Christian Gehrmann 0001

dblp:61/2362-1 · DBLP profile ↗
← Back
35ranked-venue papers
10as first author
9since 2021 · last 2026
0000-0001-8003-200XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 20 · 4 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 first-author · 1 since 2021Computer networks · 3 · 2 first-authorSystems, architecture and hardware · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1
YearPublicationVenuePosition
2026 Lost in the Pages: WebAssembly Code Recovery Through SEV-SNP's Exposed Address Space
Markus Berthilsson, Christian Gehrmann 0001
ACISP (3)2
2026 DDoSimu5G: A Simulator to Model D2D Botnet DDoS Traffic Loads on 5G Components
abstract
5G networks are increasingly exposed to Distributed Denial of Service (DDoS) attacks launched by mobile botnets exploiting user equipment (UE). Existing studies have treated malware propagation and DDoS impact separately, with no prior simulation work having modeled how Device-to-Device (D2D) malware spreads and translates into network-wide DDoS stress. This paper introduces DDoSimu5G, an extension of Simu5G [33] integrated with the ONE simulator [24], which enables, for the first time, the combined modeling of D2D malware propagation, UE mobility, and botnet-driven traffic loads on 5G infrastructure. The framework is aligned with 3GPP Proximity based Services (ProSe) in the 5G System (5GS) TS 23.304 [1] specifications, supports configurable attack scenarios, and generates diverse datasets, including infection logs, mobility traces, and PCAP traffic. By linking propagation dynamics with DDoS effects, DDoSimu5G provides the research community with a reproducible open-source tool for studying and mitigating emerging D2D-driven threats in 5G networks.
Karim Khalil, Christian Gehrmann 0001, Sara Ramezanian, Jakob Sternby
SIGSIM-PADS2
2025 A Trust Establishment and Key Management Architecture for Hospital-at-Home
abstract
The landscape of healthcare is experiencing a digitalization shift, transferring many medical activities to the patients’ homes, a phenomenon commonly referred to as Hospital-at-Home. While Internet of Things (IoT) devices facilitate the building of such systems, there is a need for powerful middleware that encapsulates device-to-device communication and enables the construction of user-friendly, secure, and robust Hospital-at-Home systems. A key challenge for such middleware is to build a trustworthy and lightweight key management system allowing different devices in the system to exchange messages securely. In this article, we present a simple, easily manageable and scalable such architecture which, in addition, supports long-term data protection using post-quantum cryptographic primitives. Our proposed solution utilizes a Merkle tree to enable the IoT devices to establish trust between each other automatically, even in the absence of an Internet connection. We have implemented the architecture and present performance figures as well as a security analysis of our approach.
Alfred Åkesson, Christian Gehrmann 0001, Görel Hedin, Björn A. Johnsson, Boris Magnusson, Mattias Nordahl, Sara Ramezanian, Paul Stankovski Wagner
ACM Trans. Comput. Heal.2
2025 CyberROAD: A cybersecurity risk assessment ontology for automotive domain aligned with ISO/SAE 21434:2021
abstract
The automotive domain is becoming increasingly complex through the integration of new technologies. As a result, cybersecurity is recognized as a pressing issue. This study focuses on the ISO/SAE 21434:2021 standard for road vehicles cybersecurity engineering, evaluating the effectiveness of the standard’s risk assessment approach. The standard suggests a set of assessment steps, and previous research has shown that practitioners often face challenges during assessment execution. The absence of clear, structured guidelines within the standard leads to different interpretations, resulting in inconsistent assessment approaches. This inconsistency makes it difficult to compare and measure the quality of the assessments. Our study uses design science methodology to create a new cybersecurity risk assessment ontology in the automotive domain, describing the relationships and interdependencies between cybersecurity risk assessment activities, stakeholders, and work packages. The ontology model is evaluated in a case study at a leading automotive systems supplier to validate the model’s suitability for developing a cybersecurity risk assessment method. The findings indicate that the ontology model provides an improved understanding of the underlying risk assessment activities and allows for a structured method for extracting procedural steps according to the standard. This systematic approach increases the cybersecurity risk assessment conformity and the consistency of assessment results. In conclusion, this paper gives valuable insights and actionable recommendations for stakeholders, researchers, and organizations seeking to improve the cybersecurity risk assessment process in the automotive domain. • Knowledge representation of cybersecurity risk assessment in the automotive domain. • Formal ontology model for the ISO/SAE 21434:2021 standard risk assessment activities. • Defining inherent dependencies to process documentation and stakeholder roles. • Applying ontology model structures to develop risk assessment method in a case study. • Workflow diagrams are applied to improve the consistency of the analysis activities.
