure against an adversary who can relay messages over a larger distance. In this paper, we propose a novel approach for thwarting relay attacks on TA schemes: the prover permits access to authentication credentials only if it can confirm that it is near the verifier. We present STASH, a system for relay-resilient transparent authentication in which the prover does proximity verification by comparing its approach trajectory towards the intended verifier, with known authorized reference trajectories. Trajectories are measured using low-cost sensors commonly available on personal devices. By analyzing empirical data, collected using a STASH prototype, we demonstrate the security of STASH against a class of adversaries and its ease-of-use. STASH is efficient and can be easily integrated to complement existing TA schemes. Mika Juuti, Christian Vaas, Ivo Sluganovic, Hans Liljestrand, N. Asokan, Ivan Martinovic |
SECON | 5 |
| 2017 | Private Set Intersection for Unequal Set Sizes with Mobile ApplicationsabstractAbstract Private set intersection (PSI) is a cryptographic technique that is applicable to many privacy-sensitive scenarios. For decades, researchers have been focusing on improving its efficiency in both communication and computation. However, most of the existing solutions are inefficient for an unequal number of inputs, which is common in conventional client-server settings. In this paper, we analyze and optimize the efficiency of existing PSI protocols to support precomputation so that they can efficiently deal with such input sets. We transform four existing PSI protocols into the precomputation form such that in the setup phase the communication is linear only in the size of the larger input set, while in the online phase the communication is linear in the size of the smaller input set. We implement all four protocols and run experiments between two PCs and between a PC and a smartphone and give a systematic comparison of their performance. Our experiments show that a protocol based on securely evaluating a garbled AES circuit achieves the fastest setup time by several orders of magnitudes, and the fastest online time in the PC setting where AES-NI acceleration is available. In the mobile setting, the fastest online time is achieved by a protocol based on the Diffie-Hellman assumption. Ágnes Kiss, Jian Liu 0012, Thomas Schneider 0003, N. Asokan, Benny Pinkas |
Proc. Priv. Enhancing Technol. | 4 |
| 2017 | Off-the-Hook: An Efficient and Usable Client-Side Phishing Prevention ApplicationabstractPhishing is a major problem on the Web. Despite the significant attention it has received over the years, there has been no definitive solution. While the state-of-the-art solutions have reasonably good performance, they suffer from several drawbacks including potential to compromise user privacy, difficulty of detecting phishing websites whose content change dynamically, and reliance on features that are too dependent on the training data. To address these limitations we present a new approach for detecting phishing webpages in real-time as they are visited by a browser. It relies on modeling inherent phisher limitations stemming from the constraints they face while building a webpage. Consequently, the implementation of our approach, Off-the-Hook, exhibits several notable properties including high accuracy, brand-independence and good language-independence, speed of decision, resilience to dynamic phish and resilience to evolution in phishing techniques. Off-the-Hook is implemented as a fully-client-side browser add-on, which preserves user privacy. In addition, Off-the-Hook identifies the target website that a phishing webpage is attempting to mimic and includes this target in its warning. We evaluated Off-the-Hook in two different user studies. Our results show that users prefer Off-the-Hook warnings to Firefox warnings. Samuel Marchal, Giovanni Armano, Tommi Grondahl, Kalle Saari, Nidhi Singh 0001, N. Asokan |
IEEE Trans. Computers | 6 |
| 2016 | C-FLAT: Control-Flow Attestation for Embedded Systems SoftwareabstractRemote attestation is a crucial security service particularly relevant to increasingly popular IoT (and other embedded) devices. It allows a trusted party (verifier) to learn the state of a remote, and potentially malware-infected, device (prover). Most existing approaches are static in nature and only check whether benign software is initially loaded on the prover. However, they are vulnerable to runtime attacks that hijack the application's control or data flow, e.g., via return-oriented programming or data-oriented exploits. As a concrete step towards more comprehensive runtime remote attestation, we present the design and implementation of Control-FLow ATtestation (C-FLAT) that enables remote attestation of an application's control-flow path, without requiring the source code. We describe a full prototype implementation of C-FLAT on Raspberry Pi using its ARM TrustZone hardware security extensions. We evaluate C-FLAT's performance using a real-world embedded (cyber-physical) application, and demonstrate its efficacy against control-flow hijacking attacks. Tigist Abera, N. Asokan, Lucas Davi, Jan-Erik Ekberg, Thomas Nyman, Andrew Paverd, Ahmad-Reza Sadeghi, Gene Tsudik |
CCS | 2 |
