Frederik Armknecht

dblp:65/6856 · DBLP profile ↗
← Back
51ranked-venue papers
35as first author
15since 2021 · last 2026
0009-0003-9935-8095ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 45 · 29 first-author · 14 since 2021Computer networks · 4 · 4 first-authorSystems, architecture and hardware · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Theory of computation · 1 · 1 first-author
YearPublicationVenuePosition
2026 NEPAL: Climbing Beyond the Limits of Graph Matching Attacks in Privacy-Preserving Record Linkage
Marcel Mildenberger, Jochen Schäfer, Frederik Armknecht
ACNS (2)3
2026 A New Construction Method for More Efficient Quadratic One-Time Noisy Multi-Client Functional Encryption Schemes
abstract
We introduce a new construction method for one-time multi-client functional encryption schemes that support noisy quadratic functions, are resistant against corruption and allow for labels. Such schemes can be used as building blocks in many practical applications, e.g. privacy-preserving machine learning on arbitrarily split data. In contrast to earlier constructions, ours uses a different structural design that allows to make use of less complex, hence more efficient building blocks. The security of our construction relies solely on its underlying building blocks and no additional hardness assumptions, making it more generic than related work. More specifically, the construction itself does not rely on structures given by bilinear groups.
Jasmin Zalonis, Linda Scheu-Hachtel, Frederik Armknecht
AsiaCCS3
2026 Breaking BAD? Better Call SAUL! - Breaking and Fixing Bloom Filters with Added Diffusion
abstract
Merging records from two databases by comparing quasi-identifiers such as names or addresses is a frequently occurring task in many academic and administrative domains. Privacy-Preserving Record Linkage (PPRL) techniques aim to provide a way of computing the similarities between quasi-identifiers without revealing the plaintext data. In practice, PPRL is usually performed by applying a similarity-preserving encoding to the data and comparing similarities on the encoded data only. However, recent research demonstrated that all standard PPRL encoding schemes, with the exception of Bloom filters with added diffusion (BAD), are vulnerable to Graph Matching Attacks and should no longer be considered secure. In this paper, we identify two properties of BAD that leak information about the plaintext to an attacker. We then proceed to show that these leaks make BAD vulnerable to an adapted variant of graph matching attacks. The newly proposed Homomorphism-based Graph Matching Attack is capable of re-identifying up to 91.6% of BAD-encoded records, thereby breaking the only remaining secure encoding scheme. As a remedy, we present a new Scheme for Anonymous, Utility-preserving Linkage (SAUL), which is not only robust against our new attack and all previous ones, but also outperforms the state of the art in terms of linkage quality.
Frederik Armknecht, Jochen Schäfer
Proc. Priv. Enhancing Technol.1
2025 A New Quadratic Noisy Functional Encryption Scheme and Its Application for Privacy Preserving Machine Learning
Jasmin Zalonis, Linda Scheu-Hachtel, Frederik Armknecht
ACNS (3)3
2024 Practical Light Clients for Committee-Based Blockchains
abstract
Light clients are gaining increasing attention in the literature since they obviate the need for users to set up dedicated blockchain full nodes. While the literature features a number of light client instantiations, most light client protocols optimize for long offline phases and implicitly assume that the block headers to be verified are signed by highly dynamic validators.In this paper, we show that (i) most light clients are rarely offline for more than a week, and (ii) validators are unlikely to drastically change in most permissioned blockchains and in a number of permissionless blockchains, such as Cosmos and Polkadot. Motivated by these findings, we propose a novel practical system that optimizes for such realistic assumptions and achieves minimal communication and computational costs for light clients when compared to existing protocols. By means of a prototype implementation of our solution, we show that our protocol achieves a reduction by up to 90 and 40000× (respectively) in end-to-end latency and up to 1000 and 10000× (respectively) smaller proof size when compared to two state-of-the-art light client instantiations from the literature.