Karim Khalil, Christian Gehrmann 0001, Günther Vogel
J. Inf. Secur. Appl.2
2023 A Comprehensive Robustness Analysis of Storj DCS Under Coordinated DDoS Attack
abstract
Decentralized Cloud Storage (DCS) is considered to be the future for sustainable data storage within Web 3.0, in which we will move from a single cloud service provider to creating an ecosystem where anybody could be a cloud storage provider. Currently, the cloud storage market is highly dominated by centralized players like Amazon S3, Google Cloud, Box, etc. Decentralized projects like Storj, Filecoin, and Sia have seen rising popularity with the advent of Web 3.0 applications. At the same time, any blockchain network is susceptible to large-scale DDoS attacks. This work focuses on the Storj DCS, where we aimed to analyze the robustness of the system under the influence of a coordinated DDoS attack which can be carried out by an adversary or a group of adversaries taking down a set of storage nodes. The novelty of our work lies in threefold: First, we use statistical methods to mathematically model the content distribution as well as the loss of a file or a segment from the system. Our model captures both the cases where we have homogeneous and non-homogeneous nodes. Secondly, we develop a cost-analytic approach to perform a robustness analysis of the Storj system and implement the proposed model in MATLAB. Finally, we calculate the cost of a DDoS attack that the adversary has to incur in order to be successful with the attack. Also, we propose a set of better parametric choices for erasure piece distribution under which the system has proved to be more robust than the parametric values implemented in Storj DCS.
Rohon Kundu, Christian Gehrmann 0001, Maria Kihl
ICPADS2
2023 Attacks Against Mobility Prediction in 5G Networks
abstract
The 5thgeneration of mobile networks introduces a new Network Function (NF) that was not present in previous generations, namely the Network Data Analytics Function (NWDAF). Its primary objective is to provide advanced analytics services to various entities within the network and also towards external application services in the 5G ecosystem. One of the key use cases of NWDAF is mobility trajectory prediction, which aims to accurately support efficient mobility management of User Equipment (UE) in the network by allocating "just in time" necessary network resources. In this paper, we show that there are potential mobility attacks that can compromise the accuracy of these predictions. In a semi-realistic scenario with 10,000 subscribers, we demonstrate that an adversary equipped with the ability to hijack cellular mobile devices and clone them can significantly reduce the prediction accuracy from 75% to 40% using just 100 adversarial UEs. While a defense mechanism largely depends on the attack and the mobility types in a particular area, we prove that a basic KMeans clustering is effective in distinguishing legitimate and adversarial UEs.
Syafiq Al Atiiq, Yachao Yuan, Christian Gehrmann 0001, Jakob Sternby, Luis Barriga
TrustCom3
2023 Practical Privacy-Preserving Ride Sharing Protocol with Symmetric Key
abstract
The advancement of mobile technologies and their ability to utilize the Global Positioning System (GPS) to accurately locate their substantial number of users, prompt Location-Based Services (LBS) significantly. Ride-sharing is a popular means of transportation that utilizes LBS. With the rapid development of smart cities and their impact on addressing the critical issues of urban life such as transportation, we can safely assume that the autonomous vehicles (AVs) will be a desired way of transportation in the near future. Therefore, the ride sharing service (RSS) providers will need to arrange their services via AVs. However, a user who wants to use a RSS has to submit their trip data (which contains location data) to the service provider. On one hand, the popularity of RSSs makes them an attractive target for cyber-attacks, and on the other hand, multiple studies show that a user’s location data can reveal sensitive information about that user. In this paper, we present a practical ride-sharing protocol for AVs that preserves both anonymity and location privacy of the users. Most of the previous works on the topic, does not provide security against malicious server and/or clients. Moreover, the previously proposed protocols rely on additional entities (e.g., a trusted third party) to satisfy the objectives of their protocols. In the presence of the malicious entities, our proposed protocol guarantees the security and privacy of the server and the clients, without relying on any additional parties. To the best of our knowledge, our protocol is the first scheme that satisfies perfect location privacy. We evaluate the performance of our protocol in a realistic setting and demonstrate its feasibility in the real life application areas, i.e., the protocol only requires 20 milliseconds to process and respond to 1000 simultaneous ride-sharing requests. Moreover, we propose a novel private sum aggregation (PSA) scheme that is designed for the use-cases where the private elements are chosen from a limited set. We believe that our novel PSA scheme may be of independent interest.