| 2016 | Invited - Things, trouble, trust: on building trust in IoT systemsabstractThe emerging and much-touted Internet of Things (IoT) presents a variety of security and privacy challenges. Prominent among them is the establishment of trust in remote IoT devices, which is typically attained via remote attestation, a distinct security service that aims to ascertain the current state of a potentially compromised remote device. Remote attestation ranges from relatively heavy-weight secure hardware-based techniques, to light-weight software-based ones, and also includes approaches that blend software (e.g., control-flow integrity) and hardware features (e.g., PUFs). In this paper, we survey the landscape of state-of-the-art attestation techniques from the IoT device perspective and argue that most of them have a role to play in IoT trust establishment. Tigist Abera, N. Asokan, Lucas Davi, Farinaz Koushanfar, Andrew Paverd, Ahmad-Reza Sadeghi, Gene Tsudik |
DAC | 2 |
| 2016 | Real-Time Client-Side Phishing Prevention Add-OnabstractSince existing solutions for steering users away from phishing websites are typically server-based, they have several drawbacks: they compromise user privacy, are not robust against adaptive attackers who serve different content at different times, and do not provide any guidance to users after flagging a website as a phish. To address these limitations, we present a new phishing prevention system implementing a fast and effective phishing detection technique we developed recently [1]. It is implemented as a client-side application and a browser add-on. It uses information extracted from website visited by the user to detect if it is a phish and warn the user. It also determines the target of the phish and offers to redirect the user there. Giovanni Armano, Samuel Marchal, N. Asokan |
ICDCS | 3 |
| 2016 | Know Your Phish: Novel Techniques for Detecting Phishing Sites and Their TargetsabstractPhishing is a major problem on the Web. Despite the significant attention it has received over the years, there has been no definitive solution. While the state-of-the-art solutions have reasonably good performance, they require a large amount of training data and are not adept at detecting phishing attacks against new targets. In this paper, we begin with two core observations: (a) although phishers try to make a phishing webpage look similar to its target, they do not have unlimited freedom in structuring the phishing webpage, and (b) a webpage can be characterized by a small set of key terms, how these key terms are used in different parts of a webpage is different in the case of legitimate and phishing webpages. Based on these observations, we develop a phishing detection system with several notable properties: it requires very little training data, scales well to much larger test data, is language-independent, fast, resilient to adaptive attacks and implemented entirely on client-side. In addition, we developed a target identification component that can identify the target website that a phishing webpage is attempting to mimic. The target detection component is faster than previously reported systems and can help minimize false positives in our phishing detection system. Samuel Marchal, Kalle Saari, Nidhi Singh 0001, N. Asokan |
ICDCS | 4 |
| 2016 | Characterizing SEAndroid Policies in the WildabstractStarting from the 5.0 Lollipop release all Android processes must be run inside confined SEAndroid access control domains. As a result, Android device manufacturers were compelled to develop SEAndroid expertise in order to create policies for their device-specific components. In this paper we analyse SEAndroid policies from a number of 5.0 Lollipop devices on the market, and identify patterns of common problems we found. We also suggest some practical tools that can improve policy design and analysis. We implemented the first of such tools, SEAL. Elena Reshetova, Filippo Bonazzi, Thomas Nyman, Ravishankar Borgaonkar, N. Asokan |
ICISSP | 5 |
| 2016 | Pitfalls in Designing Zero-Effort Deauthentication: Opportunistic Human Observation Attacks
Otto Huhta, Swapnil Udar, Mika Juuti, Prakash Shrestha, Nitesh Saxena, N. Asokan |
NDSS | 6 |
| 2016 | Practical Attacks Against Privacy and Availability in 4G/LTE Mobile Communication Systems
Altaf Shaik, Jean-Pierre Seifert, Ravishankar Borgaonkar, N. Asokan, Valtteri Niemi |
NDSS | 4 |
| 2016 | POSTER: Friend or Foe? Context Authentication for Trust Domain Separation in IoT EnvironmentsabstractNo abstract available. Markus Miettinen, Jialin Huang, Thien Duc Nguyen, N. Asokan, Ahmad-Reza Sadeghi |
WISEC | 4 |
| 2016 | ABAKA: A novel attribute-based k-anonymous collaborative solution for LBSs
Tooska Dargahi, Moreno Ambrosin, Mauro Conti, N. Asokan |
Comput. Commun. | 4 |
| 2015 | SEDA: Scalable Embedded Device AttestationabstractToday, large numbers of smart interconnected devices provide safety and security critical services for energy grids, industrial control systems, gas and oil search robots, home/office automation, transportation, and critical infrastructure. These devices often operate in swarms -- large, dynamic, and self-organizing networks. Software integrity verification of device swarms is necessary to ensure their correct and safe operation as well as to protect them against attacks. However, current device attestation schemes assume a single prover device and do not scale to swarms. We present SEDA, the first attestation scheme for device swarms. We introduce a formal security model for swarm attestation and show security of our approach in this model. We demonstrate two proof-of-concept implementations based on two recent (remote) attestation architectures for embedded systems, including an Intel research platform. We assess performance of SEDA based on these implementations and simulations of large swarms. SEDA can efficiently attest swarms with dynamic and static topologies common in automotive, avionic, industrial control and critical infrastructures settings. N. Asokan, Ferdinand Brasser, Ahmad Ibrahim 0002, Ahmad-Reza Sadeghi, Matthias Schunter, Gene Tsudik, Christian Wachsmann |