Frederik Armknecht, Ghassan Karame, Malcom Mohamed, Christiane Weis
ACSAC1
2024 R+R: Revisiting Graph Matching Attacks on Privacy-Preserving Record Linkage
abstract
Privacy-Preserving Record Linkage (PPRL) is a method of privately linking data records from different sources that refer to the same person. This can be achieved by applying a similarity-preserving encoding to quasi-identifiers. Linkage is then performed based on the similarities of the encoded data only, thereby protecting the identities included.The Graph Matching Attack (GMA) presented by Vidanage et al. (CIKM 2020) appears to significantly compromise the security of all PPRL schemes that rely on such similarity-preserving encodings. Their experiments demonstrate that an attacker can successfully re-identify plaintext records in the encoded database by leveraging similarity relationships.In this paper, we reproduce and replicate the work of Vidanage et al. While we were able to successfully reproduce their results using the original attack code, a replication using our own re-implementation of the attack failed. Further analysis revealed that the original attack’s success depends on an undocumented preprocessing step and the choice of a random seed. In response, we present a new and improved GMA based on unsupervised machine learning. Our proposed methodology overcomes the limitations of the state-of-the-art attack and outperforms it significantly in both success rate and robustness. Even in scenarios with highly limited attacker knowledge, re-identification rates of up to 100% can be achieved.
Jochen Schäfer, Frederik Armknecht, Youzhe Heng
ACSAC2
2024 Buy Crypto, Sell Privacy: Investigating the Cryptocurrency Exchange Evonax
abstract
In their study of the cryptocurrency exchange ShapeShift, Yousaf et al. (USENIX Security, 2019) have demonstrated that information provided by the APIs of exchange platforms can facilitate cross-chain traceability and thus severely hurt user privacy. Unfortunately, little empirical research on exchanges is available otherwise. In this paper, we replicate and extend the approach of Yousaf et al. by developing new methods to extract transactions using the public blockchain and the interface of the cryptocurrency exchange Evonax. We are able to identify 30,402 transactions between the launch of Evonax in February 2018 and December 31, 2022, which should be close to a complete set of all transactions. This allows us to generate deep insights into the operations of the platform as well as the behavior of its users.
Alexander Brechlin, Jochen Schäfer, Frederik Armknecht
ICBC3
2024 Towards a Cryptographic Model for Wireless Communication
abstract
The Man-in-the-Middle Model (MitMM) is commonly used in cryptography for modeling an attacker in multiparty scenarios.It essentially assumes that the attacker fully controls the communication between all parties, i. e., can stop and modify messages at her discretion.We argue that this model is too strong for realistically capturing the case of wireless communication.In consequence, schemes that exploit properties of wireless communication such as friendly jamming or distance bounding, cannot be analyzed in a common framework.Moreover, the lack of an appropriate model hinders the development of new schemes.Given the ever-increasing importance of wireless communication, e. g., in the context of the Internet of Things, we propose a new formal model for wireless communication.Starting from the formal MitMM, we identify three key aspects -communication channels, signals, and locality -that are not represented, explain how to extend the model accordingly, and propose a tailored WCM.Based thereon, we explain how these limit the capabilities of an attacker in the form of a WAM.Moreover, we demonstrate for an existing security mechanism, namely friendly jamming, which is not covered by the MitMM how the new model allows for analyzing/formalizing the security.
