Bogdan Groza

dblp:41/136 · DBLP profile ↗
← Back
41ranked-venue papers
24as first author
15since 2021 · last 2026
0000-0003-3078-3635ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 26 · 18 first-author · 7 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 3 · 3 first-author · 1 since 2021Computer networks · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 first-author
YearPublicationVenuePosition
2026 Constraint-Guided Clustering for Identifying in-Vehicle Electronic Control Units from Voltage Data
abstract
Identifying in-vehicle electronic control units based on voltage characteristics has been the subject of extensive research in cybersecurity. However, the results reported so far generally depend on restricted datasets and supervised learning. In this work, we show that clustering, i.e., unsupervised learning, of voltage characteristics, is in fact more challenging when done on a larger pool of electronic control units as several out-of-the-box clustering methods and metrics will fail to determine the correct number of clusters when exerted over a large dataset. To overcome this issue, we propose a new methodology that takes advantage of domain-specific constraints, which guide the search toward the correct number of electronic control units in a car, or even in a larger pool of units from several cars. We introduce two new metrics: correctness, which measures the success ratio with respect to the constraints, and divergence, which measures the consistency of the clustering, and show that they provide a strong indication for the optimal number of clusters. In this specific context, both metrics prove to be more reliable than the widely used Silhouette score, Davies-Bouldin and Calinski-Harabas indexes. We successfully test our methodology on the largest dataset available today for in-vehicle voltage characteristics and discover new insights regarding the number of devices.
Bogdan Groza, Patricia Iosif, Lucian Popa 0003
AAAI1
2026 A Critical Look at Accelerometer-Based Driver Fingerprinting: Between Deceptive Physics, Sensor Mingling and Weak Multiclass Assumptions
Bogdan Groza, Emilia Caragea, Adriana Berdich, Camil Jichici
EuroS&P1
2026 Efficient voltage-based intrusion detection for in-vehicle networks: From density clustering to centroid classification
abstract
Detecting intrusions on in-vehicle networks from voltage characteristics has become a popular technique. However, an effective mechanism for voltage identification of Electronic Control Units requires both a sound clustering algorithm to determine the correct number of devices on the network and an efficient classifier that allows updates in order to handle changes due to environmental conditions. Firstly, we explore the use of HDBSCAN in order to cluster ECUs based on voltage characteristics. While HDBSCAN is a highly effective algorithm, which has the merit of having only a few parameters that need to be tuned, our results show that finding the optimal parametrization is not that straight-forward. We test two well-known methods and an empirical selection in order to determine optimal choices for the largest existing dataset that contains voltage samples from ten vehicles. Secondly, we use the Nearest Centroid classifier to identify ECUs based on their fingerprints, which offers the advantage of an extremely small memory footprint and an efficient updating mechanism for the centroids. Thus, the method is both efficient and capable of adapting to environmental changes, which is a known demand for voltage-based identification. The proposed methodology demonstrates a very high detection rate that is specific to voltage-based techniques, i.e., true acceptance rate greater than 99.93% and false acceptance rate lower than 0.03%, even when faced with changing environmental conditions when updates are used. It also features an easy to update mechanism and a minimal memory footprint that is 4 to 20 times smaller than baseline classifiers such as SVM and RF.
Patricia Iosif, Lucian Popa 0003, Bogdan Groza
Comput. Networks3
2025 Secure Time Synchronization With Submicrosecond Accuracy in Controller Area Networks
abstract
In this article, we achieve submicrosecond accuracy with an AUTOSAR-compliant time synchronization protocol on CAN-FD. In addition to this, we discover two attacks, double replays and forecasting, on the AUTOSAR CanTSyn standard and design fixes for them. Several simple and efficient algorithms are tested, e.g., weighted learning, windowed, and continuous averaging, in order to determine the correct ratio between participants' clocks with minimal computational and communication overheads. We also point out that, at such a high level of synchronization accuracy, there may be significant differences when using simple or double precision floats for encoding the clock ratio with some of the algorithms. Our approach also exploits the direct memory access subsystem instead of CPU interrupts during protocol executions, which reduces the processor load, making the solution suitable for real-time systems. We evaluate the proposed protocol in a realistic scenario by deploying it on an automotive-grade setup with Infineon Aurix development boards.