CCS | 1 |
| 2015 | Secure Deduplication of Encrypted Data without Additional Independent ServersabstractEncrypting data on client-side before uploading it to a cloud storage is essential for protecting users' privacy. However client-side encryption is at odds with the standard practice of deduplication. Reconciling client-side encryption with cross-user deduplication is an active research topic. We present the first secure cross-user deduplication scheme that supports client-side encryption without requiring any additional independent servers. Interestingly, the scheme is based on using a PAKE (password authenticated key exchange) protocol. We demonstrate that our scheme provides better security guarantees than previous efforts. We show both the effectiveness and the efficiency of our scheme, via simulations using realistic datasets and an implementation. Jian Liu 0012, N. Asokan, Benny Pinkas |
CCS | 2 |
| 2015 | I Know Where You are: Proofs of Presence Resilient to Malicious ProversabstractIn the recent years, new services and businesses leveraging location-based services (LBS) are rapidly emerging. On the other hand this has raised the incentive of users to cheat about their locations to the service providers for personal benefits. Context-based proofs-of-presence (PoPs) have been proposed as a means to enable verification of users' location claims. However, as we show in this paper, they are vulnerable to context guessing attacks. To make PoPs resilient to malicious provers we propose two complementary approaches for making context-based PoPs: one approach focuses on surprisal filtering based on estimating the entropy of particular PoPs in order to detect context measurements vulnerable to such attacks. The other approach is based on utilizing longitudinal observations of ambient modalities like noise level and ambient luminosity. It is capable of extracting more entropy from the context to construct PoPs that are hard to guess by an attacker even in situations in which other context sensor modalities fail to provide reliable PoPs. Markus Miettinen, N. Asokan, Farinaz Koushanfar, Thien Duc Nguyen, Jon Rios, Ahmad-Reza Sadeghi, Majid Sobhani, Sudha Yellapantula |
AsiaCCS | 2 |
| 2015 | Checksum gestures: continuous gestures as an out-of-band channel for secure pairingabstractWe propose the use of a single continuous gesture as a novel, intuitive, and efficient mechanism to authenticate a secure communication channel. Our approach builds on a novel algorithm for encoding (at least 20-bits) authentication information as a single continuous gesture, referred to as a checksum gesture. By asking the user to perform the generated gesture, a secure channel can be authenticated. Results from a controlled user experiment (N = 13 participants, 1022 trials) demonstrate the feasibility of our technique, showing over 90% success rate in establishing a secure communication channel despite relying on complex gesture patterns. The authentication times of our method are over three-folds faster than with previous gesture-based solutions. The average execution time of a gesture is 5:7 seconds in our study, which is comparable to the input time of conventional text input based PIN authentication. Our approach is particularly well-suited for scenarios involving wearable devices that lack conventional input capabilities, e.g., pairing a smartwatch with an interactive display. Imtiaj Ahmed, Yina Ye, Sourav Bhattacharya, N. Asokan, Giulio Jacucci, Petteri Nurmi, Sasu Tarkoma |
UbiComp | 4 |
| 2015 | How far removed are you?: scalable privacy-preserving estimation of social path length with Social PaLabstractSocial relationships are a natural basis on which humans make trust decisions. Online Social Networks (OSNs) are increasingly often used to let users base trust decisions on the existence and the strength of social relationships. While most OSNs allow users to discover the length of the social path to other users, they do so in a centralized way, thus requiring them to rely on the service provider and reveal their interest in each other. Marcin Nagy, Thanh Bui, Emiliano De Cristofaro, N. Asokan, Jörg Ott, Ahmad-Reza Sadeghi |
WISEC | 4 |
| 2015 | SpotShare and nearbyPeople: applications of the Social PaL frameworkabstractImagine if there is a privacy-preserving mechanism for two mobile devices to determine if their owners have common friends. It can be useful for access control in applications like ride-sharing, sharing Internet access or even just a simple "people radar" app for showing nearby friends and friends-of-friends. Current mechanisms for doing this come at the cost of revealing these interactions and the users' locations to central servers. In a paper that appears in the WiSec 2015 proceedings, we describe Social Pal [2], a framework that allows privacy-preserving discovery of the distance between two users in a social network. Social Pal was implemented as a general purpose software framework that can be easily used by application developers who wish to incorporate such functionality into their applications. Marcin Nagy, Thanh Bui, Swapnil Udar, N. Asokan, Jörg Ott |
WISEC | 4 |
| 2014 | Context-Based Zero-Interaction Pairing and Key Evolution for Advanced Personal DevicesabstractSolutions for pairing devices without prior security associations typically require users to actively take part in the pairing process of the devices. Scenarios involving new types of devices like Internet-of-Things (IoT) appliances and wearable devices make it, however, desirable to be able to pair users' personal devices without user involvement. In this paper, we present a new approach for secure zero-interaction pairing suitable for IoT and wearable devices. Markus Miettinen, N. Asokan, Thien Duc Nguyen, Ahmad-Reza Sadeghi, Majid Sobhani |