Sara Ramezanian, Christian Gehrmann 0001
TrustCom2
2021 AppArmor Profile Generator as a Cloud Service
abstract
Along with the rapid development of containerization technology, remarkable benefits have been created for developers and operation teams, and overall software infrastructure. Although lots of effort has been devoted to enhancing containerization security, containerized environments still have a huge attack surface. This paper proposes a secure cloud service for generating a Linux security module, AppArmor profiles for containerized services. The profile generator service implements container runtime profiling to apply customized AppArmor policies to protect containerized services without the need to make hard and potentially error-prone manual policy configurations. To evaluate the effectiveness of the profile generator service, we enable it on a widely used containerized web service to generate profiles and test them with real-world attacks. We generate an exploit database with 11 exploits harmful to the tested web service. These exploits are sifted from the 56 exploits of Exploit- db targeting the tested web service’s software. We launch these exploits on the web service protected by the profile. The results show that the proposed profile generator service improves the test web service’s overall security a lot compared to using the default Docker security profile.
Christian Gehrmann 0001
CLOSER2
2021 Lic-Sec: An enhanced AppArmor Docker security profile generator
abstract
Along with the rapid development of cloud computing technology, containerization technology has drawn much attention from both industry and academia. In this paper, we perform a comparative measurement analysis of Docker-sec, which is a Linux Security Module proposed in 2018, and a new AppArmor profile generator called Lic-Sec, which combines Docker-sec with a modified version of LiCShield, which is also a Linux Security Module proposed in 2015. Docker-sec and LiCShield can be used to enhance Docker container security based on mandatory access control and allows protection of the container without manual configurations. Lic-Sec brings together their strengths and provides stronger protection. We evaluate the effectiveness and performance of Docker-sec and Lic-Sec by testing them with real-world attacks. We generate an exploit database with 40 exploits effective on Docker containers selected from the latest 400 exploits on Exploit-DB. We launch these exploits on containers spawned with Docker-sec and Lic-Sec separately. Our evaluations show that for demanding images, Lic-Sec gives protection for all privilege escalation attacks for which Docker-sec and LiCShield failed to give protection.
Christian Gehrmann 0001
J. Inf. Secur. Appl.2
2020 Secure Ownership Transfer for the Internet of Things
abstract
With the increasing number of IoT devices deployed, the problem of switching ownership of devices is becoming more apparent. Especially, there is a need for transfer protocols not only addressing a single unit ownership transfer but secure transfer of a complete infrastructure of IoT units including also resource constraint devices. In this paper we present our novel ownership transfer protocol for an infrastructure of IoT devices. The protocol is light-weight as it only uses symmetric key operations on the IoT side. The ownership transfer protocol is carefully security evaluated both using a theoretical analysis and with automatic protocol verification. In addition, we show the feasibility of the ownership transfer protocol through a proof of concept implementation including performance figures.
Martin Gunnarsson, Christian Gehrmann 0001
ICISSP2
2020 A Digital Twin Based Industrial Automation and Control System Security Architecture
abstract
The digital twin is a rather new industrial control and automation systems concept. While the approach so far has gained interest mainly due to capabilities to make advanced simulations and optimizations, recently the possibilities for enhanced security have got attention within the research community. In this article, we discuss how a digital twin replication model and corresponding security architecture can be used to allow data sharing and control of security-critical processes. We identify design-driving security requirements for digital twin based data sharing and control. We show that the proposed state synchronization design meets the expected digital twin synchronization requirements and give a high-level design and evaluation of other security components of the architecture. We also make performance evaluations of a proof of concept for protected software upgrade using the proposed digital twin design. Our new security framework provides a foundation for future research work in this promising new area.
Christian Gehrmann 0001, Martin Gunnarsson
IEEE Trans. Ind. Informatics1
2019 An Identity Privacy Preserving IoT Data Protection Scheme for Cloud Based Analytics
abstract
Efficient protection of huge amount of IoT produced data is key for wide scale data analytic services. The most efficient way is to use pure symmetric encryption as that allows both fast decryption at the analytic engine side as well as energy efficient encryption at the IoT side. However, symmetric encryption can only be performed if there is a way to directly map an encrypted object to the correct key. Typically, such mapping require a unique IoT identity, which constitute a privacy problem. In this paper, we present an IoT identity protection scheme for symmetric IoT data encryption. We give basic security definitions for this problem setting, present a new construction and give security proofs of security level achieved with the construction. Performance figures for a proof of concept implementation are also given. The new scheme gives a fair trade-off between identity privacy and complexity.