Frederik Armknecht, Christian Müller 0015
SECRYPT1
2024 Larger-scale Nakamoto-style Blockchains Don't Necessarily Offer Better Security
abstract
Extensive research on Nakamoto-style consensus protocols has shown that network delays degrade the security of these protocols. Established results indicate that, perhaps surprisingly, maximal security is achieved when the network is as small as two nodes due to increased delays in larger networks. This contradicts the very foundation of blockchains, namely that decentralization improves security.In this paper, we take a closer look at how the network scale affects security of Nakamoto-style blockchains. We argue that a crucial aspect has been neglected in existing security models: the larger the network, the harder it is for an attacker to control a significant amount of power. To this end, we introduce a probabilistic corruption model to express the increasing difficulty for an attacker to corrupt resources in larger networks. Based on our model, we analyze the impact of the number of nodes on the (maximum) network delay and the fraction of adversarial power. In particular, we show that (1) increasing the number of nodes eventually violates security, but (2) relying on a small number of nodes does not provide decent security provisions either. We then validate our analysis by means of an empirical evaluation emulating hundreds of thousands of nodes in deployments such as Bitcoin, Monero, Cardano, and Ethereum Classic. Based on our empirical analysis, we concretely analyze the impact of various real-world parameters and configurations on the consistency bounds in existing deployments and on the adversarial power that can be tolerated while providing security. As far as we are aware, this is the first work that analytically and empirically explores the real-world tradeoffs achieved by current popular Nakamoto-style deployments.
Jannik Albrecht, Sébastien Andreina, Frederik Armknecht, Ghassan Karame, Giorgia Azzurra Marson, Julian Willingmann
SP3
2024 Differentially Private Functional Encryption
abstract
We address the question of realizing privacy preserving analysis of user data. The abstract scenario considered is that an analyst aims to evaluate a function f on some user data X. To achieve comprehensive privacy, it is necessary to protect the input X directly. However, it is known that f(X) may leak too much information about X as well. A common approach to mitigate such risks is to make the computation differential private. In practice, this is often accomplished by replacing f by a noisy variant f^*. We investigate the use of multi-input functional encryption (MIFE) for achieving input- and output-privacy in one cryptographic mechanism. In a MIFE scheme, a setup authority can generate restricted decryption keys which enable to learn specific functions of encrypted messages, without revealing any additional information. To achieve differential privacy in this process, we introduce as a new cryptographic primitive: noisy multi-input functional encryption (NMIFE). It extends the concept of MIFE such that the decryption key may also encode a noisy function where the noise value is secret. While the change from MIFE to NMIFE is rather straightforward, the challenge is to come up with precise and workable definitions of correctness and security definition that we propose and explain in this work. Here, the security definition is tailored to the use case of differential privacy. As it is a special case of the established notion of full-hiding security, we present a generic transformation that allows to turn any full-hiding MIFE scheme into a secure NMIFE scheme that has practically the same performance as the initial MIFE scheme. Moreover, we make use of the fact that the proposed security definition is less restrictive and present a new concrete NMIFE scheme for evaluating the inner product. It is dubbed DiffPIPE (short for DIFFerentially Private Inner Product Evaluation). DiffPIPE is not the result from the transformation and outperforms all from existing full-hiding MIFE schemes constructed NMIFE schemes. In experiments, we demonstrate its applicability for realizing privacy preserving counting queries on data sets.
Jasmin Zalonis, Frederik Armknecht, Linda Scheu-Hachtel
Proc. Priv. Enhancing Technol.2
2023 Strengthening Privacy-Preserving Record Linkage using Diffusion
abstract
Linking personal records from different databases is an essential step in many data workflows. Privacy-Preserving Record-Linkage (PPRL) techniques have been developed to link persons despite errors in the identifiers without violating their privacy. Designing efficient PPRL schemes with high linkage quality and a strong level of privacy protection is challenging. PPRL based on Bloom filter encoding (BF) is currently one of the most popular methods as they offer high efficiency and linkage quality. However, it turned out that these schemes are vulnerable to several attacks, with pattern mining and graph matching attacks considered to be the most serious by far. While several proposals have been made to strengthen BF-based PPRL schemes against these attacks, all these lack a proper security analysis or do not preserve the high efficiency and linkage quality. This paper shows that both problems can be addressed by extending the scheme with an appropriate linear diffusion layer. As opposed to previous schemes, we provide extensive theoretical and experimental analysis that confirms that the resulting scheme provides high efficiency and linkage quality and significantly increases security against the attacks mentioned above.