CCS | 2 |
| 2014 | ConXsense: automated context classification for context-aware access controlabstractWe present ConXsense, the first framework for context-aware access control on mobile devices based on context classification. Previous context-aware access control systems often require users to laboriously specify detailed policies or they rely on pre-defined policies not adequately reflecting the true preferences of users. We present the design and implementation of a context-aware framework that uses a probabilistic approach to overcome these deficiencies. The framework utilizes context sensing and machine learning to automatically classify contexts according to their security and privacy-related properties. We apply the framework to two important smartphone-related use cases: protection against device misuse using a dynamic device lock and protection against sensory malware. We ground our analysis on a sociological survey examining the perceptions and concerns of users related to contextual smartphone security and analyze the effectiveness of our approach with real-world context data. We also demonstrate the integration of our framework with the FlaskDroid architecture for fine-grained access control enforcement on the Android platform. Markus Miettinen, Stephan Heuser, Wiebke Kronz, Ahmad-Reza Sadeghi, N. Asokan |
AsiaCCS | 5 |
| 2014 | Comparing and fusing different sensor modalities for relay attack resistance in Zero-Interaction AuthenticationabstractZero-Interaction Authentication (ZIA) refers to approaches that authenticate a user to a verifier (terminal) without any user interaction. Currently deployed ZIA solutions are predominantly based on the terminal detecting the proximity of the user's personal device, or a security token, by running an authentication protocol over a short-range wireless communication channel. Unfortunately, this simple approach is highly vulnerable to low-cost and practical relay attacks which completely offset the usability benefits of ZIA. The use of contextual information, gathered via on-board sensors, to detect the co-presence of the user and the verifier is a recently proposed mechanism to resist relay attacks. In this paper, we systematically investigate the performance of different sensor modalities for co-presence detection with respect to a standard Dolev-Yao adversary. First, using a common data collection framework run in realistic everyday settings, we compare the performance of four commonly available sensor modalities (WiFi, Bluetooth, GPS, and Audio) in resisting ZIA relay attacks, and find that WiFi is better than the rest. Second, we show that, compared to any single modality, fusing multiple modalities improves resilience against ZIA relay attacks while retaining a high level of usability. Third, we motivate the need for a stronger adversarial model to characterize an attacker who can compromise the integrity of context sensing itself. We show that in the presence of such a powerful attacker, each individual sensor modality offers very low security. Positively, the use of multiple sensor modalities improves security against such an attacker if the attacker cannot compromise multiple modalities simultaneously. Hien Thi Thu Truong, Babins Shrestha, Nitesh Saxena, N. Asokan, Petteri Nurmi |
PerCom | 5 |
| 2014 | On mobile malware infectionsabstractNo abstract available. N. Asokan |
WISEC | 1 |
| 2014 | The company you keep: mobile malware infection rates and inexpensive risk indicatorsabstractThere is little information from independent sources in the public domain about mobile malware infection rates. The only previous independent estimate (0.0009%) [11], was based on indirect measurements obtained from domain-name resolution traces. In this paper, we present the first independent study of malware infection rates and associated risk factors using data collected directly from over 55,000 Android devices. We find that the malware infection rates in Android devices estimated using two malware datasets (0.28% and 0.26%), though small, are significantly higher than the previous independent estimate. Based on the hypothesis that some application stores have a greater density of malicious applications and that advertising within applications and cross-promotional deals may act as infection vectors, we investigate whether the set of applications used on a device can serve as an indicator for infection of that device. Our analysis indicates that, while not an accurate indicator of infection by itself, the application set does serve as an inexpensive method for identifying the pool of devices on which more expensive monitoring and analysis mechanisms should be deployed. Using our two malware datasets we show that this indicator performs up to about five times better at identifying infected devices than the baseline of random checks. Such indicators can be used, for example, in the search for new or previously undetected malware. It is therefore a technique that can complement standard malware scanning. Our analysis also demonstrates a marginally significant difference in battery use between infected and clean devices. Hien Thi Thu Truong, Eemil Lagerspetz, Petteri Nurmi, Adam J. Oliner, Sasu Tarkoma, N. Asokan, Sourav Bhattacharya |
WWW | 6 |