Christian Gehrmann 0001, Martin Gunnarsson
IEEE BigData1
2019 SDN Access Control for the Masses
Nicolae Paladi, Christian Gehrmann 0001
Comput. Secur.2
2019 Metadata filtering for user-friendly centralized biometric authentication
abstract
While biometric authentication for commercial use so far mainly has been used for local device unlock use cases, there are great opportunities for using it also for central authentication such as for remote login. However, many current biometric sensors like for instance mobile fingerprint sensors have too large false acceptance rate (FAR) not allowing them, for security reasons, to be used in larger user group for central identification purposes. A straightforward way to avoid this FAR problem is to either request a user unique identifier such as a device identifier or require the user to enter a unique user ID prior to making the biometric matching. Usage of a device identifier does not work when a user desires to authenticate on a previously unused device of a generic type. Furthermore, requiring the user at each login occasion to enter a unique user ID, is not at all user-friendly. To avoid this problem, we in this paper investigate an alternative, most user-friendly approach, for identification in combination with biometric-based authentication using metadata filtering. An evaluation of the adopted approach is carried out using realistic simulations of the Swedish population to assess the feasibility of the proposed system. The results show that metadata filtering in combination with traditional biometric-based matching is indeed a powerful tool for providing reliable, and user-friendly, central authentication services for large user groups.
Christian Gehrmann 0001, Marcus Rodan, Niklas Jönsson
EURASIP J. Inf. Secur.1
2018 Practical Attacks on Relational Databases Protected via Searchable Encryption
Mohamed Ahmed Abdelraheem, Tobias Andersson, Christian Gehrmann 0001, Cornelius Glackin
ISC3
2017 Providing User Security Guarantees in Public Infrastructure Clouds
abstract
The infrastructure cloud (IaaS) service model offers improved resource flexibility and availability, where tenants - insulated from the minutiae of hardware maintenance - rent computing resources to deploy and operate complex systems. Large-scale services running on IaaS platforms demonstrate the viability of this model; nevertheless, many organizations operating on sensitive data avoid migrating operations to IaaS platforms due to security concerns. In this paper, we describe a framework for data and operation security in IaaS, consisting of protocols for a trusted launch of virtual machines and domain-based storage protection. We continue with an extensive theoretical analysis with proofs about protocol resistance against attacks in the defined threat model. The protocols allow trust to be established by remotely attesting host platform configuration prior to launching guest virtual machines and ensure confidentiality of data in remote storage, with encryption keys maintained outside of the IaaS domain. Presented experimental results demonstrate the validity and efficiency of the proposed protocols. The framework prototype was implemented on a test bed operating a public electronic health record system, showing that the proposed protocols can be integrated into existing cloud environments.
Nicolae Paladi, Christian Gehrmann 0001, Antonis Michalas
IEEE Trans. Cloud Comput.2
2016 IoT Protection through Device to Cloud Synchronization
abstract
This paper addresses the problem of protecting distributed IoT units from network based attacks while still having a high level of availability. In particular we suggest a novel method where the IoT device execution state is modeled with a suitable high level application model and where the execution state of the application of the IoT device is "mirrored" in a cloud executed machine. This machine has very high availability and high attack resistance. The IoT device will only communicate with the mirror machine in the cloud using a dedicated synchronization protocol. All essential IoT state information and state manipulations are communicated through this synchronization protocol while all end application communication directed towards the IoT units is done towards the mirror machine in the cloud. This gives a very robust and secure system with high availability at the price of slower responses. However, for many non-real time IoT application with high security demands this performance penalty can be justified.
Christian Gehrmann 0001, Mohamed Ahmed Abdelraheem
CloudCom1
2016 Threats to 5G Group-based Authentication
abstract
The fifth generation wireless system (5G) is expected to handle an unpredictable number of heterogeneous connected devices and to guarantee at least the same level of security provided by the contemporary wireless standards, including the Authentication and Key Agreement (AKA) protocol. The current AKA protocol has not been designed to efficiently support a very large number of devices. Hence, a new group-based AKA protocol is expected to be one of the security enhancement introduced in 5G. In this paper, we advance the group-based AKA threat model, reflecting previously neglected security risks. The threat model presented in the paper paves the way for the design of more secure protocols.