Frederik Armknecht, Youzhe Heng, Rainer Schnell
Proc. Priv. Enhancing Technol.1
2022 If You Like Me, Please Don't "Like" Me: Inferring Vendor Bitcoin Addresses From Positive Reviews
abstract
Abstract Bitcoin and similar cryptocurrencies are becoming increasingly popular as a payment method in both legitimate and illegitimate online markets. Such markets usually deploy a review system that allows users to rate their purchases and help others to determine reliable vendors. Consequently, vendors are interested into accumulating as many positive reviews (likes) as possible and to make these public. However, we present an attack that exploits these publicly available information to identify cryptocurrency addresses potentially belonging to vendors. In its basic variant, it focuses on vendors that reuse their addresses. We also show an extended variant that copes with the case that addresses are used only once. We demonstrate the applicability of the attack by modeling Bitcoin transactions based on vendor reviews of two separate darknet markets and retrieve matching transactions from the blockchain. By doing so, we can identify Bitcoin addresses likely belonging to darknet market vendors.
Jochen Schäfer, Christian Müller 0015, Frederik Armknecht
Proc. Priv. Enhancing Technol.3
2021 How to Take Over Drones
abstract
The number of unmanned aerial vehicles (UAV) (hereinafter referred to as drone) is rising in both, private and commercial applications. This makes it necessary that a drone remains under full control of the owner at any time. Most drones are controlled wirelessly by protocols in the 2.4 GHz band. The most commonly used protocols are DSMX (Spektrum), ACCST D16 EU-LBT (FrSky), DEVO (Walkera) and S-FHSS (Futaba). While it has been known that the DSMX protocol is vulnerable to attacks, the security of the other protocols was an open question.
Sebastian Plotz, Frederik Armknecht, Christian Bunse
AsiaCCS2
2021 Regulating Storage Overhead in Existing PoW-based Blockchains
abstract
Proof of Work (PoW) blockchains regulate the frequency and security of extensions to the blockchain in a decentralized manner by adjusting the difficulty in the network. However, analogous decentralized measures to regulate the replication level of the associated transactions and blocks data are completely missing so far. We argue that such measures are required as well. On the one hand, the smaller the number of replicas, the higher the vulnerability of the system against compromises and DoS-attacks. On the other hand, the larger the number of replicas, the higher the storage overhead, and the higher the operational blockchain cost are. In this paper, we propose a novel solution, EWoK (Entangled proofs of WOrk and Knowledge), that regulates in a decentralized manner the minimum number of replicas that should be stored by miners in the blockchain. EWoK achieves this by tying replication to the only directly-incentivized process in PoW-blockchains -- which is PoW itself. EWoK only incurs small modifications to existing PoW protocols and is fully compliant with the specifications of existing mining hardware. Our implementation results confirm that EWoK can be easily integrated within existing mining pool protocols, such as GetBlockTemplate and Stratum mining, and does not impair the mining efficiency.
Frederik Armknecht, Jens-Matthias Bohli, Ghassan Karame, Wenting Li 0001
SACMAT1
2021 Outsourcing Proofs of Retrievability
abstract
Proofs of Retrievability (POR) are cryptographic proofs that enable a cloud provider to prove that a user can retrieve his file in its entirety. POR need to be frequently executed by the user to ensure that their files stored in the cloud can be fully retrieved at any point in time. To conduct and verify POR, users need to be equipped with devices that have network access, and that can tolerate the (non-negligible) computational overhead incurred by the verification process. This clearly hinders the large-scale adoption of POR by cloud users, since many users increasingly rely on portable devices that have limited computational capacity, or might not always have network access. In this paper, we introduce the notion of outsourced proofs of retrievability (OPOR), in which users can task an external auditor to perform and verify POR with the cloud provider. We argue that the OPOR setting is subject to security risks that have not been covered by existing POR security models. To remedy that, we propose a formal framework and a security model for OPOR. We then propose a generic procedure for transforming a public POR into an OPOR and we show the security of the resulting OPOR in our proposed security model. We demonstrate the transformation on two different instantiations of public POR schemes due to Shacham and Waters (Asiacrypt'08)-one based on BLS signatures and one using RSA signatures. A shortcoming of this transformation is that the generated OPOR inherits the high computational overhead from the underlying public key cryptography. Consequently, we propose afterwards an OPOR that is build from a private POR by Shacham and Waters. We implement a prototype based on our solutions, and evaluate their performance in a realistic cloud setting. Our evaluation results show that our proposals minimize user effort, and incur negligible overhead on the auditor.