| 2014 | Mobile Trusted ComputingabstractTrusted computing technologies for mobile devices have been researched, developed, and deployed over the past decade. Although their use has been limited so far, ongoing standardization may change this by opening up these technologies for easy access by developers and users. In this survey, we describe the current state of trusted computing solutions for mobile devices from research, standardization, and deployment perspectives. N. Asokan, Jan-Erik Ekberg, Kari Kostiainen, Anand Rajan, Carlos V. Rozas, Ahmad-Reza Sadeghi, Steffen Schulz 0001, Christian Wachsmann |
Proc. IEEE | 1 |
| 2013 | CrowdShare: Secure Mobile Resource Sharing
N. Asokan, Alexandra Dmitrienko, Marcin Nagy, Elena Reshetova, Ahmad-Reza Sadeghi, Thomas Schneider 0003, Stanislaus Stelle |
ACNS | 1 |
| 2013 | Do I know you?: efficient and privacy-preserving common friend-finder protocols and applicationsabstractThe increasing penetration of Online Social Networks (OSNs) prompts the need for effectively accessing and utilizing social networking information. In numerous applications, users need to make trust and/or access control decisions involving other (possibly stranger) users, and one important factor is often the existence of common social relationships. This motivates the need for secure and privacy-preserving techniques allowing users to assess whether or not they have mutual friends. Marcin Nagy, Emiliano De Cristofaro, Alexandra Dmitrienko, N. Asokan, Ahmad-Reza Sadeghi |
ACSAC | 4 |
| 2013 | Trusted execution environments on mobile devicesabstractA trusted execution environment (TEE) is a secure processing environment that is isolated from the normal processing environment where the device operating system and applications run. The first mobile phones with hardware-based TEEs appeared almost a decade ago, and today almost every smartphone and tablet contains a TEE like ARM TrustZone. Despite such a large-scale deployment, the use of TEE functionality has been limited for developers. With emerging standardization this situation is about to change. In this tutorial, we explain the security features provided by mobile TEEs and describe On-board Credentials (ObC) system that enables third-party TEE development. We discuss ongoing TEE standardization activities, including the recent Global Platform standards and the Trusted Platform Module (TPM) 2.0 specification, and identify open problems for the near future of mobile hardware security. Jan-Erik Ekberg, Kari Kostiainen, N. Asokan |
CCS | 3 |
| 2013 | CCS'13 co-located workshop summary for SPSM 2013abstractSecurity and privacy in smartphones and mobile devices is an emerging area which has received significant attention from the research community during the past few years. The SPSM workshop was created to bring together these researchers and practitioners. Following the success of the two previous editions, we present this third edition of the workshop which has attracted significantly more submissions and benefited from the expertise of an expanded international program committee. Adrienne Porter Felt, N. Asokan |
CCS | 2 |
| 2012 | Is this app safe?: a large scale study on application permissions and risk signalsabstractThird-party applications (apps) drive the attractiveness of web and mobile application platforms. Many of these platforms adopt a decentralized control strategy, relying on explicit user consent for granting permissions that the apps request. Users have to rely primarily on community ratings as the signals to identify the potentially harmful and inappropriate apps even though community ratings typically reflect opinions about perceived functionality or performance rather than about risks. With the arrival of HTML5 web apps, such user-consent permission systems will become more widespread. We study the effectiveness of user-consent permission systems through a large scale data collection of Facebook apps, Chrome extensions and Android apps. Our analysis confirms that the current forms of community ratings used in app markets today are not reliable indicators of privacy risks of an app. We find some evidence indicating attempts to mislead or entice users into granting permissions: free applications and applications with mature content request more permissions than is typical; 'look-alike' applications which have names similar to popular applications also request more permissions than is typical. We also find that across all three platforms popular applications request more permissions than average. Pern Hui Chia, Yusuke Yamamoto, N. Asokan |
WWW | 3 |
| 2011 | Towards User-Friendly Credential Transfer on Open Credential Platforms
Kari Kostiainen, N. Asokan, Alexandra Afanasyeva |
ACNS | 2 |
| 2011 | Old, new, borrowed, blue --: a perspective on the evolution of mobile platform security architecturesabstractThe recent dramatic increase in the popularity of "smartphones" has led to increased interest in smartphone security research. From the perspective of a security researcher the noteworthy attributes of a modern smartphone are the ability to install new applications, possibility to access Internet and presence of private or sensitive information such as messages or location. These attributes are also present in a large class of more traditional "feature phones." Mobile platform security architectures in these types of devices have seen a much larger scale of deployment compared to platform security architectures designed for PC platforms. In this paper we start by describing the business, regulatory and end-user requirements which paved the way for this widespread deployment of mobile platform security architectures. We briefly describe typical hardware-based security mechanism that provide the foundation for mobile platform security. We then describe and compare the currently most prominent open mobile platform security architectures and conclude that many features introduced recently are borrowed, or adapted with a twist, from older platform security architectures. Finally, we identify a number of open problems in designing effective mobile platform security. Kari Kostiainen, Elena Reshetova, Jan-Erik Ekberg, N. Asokan |