Rosario Giustolisi, Christian Gehrmann 0001
SECRYPT2
2016 TruSDN: Bootstrapping Trust in Cloud Network Infrastructure
Nicolae Paladi, Christian Gehrmann 0001
SecureComm2
2015 SMACK: Short message authentication check against battery exhaustion in the Internet of Things
abstract
Internet of Things (IoT) commonly identifies the upcoming network society where all connectable devices will be able to communicate with one another. In addition, IoT devices are supposed to be directly connected to the Internet, and many of them are likely to be battery powered. Hence, they are particularly vulnerable to Denial of Service (DoS) attacks specifically aimed at quickly draining battery and severely reducing device lifetime. In this paper, we propose SMACK, a security service which efficiently identifies invalid messages early after their reception, by checking a short and lightweight Message Authentication Code (MAC). So doing, further useless processing on invalid messages can be avoided, thus reducing the impact of DoS attacks and preserving battery life. In particular, we provide an adaptation of SMACK for the standard Constrained Application Protocol (CoAP). Finally, we experimentally evaluate SMACK performance through our prototype implementation for the resource constrained CC2538 platform. Our results show that SMACK is efficient and affordable in terms of memory requirements, computing time, and energy consumption.
Christian Gehrmann 0001, Marco Tiloca, Rikard Hoglund
SECON1
2015 ASArP: Automated Security Assessment & Audit of Remote Platforms using TCG-SCAP synergies
Mudassar Aslam, Christian Gehrmann 0001, Mats Björkman
J. Inf. Secur. Appl.2
2014 Security aspects of e-Health systems migration to the cloud
abstract
As adoption of e-health solutions advances, new computing paradigms - such as cloud computing - bring the potential to improve efficiency in managing medical health records and help reduce costs. However, these opportunities introduce new security risks which can not be ignored. Based on our experience with deploying part of the Swedish electronic health records management system in an infrastructure cloud, we make an overview of major requirements that must be considered when migrating e-health systems to the cloud. Furthermore, we describe in-depth a new attack vector inherent to cloud deployments and present a novel data confidentiality and integrity protection mechanism for infrastructure clouds. This contribution aims to encourage exchange of best practices and lessons learned in migrating public e-health systems to the cloud.
Antonis Michalas, Nicolae Paladi, Christian Gehrmann 0001
Healthcom3
2014 Trusted Geolocation-Aware Data Placement in Infrastructure Clouds
abstract
Data geolocation in the cloud is becoming an increasingly pressing problem, aggravated by incompatible legislation in different jurisdictions and compliance requirements of data owners. In this work we present a mechanism allowing cloud users to control the geographical location of their data, stored or processed in plaintext on the premises of Infrastructure-as-a Service cloud providers. We use trusted computing principles and remote attestation to establish platform state. We enable cloud users to confine plaintext data exclusively to the jurisdictions they specify, by sealing decryption keys used to obtain plaintext data to the combination of cloud host geolocation and platform state. We provide a detailed description of the implementation as well as performance measurements on an open source cloud infrastructure platform using commodity hardware.
Nicolae Paladi, Mudassar Aslam, Christian Gehrmann 0001
TrustCom3
2014 Avoiding weak parameters in secret image sharing
abstract
Secret image sharing is a popular image hiding scheme that typically uses (3, 3, n) multi-secret sharing to hide the colors of a secret image. The use of (3, 3, n) multi-secret sharing, however, can lead to information loss. In this paper, we study this loss of information from an image perspective, and show that one-third of the color values of the secret image can be leaked when the sum of any two selected share numbers is equal to the considered prime number in the secret sharing. Furthermore, we show that if the selected share numbers do not satisfy this condition (for example, when the value of each of the selected share number is less than the half of the value of the prime number), then the colors of the secret image are not leaked. In this case, a noise-like image is reconstructed from the knowledge of less than three shares.