Frederik Armknecht, Jens-Matthias Bohli, Ghassan Karame, Wenting Li 0001
IEEE Trans. Cloud Comput.1
2020 ProMACs: Progressive and Resynchronizing MACs for Continuous Efficient Authentication of Message Streams
abstract
Efficiently integrity verification of received data requires Message Authentication Code (MAC) tags. However, while security calls for rather long tags, in many scenarios this contradicts other requirements. Examples are strict delay requirements (e.g., robot or drone control) or resource-scarce settings (e.g., LoRaWAN networks with limited battery capacity).
Frederik Armknecht, Paul Walther, Gene Tsudik, Martin Beck, Thorsten Strufe
CCS1
2019 Privacy implications of room climate data
abstract
Smart heating applications promise to increase energy efficiency and comfort by collecting and processing room climate data. While it has been suspected that the sensed data may leak crucial personal information about the occupants, this belief has up until now not been supported by evidence. In this work, we investigate privacy risks arising from the collection of room climate measurements. We assume that an attacker has access to the most basic measurements only: temperature and relative humidity. We train machine learning classifiers to predict the presence and number of room occupants and to discriminate between different types of activities. On data that was collected at three different locations, we show that occupancy can be detected from data measured by a single sensor with up to [Formula: see text] accuracy. One can even distinguish between the cases that no, one, or two persons are present with up to [Formula: see text] accuracy. Moreover, the four actions reading, working on a PC, standing, and walking, can be discriminated with up to [Formula: see text] accuracy, which is likewise clearly better than guessing ([Formula: see text]). Constraining the set of actions allows to achieve even higher prediction rates. For example, we discriminate standing and walking occupants with [Formula: see text] accuracy. In addition, we show that the accuracy can be increased in most cases if an attacker has access to measurements from two different sensors located in the same room. Our results provide evidence that even the leakage of such ‘inconspicuous’ data as temperature and relative humidity can seriously violate privacy.
Frederik Armknecht, Zinaida Benenson, Philipp Morgner, Christian Müller 0015, Christian Riess
J. Comput. Secur.1
2018 Unsupervised Machine Learning on Encrypted Data
Angela Jäschke, Frederik Armknecht
SAC2
2017 (Finite) Field Work: Choosing the Best Encoding of Numbers for FHE Computation
Angela Jäschke, Frederik Armknecht
CANS2
2017 Side Channels in Deduplication: Trade-offs between Leakage and Efficiency
abstract
Deduplication removes redundant copies of files or data blocks stored on the cloud. Client-side deduplication, where the client only uploads the file upon the request of the server, provides major storage and bandwidth savings, but introduces a number of security concerns. Harnik et al. (2010) showed how cross-user client-side deduplication inherently gives the adversary access to a (noisy) side-channel that may divulge whether or not a particular file is stored on the server, leading to leakage of user information. We provide formal definitions for deduplication strategies and their security in terms of adversarial advantage. Using these definitions, we provide a criterion for designing good strategies and then prove a bound characterizing the necessary trade-off between security and efficiency.