CODASPY | 4 |
| 2011 | Best-effort authentication for opportunistic networksabstractA “best-effort” authentication method, which is easier to attack than generic authentication methods (but requires fewer computations for benign nodes), may be sufficient for certain networking scenarios. We illustrate this point by examining the case of fragment authentication by intermediaries in an opportunistic network. We describe mechanisms for implementing best-effort authentication, with the caveat that an authentication strength sufficient in one scenario may be unfit for another. John Solis, Philip Ginzboorg, N. Asokan, Jörg Ott |
IPCCC | 3 |
| 2011 | Vibrate-to-unlock: Mobile phone assisted user authentication to multiple personal RFID tagsabstractPersonal RFID tags store valuable information private to their users that can easily be subject to eavesdropping, unauthorized reading, owner tracking, and cloning. RFID tags are also susceptible to relay attacks and likely to get lost and stolen. In this paper, we introduce the problem of user authentication to RFID tags. This allows users to control when and where their RFID tags can be accessed. We present a novel approach for user authentication to multiple RFID tags called “Vibrate-to-Unlock” (VtU). This technique uses a mobile phone as an authentication token, forming an unidirectional tactile communication channel between users and their RFID tags. Authenticating to an RFID tag involves touching a vibrating phone to the tag or an object carrying the tag, such as a wallet. We discuss the design and implementation of this new method on Intel's WISP tags. We also report on a preliminary usability evaluation of our VtU prototype. Nitesh Saxena, Md. Borhan Uddin, Jonathan Voris, N. Asokan |
PerCom | 4 |
| 2011 | Secure Device Pairing Based on a Visual Channel: Design and Usability Studyabstract“Pairing” is the establishment of authenticated key agreement between two devices over a wireless channel. Such devices are ad hoc in nature as they lack any common preshared secrets or trusted authority. Fortunately, these devices can be connected via auxiliary physical (audio, visual, tactile) channels which can be authenticated by human users. They can, therefore, be used to form the basis of a pairing operation. Recently proposed pairing protocols and methods are based upon bidirectional physical channels. However, various pairing scenarios are asymmetric in nature, i.e., only a unidirectional physical channel exists between two devices (such as between a cell phone and an access point). In this paper, we show how strong mutual authentication can be achieved even with a unidirectional visual channel, where prior methods could provide only a weaker property termed as presence. This could help reduce the execution time and improve usability of prior pairing methods. In addition, by adopting recently proposed improved pairing protocols, we propose how visual channel authentication can be used even on devices that have very limited displaying capabilities, all the way down to a device whose display consists of a cheap single light-source, such as a light-emitting diode. We present the results of a preliminary usability study evaluating our proposed method. Nitesh Saxena, Jan-Erik Ekberg, Kari Kostiainen, N. Asokan |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2010 | A closer look at recognition-based graphical passwords on mobile devicesabstractGraphical password systems based on the recognition of photographs are candidates to alleviate current over-reliance on alphanumeric passwords and PINs. However, despite being based on a simple concept -- and user evaluations consistently reporting impressive memory retention -- only one commercial example exists and overall take-up is low. Barriers to uptake include a perceived vulnerability to observation attacks; issues regarding deployability; and the impact of innocuous design decisions on security not being formalized. Our contribution is to dissect each of these issues in the context of mobile devices -- a particularly suitable application domain due to their increasing significance, and high potential to attract unauthorized access. This produces: 1) A novel yet simple solution to the intersection attack that permits greater variability in login challenges; 2) Detailed analysis of the shoulder surfing threat that considers both simulated and human testing; 3) A first look at image processing techniques to contribute towards automated photograph filtering. We operationalize our observations and gather data in a field context where decentralized mechanisms of varying entropy were installed on the personal devices of participants. Across two working weeks success rates collected from users of a high entropy version were similar to those of a low entropy version at 77%, and login durations decreased significantly across the study. Paul Dunphy, Andreas P. Heiner, N. Asokan |
SOUPS | 3 |
| 2010 | Controlling resource hogs in mobile delay-tolerant networks
John Solis, N. Asokan, Kari Kostiainen, Philip Ginzboorg, Jörg Ott |
Comput. Commun. | 2 |