Adrian Musuroi, Bogdan Groza
IEEE Trans. Ind. Informatics2
2024 Control System Level Intrusion Detection on J1939 Heavy-Duty Vehicle Buses
abstract
As the security vulnerabilities of controller area networks (CAN) become well known, heavy-duty vehicles implementing the SAE J1939 specification layer on this bus are immediate targets. Recently released standards provide clear cybersecurity requirements, but the exact methods to be implemented are not specified and remain up to the manufacturers. In this work, we address adversary actions and countermeasures at the control system level for a heavy-duty vehicle J1939 CAN bus. This low level approach allows us to complement regular attacks with more knowledgeable attacks that may evade detection and discuss realistic countermeasures. Indeed, as we also show by experiments, traditional approaches based on machine learning algorithms will largely fail to detect such attacks. We present experiments based on a model that links between the Simulink environment, an extension of the MATLAB platform for the simulation of in-vehicle control systems, with the CANoe environment, which facilitates the simulation of in-vehicle networks.
Camil Jichici, Adriana Berdich, Adrian Musuroi, Bogdan Groza
IEEE Trans. Ind. Informatics4
2024 Cyberattacks on Adaptive Cruise Controls and Emergency Braking Systems: Adversary Models, Impact Assessment, and Countermeasures
abstract
In the recent years, there has been a lot of focus on designing security for in-vehicle networks and detecting intrusions. Still, no countermeasure is perfect and most of the existing intrusion detection systems have a nonzero false negative rate, which implies that adversarial frames may still go undetected on the bus. Unfortunately, answers are largely missing for what will happen with the vehicle in such circumstances, i.e., how is the safety of the vehicle and bystanders affected by adversarial actions that go undetected, while there are little or no answers on the acceptable misclassification rates in real-world deployments. In this article, we attempt to provide such answers by pursuing an impact assessment for adversarial actions on the bus assuming low false negative rates. The assessment is based on the effects of such attacks on models for automatic emergency braking and adaptive cruise control systems that are implemented in Simulink, a commonly used tool for designing such systems in the automotive industry. To achieve this, we embed adversarial behavior into the Simulink model, according to recently reported attacks on in-vehicle controller area network buses. This allows us to assess the impact of adversarial actions according to existing safety standards and regulations.
Adriana Berdich, Bogdan Groza
IEEE Trans. Reliab.2
2023 A Survey on Fingerprinting Technologies for Smartphones Based on Embedded Transducers
abstract
Smartphones are a vital technology, they improve our social interactions, provide us a great deal of information and bring forth the means to control various emerging technologies, like the numerous IoT devices that are controlled via smartphone apps. In this context, smartphone fingerprinting from sensor characteristics is a topic of high interest not only due to privacy implications or potential use in forensics investigations, but also because of various applications in device authentication. In this work we review existing approaches for smartphone fingerprinting based on internal components, focusing mostly on camera sensors, microphones, loudspeakers and accelerometers. Other sensors, i.e., gyroscopes and magnetometers, are also accounted, but they correspond to a smaller body of works. The output of these transducers, which convert one type of energy into another, e.g., mechanical into electrical, leaks through various channels such as mobile apps and cloud services, while there is little user awareness on the privacy risks. Needless to say, miniature physical imperfections from the manufacturing process make each such transducer unique. One of the main intentions of our study is to rank these sensors according to the accuracy they provide in identifying smartphones and to give a clear overview on the amount of research that each of these components triggered so far. We review the features which can be extracted from each type of data and the classification algorithms that have been used. Last but not least, we also point out publicly available datasets which can serve for future investigations.