Frederik Armknecht, Colin Boyd, Gareth T. Davies, Kristian Gjøsteen, Mohsen Toorani
AsiaCCS1
2017 Sharing Proofs of Retrievability across Tenants
abstract
Proofs of Retrievability (POR) are cryptographic proofs which provide assurance to a single tenant (who creates tags using his secret material) that his files can be retrieved in their entirety. However, POR schemes completely ignore storage-efficiency concepts, such as multi-tenancy and data deduplication, which are being widely utilized by existing cloud storage providers. Namely, in deduplicated storage systems, existing POR schemes would incur an additional overhead for storing tenants' tags which grows linearly with the number of users deduplicating the same file. This overhead clearly reduces the (economic) incentives of cloud providers to integrate existing POR/PDP solutions in their offerings. In this paper, we propose a novel storage-efficient POR, dubbed SPORT, which transparently supports multi-tenancy and data deduplication. More specifically, SPORT enables tenants to securely share the same POR tags in order to verify the integrity of their deduplicated files. By doing so, SPORT considerably reduces the storage overhead borne by cloud providers when storing the tags of different tenants deduplicating the same content. We show that SPORT resists against malicious tenants/cloud providers (and against collusion among a subset of the tenants and the cloud). Finally, we implement a prototype based on SPORT, and evaluate its performance in a realistic cloud setting. Our evaluation results show that our proposal incurs tolerable computational overhead on the tenants and the cloud provider.
Frederik Armknecht, Jens-Matthias Bohli, David Froelicher, Ghassan Karame
AsiaCCS1
2017 Privacy Implications of Room Climate Data
Philipp Morgner, Christian Müller 0015, Matthias Ring, Björn M. Eskofier, Christian Riess, Frederik Armknecht, Zinaida Benenson
ESORICS (2)6
2017 Short Paper: Industrial Feasibility of Private Information Retrieval
abstract
A popular security problem in database management is how to guarantee to a querying party that the database owner will not learn anything about the data that is retrieved -a problem known as Private Information Retrieval (PIR).While a variety of PIR schemes are known, they are rarely considered for practical use cases yet.We investigate the feasibility of PIR in the telecommunications world to open up data of carriers to external parties.To this end, we first provide a comparative survey of the current PIR state of the art (including ORAM schemes as a generalized concept) as well as implementation and analysis of two PIR schemes for the considered use case.While an overall conclusion is that PIR techniques are not too far away from practical use in specific cases, we see ORAM as a more suitable candidate for further R&D investment.
Angela Jäschke, Björn Grohmann, Frederik Armknecht, Andreas Schaad
SECRYPT3
2017 Insecure to the touch: attacking ZigBee 3.0 via touchlink commissioning
abstract
Hundred millions of Internet of Things devices implement ZigBee, a low-power mesh network standard, and the number is expected to be growing. To facilitate an easy integration of new devices into a ZigBee network, touchlink commissioning was developed. It was adopted in the latest specifications, ZigBee 3.0, which were released to the public in December 2016, as one of two commissioning options for ZigBee devices. ZigBee 3.0 products can be used in various applications, also including security-critical products such as door locks and intruder alarm systems. The aim of this work is to warn about a further adoption of this commissioning mode. We analyze the security of touchlink commissioning procedure and present novel attacks that make direct use of standard's features, showing that this commissioning procedure is insecure by design. We release an open-source penetration testing framework to evaluate the practical implications of these vulnerabilities. Evaluating our tools on popular ZigBee-certified products, we demonstrate that a passive eavesdropper can extract key material from a distance of 130 meters. Furthermore, an active attacker is able to take-over devices from distances of 190 meters. Our analysis concludes that even a single touchlink-enabled device is sufficient to compromise the security of a ZigBee 3.0 network, and therefore, touchlink commissioning should not be supported in any future ZigBee products.