| 2009 | On-board credentials with open provisioningabstractSecurely storing and using credentials is critical for ensuring the security of many modern distributed applications. Existing approaches to address this problem fall short. User memorizable passwords are flexible and cheap, but they suffer from bad usability and low security. On the other hand, dedicated hardware tokens provide high levels of security, but the logistics of manufacturing and provisioning such tokens are expensive, which makes them unattractive for most service providers. A new approach to address the problem has become possible due to the fact that several types of general-purpose secure hardware, like TPM and M-shield, are becoming widely deployed. These platforms enable, to different degrees, a strongly isolated secure environment. In this paper, we describe how we use general-purpose secure hardware to develop an architecture for credentials which we call On-board Credentials (ObCs). ObCs combine the flexibility of virtual credentials with the higher levels of protection due to the use of secure hardware. A distinguishing feature of the ObC architecture is that it is open: it allows anyone to design and deploy new credential algorithms to ObC-capable devices without approval from the device manufacturer or any other third party. The primary contribution of this paper is showing and solving the technical challenges in achieving openness while avoiding additional costs (by making use of already deployed secure hardware) and without compromising security (e.g., ensuring strong isolation). Our proposed architecture is designed with the constraints of existing secure hardware in mind and has been prototyped on several different platforms including mobile devices based on M-Shield secure hardware. Kari Kostiainen, Jan-Erik Ekberg, N. Asokan, Aarne Rantala |
AsiaCCS | 3 |
| 2008 | Securing Peer-to-Peer Distributions for Mobile Devices
André Osterhues, Ahmad-Reza Sadeghi, Marko Wolf, Christian Stüble, N. Asokan |
ISPEC | 5 |
| 2007 | Enabling Fairer Digital Rights Management with Trusted Computing
Ahmad-Reza Sadeghi, Marko Wolf, Christian Stüble, N. Asokan, Jan-Erik Ekberg |
ISC | 4 |
| 2007 | Secure software installation in a mobile environmentabstractSoftware security in mobile devices today is done by granting privileges to software, usually based on code signing. The cost of obtaining signatures and meeting strict quality requirements deters hobbyist developers from participating and contributing to application development. If a certain piece of software does not come with an acceptable signature, the mobile device may give the user the option of deciding whether that software should be granted the requested privileges. Naturally, designing the user interaction for this step without hampering usability and security is tricky. When users are simply prompted whether they want to grant certain privileges to some software, they often do not have enough information to understand the implications of this action. Andreas P. Heiner, N. Asokan |
SOUPS | 2 |
| 2006 | Secure Device Pairing based on a Visual Channel (Short Paper)abstractRecently several researchers and practitioners have begun to address the problem of how to set up secure communication between two devices without the assistance of a trusted third party. McCune et al., (2005) proposed that one device displays the hash of its public key in the form of a barcode, and the other device reads it using a camera. Mutual authentication requires switching the roles of the devices and repeating the above process in the reverse direction. In this paper, we show how strong mutual authentication can be achieved even with a unidirectional visual channel, without having to switch device roles. By adopting recently proposed improved pairing protocols, we propose how visual channel authentication can be used even on devices that have very limited displaying capabilities Nitesh Saxena, Jan-Erik Ekberg, Kari Kostiainen, N. Asokan |
S&P | 4 |
| 2005 | Visitor Access Management in Personal Wireless NetworksabstractThe increasing popularity and variety of consumer multimedia devices is driving the need for networked homes. Yet setting up a secure wireless network is a daunting task for most ordinary users. Recently, there have been several proposals for easing this process. However, none of the proposals consider the problem of how to make it easy to manage visitor access. In this paper, we motivate the requirements for visitor management, show the shortcomings of the current easy setup proposals in this regard, and propose a new setup procedure that makes it easy to manage visitor access to wireless networks. Our contributions are twofold: first we present an approach to assigning categories to client devices at admission time so that selective revocation of clients based on those categories becomes possible. Then we present the idea of admission tickets, a flexible and secure way to delegate conditional access rights. We report the results and experience of prototyping of the proposed procedure using the HostAP framework. N. Asokan, Seamus Moloney, Philip Ginzboorg, Kari Kostiainen |
ISM | 1 |
| 2001 | Authentication and key generation for mobile IP using GSM authentication and roamingabstractA new authentication, authorization and accounting (AAA) infrastructure for use on the Internet is being developed at the IETF. AAA support is also being specified for mobile IP. The paper describes an implemented prototype system that demonstrates how the existing GSM authentication and operator roaming infrastructure can be used for mobile IP authentication and key distribution. We present a mechanism for authenticating the user and generating mobile IP authentication keys using the GSM subscriber identity module (SIM). The Internet AAA network has an interface to the GSM network for obtaining authentication information from the GSM Authentication Centre (AuC). After the authentication keys have been generated, the default mobile IP authentication with these keys is used for several subsequent registrations. Henry Haverinen, N. Asokan, Tuomas Määttänen |