Adriana Berdich, Bogdan Groza, René Mayrhofer
IEEE Internet Things J.2
2023 CAN-LOC: Spoofing Detection and Physical Intrusion Localization on an In-Vehicle CAN Bus Based on Deep Features of Voltage Signals
abstract
The Controller Area Network (CAN), which is used for communication between in-vehicle devices, has been shown to be vulnerable to spoofing attacks. Voltage-based spoofing detection (VBS-D) mechanisms are considered state-of-the-art solutions, complementing cryptography-based authentication whose security is limited due to the CAN protocol’s limited message size. Unfortunately, VBS-D mechanisms are vulnerable to poisoning performed by a malicious device connected to the CAN bus, specifically designed to poison the deployed VBS-D mechanism as it adapts to environmental changes that take place when the vehicle is moving. In this paper, we harden VBS-D mechanisms using a deep learning-based mechanism which runs immediately, when the vehicle starts; this mechanism utilizes physical side-channels to detect and locate physical intrusions, even when the malicious devices connected to the CAN bus are silent. We demonstrate the mechanism’s effectiveness (100% intrusion detection accuracy and error rates of close to 0%) in various physical intrusion scenarios and varying temperatures on a CAN bus prototype. In addition, we present a deep learning-based VBS-D mechanism that securely adapts to environmental changes. This mechanism’s robustness (99.8% device identification accuracy) is demonstrated on a real moving vehicle.
Efrat Levy, Asaf Shabtai, Bogdan Groza, Pal-Stefan Murvay, Yuval Elovici
IEEE Trans. Inf. Forensics Secur.3
2023 Sweep-to-Unlock: Fingerprinting Smartphones Based on Loudspeaker Roll-Off Characteristics
abstract
Fingerprinting smartphones based on acoustic characteristics of their loudspeaker may have a number of applications in device-to-device authentication as well as in forensic investigations. In this work we propose an efficient fingerprinting methodology by using the roll-off characteristics of the device speaker, i.e., the transition between the low and high stopbands to the passband segment of the speaker. We extract roll-off characteristics from sweep signals, also know as chirps, that are commonly used in practice to test speaker response. This procedure appears to be more stable against variations of the volume level and allows the use of simple linear approximations, which are intuitive and easy to compute, in order to extract the fingerprint. To increase detection accuracy, on the basis of the proven performance of deep learning techniques, a convolutional and a bi-directional long short term memory neural network are further proposed and their performance demonstrated for authentication purposes. While numerous applications may be envisioned, we specifically focus on the use of speaker characteristics in relation to in-vehicle infotainment units, checking if recordings from these units can be used to fingerprint a specific phone.
Adriana Berdich, Bogdan Groza, René Mayrhofer, Efrat Levy, Asaf Shabtai, Yuval Elovici
IEEE Trans. Mob. Comput.2
2022 PanoptiCANs - Adversary-Resilient Architectures for Controller Area Networks
Bogdan Groza, Lucian Popa 0003, Tudor Andreica, Pal-Stefan Murvay, Asaf Shabtai, Yuval Elovici
ESORICS (3)1
2022 ECUPrint - Physical Fingerprinting Electronic Control Units on CAN Buses Inside Cars and SAE J1939 Compliant Vehicles
abstract
We fingerprint 54 ECUs from 10 cars, one of them being a heavy-duty vehicle that is compliant to the SAE J1939 standard. These later specifications implemented in commercial vehicles offer concrete sender addresses in every CAN frame, making physical characteristics easier to link to specific ECUs. This is not the case for traffic collected inside passenger cars where the allocation of CAN bus identifiers is non-uniform, without explicit sender and receiver addresses, making ECU identification more challenging. While previous research has shown good separation between ECUs even when single features are used, e.g., skews or maximum voltage level, prior results are based on a small number of cars, while our larger experimental basis proves that single features are likely insufficient to separate between a large number of ECUs. Concretely, for a crisp separation, at least four features seem to be needed, i.e., mean voltage, max voltage, bit time and plateau time, while clock skews or any single voltage feature lead to overlaps. We provide clear experimental bounds on the intra and inter-distances regarding skews and voltage features, not neglecting environmental variations which may occur when the car is running.