Manoranjan Mohanty, Christian Gehrmann 0001, Pradeep K. Atrey
VCIP2
2013 Continuous security evaluation and auditing of remote platforms by combining trusted computing and security automation techniques
abstract
In many new distributed systems paradigms such a cloud computing, Internet of Things (IoT), electronic banking, etc. the security of the host platforms is very critical which is managed by the platform owner. The platform administrators use security automation techniques such as those provided by Security Content Automation Protocol (SCAP) standards to ensure that the outsourced platforms are set up correctly and follow the security recommendations (governmental or industry). However, the remote platform users still have to trust the platform administrators. The third party security audits, used to shift the required user trust from the platform owner to a trusted entity, are scheduled and are not very frequent to deal with the daily reported vulnerabilities which can be exploited by the attackers. In this paper we propose a remote platform evaluation mechanism which can be used by the remote platform users themselves, or by the auditors to perform frequent platform security audits for the platform users. We analyze the existing SCAP and trusted computing (TCG) standards for our solution, identify their shortcomings, and suggest ways to integrate them. Our proposed platform security evaluation framework uses the synergy of TCG and SCAP to address the limitations of each technology when used separately.
Mudassar Aslam, Christian Gehrmann 0001, Mats Björkman
SIN2
2013 Authorization framework for the Internet-of-Things
abstract
This paper describes a framework that allows fine-grained and flexible access control to connected devices with very limited processing power and memory. We propose a set of security and performance requirements for this setting and derive an authorization framework distributing processing costs between constrained devices and less constrained back-end servers while keeping message exchanges with the constrained devices at a minimum. As a proof of concept we present performance results from a prototype implementing the device part of the framework.
Ludwig Seitz, Göran Selander, Christian Gehrmann 0001
WOWMOM3
2012 Securely Launching Virtual Machines on Trustworthy Platforms in a Public Cloud - An Enterprise's Perspective
Mudassar Aslam, Christian Gehrmann 0001, Lars Rasmusson, Mats Björkman
CLOSER2
2012 Security and Trust Preserving VM Migrations in Public Clouds
abstract
In this paper we consider the security and trust implications of virtual machine (VM) migration from one cloud platform to the other in an Infrastructure-as-a-Service (IaaS) cloud service model. We show how to extend and complement previous Trusted Computing techniques for secure VM launch to also cover the VM migration case. In particular, we propose a Trust_Token based VM migration protocol which guarantees that the user VM can only be migrated to a trustworthy cloud platform. Different from previous schemes, our solution is not dependent on an active (on-line) trusted third party. We show how our proposed mechanisms fulfill major security and trust requirements for secure VM migration in cloud environments.
Mudassar Aslam, Christian Gehrmann 0001, Mats Björkman
TrustCom2
2011 Are there good reasons for protecting mobile phones with hypervisors?
abstract
Security threats on consumer devices such as mobile phones are increasing as the software platforms become more open and complex. Therefore, hypervisors, which bring potential new secure services to embedded systems, are becoming increasingly important. In this paper, we look into how to design a hypervisor-based security architecture for an advanced mobile phone. Key security components of the architecture have been verified through a hypervisor implemented on an emulated ARM platform. We compare the hypervisor security architecture with TrustZone and summarize the major benefits and limitations of the hypervisor approach. In short, hypervisors exhibit several advantages such as support of multiple secure execution domains and monitoring of non-trusted domains; however, this comes at the cost of larger legacy system porting efforts.
Christian Gehrmann 0001, Heradon Douglas, Dennis Kengo Nilsson
CCNC1
2000 Securing ad hoc services, a Jini view: extended abstract
abstract
Problems with securing ad hoc services are discussed. How authentication and key exchange for ad hoc services can be performed are shown. We use a simple trust model for the participants in an ad hoc network. We show how to create an authenticated secure ad hoc connection using, for example, the Java/Jini environment.
Christian Gehrmann 0001, Pekka Nikander
MobiHoc1
1998 Unconditionally Secure Group Authentication
Marten van Dijk, Christian Gehrmann 0001, Ben J. M. Smeets
Des. Codes Cryptogr.2
1998 Multiround Unconditionally Secure Authentication
Christian Gehrmann 0001
Des. Codes Cryptogr.1
1997 Fast Message Authentication Using Efficient Polynomial Evaluation
Valentin B. Afanassiev, Christian Gehrmann 0001, Ben J. M. Smeets
FSE2
1995 Secure Multiround Authentication Protocols
Christian Gehrmann 0001
EUROCRYPT1
1994 Cryptanalysis of the Gemmell and Naor Multiround Authentication Protocol
Christian Gehrmann 0001
CRYPTO1