ICC | 2 |
| 2000 | Key agreement in ad hoc networks
N. Asokan, Philip Ginzboorg |
Comput. Commun. | 1 |
| 2000 | Optimistic fair exchange of digital signaturesabstractWe present a new protocol that allows two players to exchange digital signatures over the Internet in a fair way, so that either each player gets the other's signature, or neither player does. The obvious application is where the signatures represent items of value, for example, an electronic check or airline ticket. The protocol can also be adapted to exchange encrypted data. It relies on a trusted third party, but is "optimistic," in that the third party is only needed in cases where one player crashes or attempts to cheat. A key feature of our protocol is that a player can always force a timely and fair termination, without the cooperation of the other player, even in a completely asynchronous network. A specialization of our protocol can be used for contract signing; this specialization is not only more efficient, but also has the important property that the third party can be held accountable for its actions: if it ever cheats, this can be detected and proven. N. Asokan, Victor Shoup, Michael Waidner |
IEEE J. Sel. Areas Commun. | 1 |
| 1999 | Authenticating public terminals
N. Asokan, Hervé Debar, Michael Steiner 0001, Michael Waidner |
Comput. Networks | 1 |
| 1998 | Optimistic Fair Exchange of Digital Signatures (Extended Abstract)
N. Asokan, Victor Shoup, Michael Waidner |
EUROCRYPT | 1 |
| 1998 | Asynchronous Protocols for Optimistic Fair ExchangeabstractThe optimistic approach of involving a third party only in the case of exceptions is a useful technique to build secure, yet practical fair exchange protocols. Previous solutions using this approach implicitly assumed that players had reliable communication channels to the third party. We present a set of optimistic fair exchange protocols which tolerate temporary failures in the communication channels to the third party. A central feature of the protocols is that either player can asynchronously and unilaterally bring a protocol run to completion. N. Asokan, Victor Shoup, Michael Waidner |
S&P | 1 |
| 1998 | Protecting the Computation Results of Free-Roaming Agents
Günter Karjoth, N. Asokan, Ceki Gülcü |
Pers. Ubiquitous Comput. | 2 |
| 1997 | Optimistic Protocols for Fair ExchangeabstractThis report has been submitted for publication outside of IBM and will probably be copyrighted if accepted for publication. It has been issued as a Research Report for early dissemination of its contents and will be distributed outside of IBM up to one year after the date indicated at the top of this page. In view of the transfer of copyright to the outside publisher, its distribution outside of IBM prior to publication should be limited to peer communications and specific requests. After outside publication, requests should be filled only by reprints or legally obtained copies of the article (e.g., payment of royalties). N. Asokan, Matthias Schunter, Michael Waidner |
CCS | 1 |
| 1997 | Server-Supported SignaturesabstractNon-repudiation is one of the most important security services. In this paper we present a novel non-repudiation technique, called server-supported signatures, S3. It is based on one-way hash functions and traditional digital signatures. One of its highlights is that for ordinary users the use of a symmetric cryptography is limited to signature verification. S3 is efficient in terms of computational, communication and storage costs. It also offers a degree of security comparable to that of existing techniques based on asymmetric cryptography. N. Asokan, Gene Tsudik, Michael Waidner |
J. Comput. Secur. | 1 |
| 1996 | Server-Supported Signatures
N. Asokan, Gene Tsudik, Michael Waidner |
ESORICS | 1 |
| 1995 | Untraceability in Mobile NetworksabstractUser mobilityis a feature that raises many new security-related issues and concerns.One of them is the disclosure of a mobile user's reai identity during the authentication process, or other procedures specific to mobile networks.Such disclosure allows an unauthorized third-party to track the m.obile user's movements and current whereabouts.Depending ou the context, access to auy information related to a mobile user's location without his consent can be a serious violation of his privacy.This new issue might be seen as a conflicting requirement with respect to authentication: untraceability requires hiding the user's identity while authentication requires the user's identity to be revealed in order to be proved.What is needed is a single mechanism reconciling both authentication and privacy of a mobile user's identification.The basic :solution to this problem is the use of uliases.Aliases insure untraceability by hiding the user's real identity as well as his relationship with domain authorities.In this paper, we present a classification scheme to identify the various degrees of untraceability requirements.We then present an efficient method for the computation of aliases and apply It to a new set of inter-domain authentication protocols.We demonstrate that these protocols can be designed to meet various degrees of untraceability requirements.In designing these protocols, we try to avoid the drawbacks of authentication protoc:ols in existing mobile network architectures such as CDPD and GSM. Didier Samfat, Refik Molva, N. Asokan |
MobiCom | 3 |