Lucian Popa 0003, Bogdan Groza, Camil Jichici, Pal-Stefan Murvay
IEEE Trans. Inf. Forensics Secur.2
2022 Effective Intrusion Detection and Prevention for the Commercial Vehicle SAE J1939 CAN Bus
abstract
Detecting and preventing intrusions on in-vehicle buses is a topic of great importance which may have an even greater significance in the context of commercial vehicles that are liable for the security of the demanding tasks they carry, passengers or goods not least. In this respect, the SAE J1939 protocol, which is a CAN based higher-layer protocol for commercial vehicles, requires special attention due to the existence of both specific procedures in the standard, e.g., address claims and multi-frame transmissions, as well as due to sharp specifications regarding the content of messages which may facilitate the deployment of a more targeted intrusion detection system. Needless to say, most of the research works on CAN intrusion detection are treating in-vehicle traffic as black-box with no concerns over the actual meaning of the frames content. In this context, we pursue the development of a targeted solution for J1939 buses. We collect real-world traffic from a commercial vehicle bus, compliant to the J1939 standard, and make a comprehensive analysis of its structure and content. This allows us to design an effective intrusion prevention system that detects and eliminates in real-time all frames that were manipulated by an adversary by overriding them with error flags. To prove the correctness of our approach, we present results with a proof-of-concept implementation on high-end automotive-grade controllers.
Camil Jichici, Bogdan Groza, Radu Ragobete, Pal-Stefan Murvay, Tudor Andreica
IEEE Trans. Intell. Transp. Syst.2
2021 CAN-SQUARE - Decimeter Level Localization of Electronic Control Units on CAN Buses
Bogdan Groza, Pal-Stefan Murvay, Lucian Popa 0003, Camil Jichici
ESORICS (1)1
2021 CANARY - a reactive defense mechanism for Controller Area Networks based on Active RelaYs
Bogdan Groza, Lucian Popa 0003, Pal-Stefan Murvay, Yuval Elovici, Asaf Shabtai
USENIX Security Symposium1
2021 CANTO - Covert AutheNtication With Timing Channels Over Optimized Traffic Flows for CAN
abstract
Previous research works have endorsed the use of delays and clock skews for detecting intrusions or fingerprinting controllers that communicate on the CAN bus. Recently, timing characteristics of CAN frames have been also used for establishing a covert channel for cryptographic authentication, in this way cleverly removing the need for cryptographic material inside the short payload of data frames. However, the main drawback of this approach is the limited security level that can be achieved over existing CAN bus traffic. In this work we significantly improve on this by relying on optimization algorithms for scheduling CAN frames and deploy the covert channel on optimized CAN traffic. Under practical bus allocations, we are able to extract 3-5 bits of authentication data from each frame which leads to an efficient intrusion detection and authentication mechanism. By accumulating covert channel data over several consecutive frames, we can achieve higher security levels that are in line with current real-world demands. To prove the correctness of our approach, we present experiments on automotive-grade controllers, i.e., Infineon Aurix, and bus measurements with the use of industry standard tools, i.e., CANoe.
Bogdan Groza, Lucian Popa 0003, Pal-Stefan Murvay
IEEE Trans. Inf. Forensics Secur.1
2020 ANTARES - ANonymous Transfer of vehicle Access Rights from External cloud Services
abstract
As car sharing becomes an increasingly common task, mediating user access rights from external servers comes with threats regarding user’s privacy. Clearly, users can be tracked by service mediators, e.g., cloud providers, that manage vehicle fleets, etc. In this work we design and test a simple solution based on oblivious transfer, a well-known and secure cryptographic block, that allows to preserve user’s privacy when gaining access to the vehicle. We test the feasibility of deploying such a solution on Android capable smartphones but also account for potential in-vehicle components, e.g., car head units, that may be soon put to such tasks. We use Microsoft Azure as cloud service provider and deploy a Java implementation, based on the Bouncy Castle cryptographic library, on the server side. Our experimental results show that Android based units are capable of handling the required cryptographic operations and the implementation of the employed protocol can be done by existing open-source support.
Adriana Berdich, Alfred Anistoroaei, Bogdan Groza, Eugen Horatiu Gurban, Pal-Stefan Murvay, Daniel Iercan
VTC Spring3
2019 Performance Evaluation of Elliptic Curve Libraries on Automotive-Grade Microcontrollers
abstract
As cryptography is quickly entering the automotive domain, public-key cryptographic functions are a vital building block and are part of recent industry-proposed standards. Elliptic curves provide a more compact representation for public/private keys making them more suitable for embedded devices with limited amounts of memory. Nonetheless, they provide more compact signatures and open road for identity-based cryptographic primitives by exploiting the flexibility of bilinear pairings. In this work we carry a performance evaluation on some modern libraries, e.g., MIRACL, RELIC, and compare them to the more classical WolfSSL. The evaluation is carried on a state-of-the-art representative controller from the automotive industry, i.e., a 32 bit Infineon TC297. Having a crisper image on computational requirements is relevant for future automotive and industrial applications.
Lucian Popa 0003, Bogdan Groza, Pal-Stefan Murvay
ARES2
2019 Efficient Intrusion Detection With Bloom Filtering in Controller Area Networks
abstract
Due to its cost efficiency, the controller area network (CAN) is still the most wide-spread in-vehicle bus, and the numerous reported attacks demonstrate the urgency in designing new security solutions for CAN. In this paper, we propose an intrusion detection mechanism that takes advantage of Bloom filtering to test frame periodicity based on message identifiers and parts of the data-field which facilitates detection of potential replay or modification attacks. This proves to be an effective approach since most of the traffic from in-vehicle buses is cyclic in nature and the format of the data-field is fixed due to rigid signal allocation. Bloom filters provide an efficient time-memory tradeoff which is beneficial for the constrained resources of automotive grade controllers. We test the correctness of our approach and obtain good results on an industry-standard CANoe-based simulation for a J1939 commercial-vehicle bus and also on CAN with flexible data-rate traces obtained from a real-world high-end vehicle. The proposed filtering mechanism is straightforward to adapt for any other time-triggered in-vehicle bus, e.g., FlexRay, since it is built on time-driven characteristics.
Bogdan Groza, Pal-Stefan Murvay
IEEE Trans. Inf. Forensics Secur.1
2018 Practical Security Exploits of the FlexRay In-Vehicle Communication Protocol
Pal-Stefan Murvay, Bogdan Groza
CRiSIS2
2017 DoS Attacks on Controller Area Networks by Fault Injections from the Software Layer
abstract
The Controller Area Network (CAN) is still the most widely employed bus in the automotive sector. Its lack of security mechanisms led to a high number of attacks and consequently several security countermeasures were proposed, i.e., authentication protocols or intrusion detection mechanisms. We discuss vulnerabilities of the CAN data link layer that can be triggered from the application level with the use of an off the shelf CAN transceiver. Namely, due to the wired-AND design of the CAN bus, dominant bits will always overwrite recessive ones, a functionality normally used to assure priority for frames with low value identifiers. We exploit this characteristic and show Denial of Service attacks both on senders and receivers based on bit injections by using bit banging to maliciously control the CAN transceiver. We demonstrate the effects and limitations of such attacks through experimental analysis and discuss possible countermeasures. In particular, these attacks may have high impact on centralized authentication mechanisms that were frequently proposed in the literature since these attacks can place monitoring nodes in a bus-off state for certain periods of time.
Pal-Stefan Murvay, Bogdan Groza
ARES2
2017 A Vehicle Collision-Warning System Based on Multipeer Connectivity and Off-the-Shelf Smart-Devices
Bogdan Groza, Cosmin Briceag
CRiSIS1
2017 Designing Wireless Automotive Keys with Rights Sharing Capabilities on the MSP430 Microcontroller
Bogdan Groza, Tudor Andreica, Pal-Stefan Murvay
VEHITS1
2017 An Experimental Model for In-vehicle Networks and Subsystems
Bogdan Groza, Eugen Horatiu Gurban, Pal-Stefan Murvay
VEHITS1
2017 LiBrA-CAN: Lightweight Broadcast Authentication for Controller Area Networks
abstract
Despite realistic concerns, security is still absent from vehicular buses such as the widely used Controller Area Network (CAN). We design an efficient protocol based on efficient symmetric primitives, taking advantage of two innovative procedures: splitting keys between nodes and mixing authentication tags. This results in a higher security level when compromised nodes are in the minority, a realistic assumption for automotive networks. Experiments are performed on state-of-the-art Infineon TriCore controllers, contrasted with low-end Freescale S12X cores, while simulations are provided for the recently released CAN-FD standard. To gain compatibility with existent networks, we also discuss a solution based on CAN+.
Bogdan Groza, Pal-Stefan Murvay, Anthony Van Herrewege, Ingrid Verbauwhede
ACM Trans. Embed. Comput. Syst.1
2016 Development of an AUTOSAR Compliant Cryptographic Library on State-of-the-Art Automotive Grade Controllers
abstract
In the light of the recently reported attacks on intra-vehicle networks, it has become clear that cryptography is vital for assuring the security of in-vehicle communications. The current preoccupation of industry professionals in this direction is proved by the inclusion of a comprehensive cryptographic extension in the recent-most version of the AUTOSAR (AUTomotive Open System ARchitecture) stan-dard. In this work we try to give an answer on how prepared are current state-of-the-art automotive controllers for implementing cryptographic primitives and what is the exact cost of software implementations. We take into account automotive grade controllers that range from some of the most constrained platforms, e.g., from 8051 based tire sensors with 8-bit cores, up to 32-bit Infineon TriCore architectures, as well as devices that lay in between these two. We provide experimental results on several symmetric cryptographic primitives, i.e., block ciphers and hash functions, mainly focusing on the lightest constructions proposed in the literature, e.g., Speck, Katan, Blake, as well as on past or current standards, e.g., AES, SHA2 or SHA3. As expected, the results are sparse, some of the platforms being well prepared, capable to easily handle software implementation or carrying dedicated hardware, while for others no dedicated hardware exists while software implementation of current cryptographic standards cannot be handled, especially with the overhead incurred by the cohesion to the AUTOSAR standard.
Pal-Stefan Murvay, Alexandru Matei, Cristina Solomon, Bogdan Groza
ARES4
2016 Evaluating SRAM as Source for Fingerprints and Randomness on Automotive Grade Controllers
abstract
It is well known that the state of uninitialized SRAM provides a unique pattern on each device due to physical imperfections. Both the affinity toward some fixed state as well as the deviation from it can be successfully exploited in security mechanisms. Fixed values provide an efficient mechanism for physical identification and for extracting cryptographic keys while the randomness of bits that flip can be exploited as input for PRNGs that are vital for the generation of ephemeral keys. In this work we try to give an assessment of these two capabilities on several state-of-the art automotive grade embedded platforms. The security of embedded devices inside vehicles has gained serious attention in the past years due to the impact of emerging technologies, e.g., self-driving cars, vehicle-to-vehicle communication, which are futile in the absence of the appropriate security mechanisms. Our examination of several state-of-the-art automotive grade controllers shows that SRAM can offer sufficient entropy and patterns for identification but careful testing is needed as some models fail to provide the expected results
Bogdan Groza, Pal-Stefan Murvay, Tudor Andreica
SECRYPT1
2014 Cryptographic puzzles and DoS resilience, revisited
Bogdan Groza, Bogdan Warinschi
Des. Codes Cryptogr.1
2014 Source Identification Using Signal Characteristics in Controller Area Networks
abstract
The CAN (Controller Area Network) bus, i.e., the de facto standard for connecting ECUs inside cars, is increasingly becoming exposed to some of the most sophisticated security threats. Due to its broadcast nature and ID oriented communication, each node is sightless in regards to the source of the received messages and assuring source identification is an uneasy challenge. While recent research has focused on devising security in CAN networks by the use of cryptography at the protocol layer, such solutions are not always an alternative due to increased communication and computational overheads, not to mention backward compatibility issues. In this work we set steps for a distinct approach, namely, we try to take authentication up to unique physical characteristics of the frames that are placed by each node on the bus. For this we analyze the frames by taking measurements of the voltage, filtering the signal and examining mean square errors and convolutions in order to uniquely identify each potential sender. Our experimental results show that distinguishing between certain nodes is clearly possible and by clever choices of transceivers and frame IDs each message can be precisely linked to its sender.
Pal-Stefan Murvay, Bogdan Groza
IEEE Signal Process. Lett.2
2013 Bridging Dolev-Yao Adversaries and Control Systems with Time-Sensitive Channels
Bogdan Groza, Marius Minea
CRITIS1
2013 Efficient Protocols for Secure Broadcast in Controller Area Networks
abstract
Controller Area Network is a bus commonly used by controllers inside vehicles and in various industrial control applications. In the past controllers were assumed to operate in secure perimeters, but today these environments are well connected to the outside world and recent incidents showed them extremely vulnerable to cyber-attacks. To withstand such threats, one can implement security in the application layer of CAN. Here we design, refine and implement a broadcast authentication protocol based on the well known paradigm of using key-chains and time synchronization, a commonly used mechanism in wireless sensor networks, which allows us to take advantage from the use of symmetric primitives without the need of secret shared keys during broadcast. But, as process control is a time critical operation we make several refinements in order to improve on the authentication delay. For this we study several trade-offs to alleviate shortcomings on computational speed, memory and bandwidth up to the point of using reduced versions of hash functions that can assure ad hoc security. To prove the efficiency of the protocol we provide experimental results on two representative microcontrollers from the market: a Freescale S12X and an Infineon TriCore, both devices were specifically chosen as they are located somewhat on the extremes of computational power.
Bogdan Groza, Pal-Stefan Murvay
IEEE Trans. Ind. Informatics1
2012 LiBrA-CAN: A Lightweight Broadcast Authentication Protocol for Controller Area Networks
Bogdan Groza, Pal-Stefan Murvay, Anthony Van Herrewege, Ingrid Verbauwhede
CANS1
2012 Revisiting Difficulty Notions for Client Puzzles and DoS Resilience
Bogdan Groza, Bogdan Warinschi
ISC1
2012 SAPHE: simple accelerometer based wireless pairing with heuristic trees
abstract
Accelerometers provide a good source of entropy for bootstrapping a secure communication channel in autonomous and spontaneous interactions between mobile devices that share a common context but were not previously associated. We propose two simple and efficient key exchange protocols based on accelerometer data that use only simple hash functions combined with heuristic search trees. Using heuristics such as the Euclidean distance proves to be beneficial as it allows a more effective recovery of the shared key. While the first protocol seems to give just some performance improvements, the second, which we call hashed heuristic tree, is more secure than previous proposals since it increases the difference in protocol execution between benign and malicious parties. Nevertheless, the hashed heuristic tree is an entirely new approach which has the advantage of allowing different heuristics in the search, leaving plenty of room for future variants and optimizations.
Bogdan Groza, René Mayrhofer
MoMM1
2011 Some Security Issues in SCALANCE Wireless Industrial Networks
abstract
We discuss some security weaknesses of Scalance wireless access points and clients. These devices, developed by Siemens, are commonly used for wireless communication in network control systems. After the identification of the Stuxnet worm, which targeted PLCs from uranium enrichment facilities in Iran, these devices become of increased interest to the security community. Here we analyze them both in a static environment, at the configuration level, as well as in a dynamic environment where they are used for a remote control scenario. We show some vulnerabilities in both situations, in particular some weaknesses in the authentication protocol from their web-based configuration interface and an attack which halts the communication by using deauthentication packets. As proof-of-concept we simulate the evolution of a process which is controlled over the wireless network and could be seriously affected by an adversary unless a local controller is present for redundancy in case of communication failures.
Marius Cristea, Bogdan Groza, Mihai Iacob
ARES2
2011 Secure Broadcast with One-Time Signatures in Controller Area Networks
abstract
We use one-time signatures to assure authenticity for messages that are broadcast over a Controller Area Network (CAN). The advantage is that we can use the simplest one-way functions which are computationally efficient while authentication does not depend on disclosure delays as in the case of protocols based on one-way chains and time synchronization. As the size of the one-time signatures is proportional to the bit length of the signed message, another benefit in using them is due to the reduced size of messages that are broadcast in CAN. To avoid the use of authentication trees, which will allow multiple uses of the one-time signature, but increases the size of signatures as well as memory requirements, we use an upper layer of key-chains with time synchronization in order to commit the public keys that can be further used for signing at any instant. The theoretical results are followed by experimental results on development boards equipped with Free scale S12, a commonly used automotive grade microcontroller. We also benefit from the acceleration offered by the XGATE coprocessor available on S12X derivatives which significantly increases computational performances. To further increase efficiency we also design and use a hardware random number generator which saves computational time that otherwise will be spent to derive fresh key material.
Bogdan Groza, Pal-Stefan Murvay
ARES1
2011 Formal modelling and automatic detection of resource exhaustion attacks
abstract
Many common protocols: TCP, IPSec, etc., are vulnerable to denial of service attacks, where adversaries maliciously consume significant resources of honest principals, leading to resource exhaustion. We propose a set of cost-based rules that formalize DoS attacks by resource exhaustion and can automate their detection. Our classification separates excessive but legal protocol use (e.g., flooding) from illegal protocol manipulation that causes participants to waste computation time without reaching the protocol goals. We also distinguish simple intruder intervention leading to wasteful execution from DoS attacks proper, which can be repeatedly initiated. Our rules can highlight attacks that are undetectable by the targeted honest agents, or by all protocol participants. We have successfully tested an implementation of the methodology in a validation platform on relevant protocol examples, in what to the best of our knowledge is the first formal automated analysis of DoS attacks.
Bogdan Groza, Marius Minea
AsiaCCS1
2011 Performance improvements for SHA-3 finalists by exploiting microcontroller on-chip parallelism
abstract
As ubiquitous devices, microcontrollers are deployed in a great variety of applications many of which involve communication over insecure channels that require cryptography. Here we investigate the possibility of using on-chip coprocessors from currently available microcontrollers for increasing computational power by employing parallelism. For this we focus on the analysis of SHA-3 finalists in order to identify features that can lead to an efficient parallel implementation with on-chip coprocessors. Experimental results on a Freescale S12X family microcontroller equipped with an XGATE coprocessor are presented. In this two core environment, speedups between 18 and 73 percents are obtained for the five SHA-3 finalists. In our software implementations BLAKE proves to be the best performer, especially for short messages, followed at some range by Grøstl, then by Skein, Keccak and JH.
Pal-Stefan Murvay, Bogdan Groza
CRiSIS2
2011 Higher Layer Authentication for Broadcast in Controller Area Networks
Bogdan Groza, Pal-Stefan Murvay
SECRYPT1
2009 A Calculus to Detect Guessing Attacks
Bogdan Groza, Marius Minea
ISC1
2007 Broadcast Authentication Protocol with Time Synchronization and Quadratic Residues Chain
abstract
Assuring information authenticity is an important issue in the field of information security. A new broadcast authentication protocol is proposed. The protocol is based on time synchronization and uses chains constructed with the squaring function. The proposed solution is efficient for transmissions over long periods of time since the chains have an unbounded length. The protocol assures information authenticity at the reduced cost of almost one modular multiplication for each broadcasted packet. Time synchronization issues are discussed and the security of the protocol is equivalent to factoring since the squaring function is used. A failure mode analysis of the protocol is done; this is also an aspect of novelty and applies to other protocols based on time synchronization as well
Bogdan Groza
ARES1
2007 On the use of one-way chain based authentication protocols in secure control systems
abstract
The use of one-way chains in authentication protocols is a technique of great importance which has many applications. Employing cryptographic techniques in the area of industrial control systems has gained significant interest in the last few years. This paper proposes the use of a one-way chain based authentication protocol in a robust control system. Some enhancements of a generic one-way chain based authentication protocol are required by the scenario of secure robust and they are intended for achieving lower authentication delays and computational costs while preserving the control robust in the presence of potential attackers. We also underline that the techniques described in this paper are not restricted to the subject of authentication in robust control systems since the presented protocols may be useful for other applications as well
Bogdan Groza, Toma-Leonida Dragomir
ARES1