Philipp Morgner, Stephan Mattejat, Zinaida Benenson, Christian Müller 0015, Frederik Armknecht
WISEC5
2016 Accelerating Homomorphic Computations on Rational Numbers
Angela Jäschke, Frederik Armknecht
ACNS2
2016 Towards a Unified Security Model for Physically Unclonable Functions
Frederik Armknecht, Daisuke Moriyama, Ahmad-Reza Sadeghi, Moti Yung
CT-RSA1
2016 Mirror: Enabling Proofs of Data Replication and Retrievability in the Cloud
Frederik Armknecht, Ludovic Barman, Jens-Matthias Bohli, Ghassan Karame
USENIX Security Symposium1
2015 Transparent Data Deduplication in the Cloud
abstract
Cloud storage providers such as Dropbox and Google drive heavily rely on data deduplication to save storage costs by only storing one copy of each uploaded file. Although recent studies report that whole file deduplication can achieve up to 50% storage reduction, users do not directly benefit from these savings-as there is no transparent relation between effective storage costs and the prices offered to the users. In this paper, we propose a novel storage solution, ClearBox, which allows a storage service provider to transparently attest to its customers the deduplication patterns of the (encrypted) data that it is storing. By doing so, ClearBox enables cloud users to verify the effective storage space that their data is occupying in the cloud, and consequently to check whether they qualify for benefits such as price reductions, etc. ClearBox is secure against malicious users and a rational storage provider, and ensures that files can only be accessed by their legitimate owners. We evaluate a prototype implementation of ClearBox using both Amazon S3 and Dropbox as back-end cloud storage. Our findings show that our solution works with the APIs provided by existing service providers without any modifications and achieves comparable performance to existing solutions.
Frederik Armknecht, Jens-Matthias Bohli, Ghassan Karame, Franck Youssef
CCS1
2015 On Lightweight Stream Ciphers with Shorter Internal States
Frederik Armknecht, Vasily Mikhalev
FSE1
2014 Outsourced Proofs of Retrievability
abstract
Proofs of Retrievability (POR) are cryptographic proofs that enable a cloud provider to prove that a user can retrieve his file in its entirety. POR need to be frequently executed by the user to ensure that their files stored on the cloud can be fully retrieved at any point in time. To conduct and verify POR, users need to be equipped with devices that have network access, and that can tolerate the (non-negligible) computational overhead incurred by the verification process. This clearly hinders the large-scale adoption of POR by cloud users, since many users increasingly rely on portable devices that have limited computational capacity, or might not always have network access.
Frederik Armknecht, Jens-Matthias Bohli, Ghassan Karame, Zongren Liu, Christian A. Gorke
CCS1
2014 Fourth International Workshop on Trustworthy Embedded Devices (TrustED 2014)
abstract
The Internet of Things (IoTS) is expected to seamlessly connect everything and everyone and bring about the promise of smart environments, industry 4.0, intelligent infrastructure management, environmental monitoring and disaster recover, etc. In fact, ABI Research [MI-ABI2013] and Gartner [MI-Gartner2013] estimate that there will be between 20 and 30 billion devices on the IoTS by 2020. The explosion in the number of interconnected devices makes it a challenge to guarantee their security, the security of their networks and the privacy of the data collected by them. The Workshop on Trustworthy Embedded Devices (TrustED) focuses on all aspects of security and privacy related to embedded systems and the IoTS. TrustED 2014 continues a successful series of workshops, which were held in conjunction with ESORICS 2011, IEEE Security & Privacy 2012, and ACM CCS 2013 (see http://www.trusted-workshop.de for details). The goal of this workshop is to bring together experts from academia and research institutes, industry, and government in the field of security and privacy in cyber physical systems.
Frederik Armknecht, Jorge Guajardo
CCS1
2014 On Increasing the Throughput of Stream Ciphers
Frederik Armknecht, Vasily Mikhalev
CT-RSA1
2014 An additional protection layer for confidential OSNs posts
abstract
The design of secure and usable access schemes to personal data represent a major challenge of online social networks (OSNs). State of the art requires prior interaction to grant access. Sharing with users who are not subscribed or previously have not been accepted as contacts in any case is only possible via public posts, which can easily be abused by automatic harvesting for user profiling, targeted spear-phishing, or spamming. Moreover, users are restricted to the access rules defined by the provider, which may be overly restrictive, cumbersome to define, or insufficiently fine-grained. We suggest a complementary approach that can be easily deployed in addition to existing access control schemes, does not require any interaction, and includes even public, unsubscribed users. It exploits the fact that different social circles of a user share different experiences and hence encrypts arbitrary posts. Assembling only well-established cryptographic primitives, we prove that the security of our scheme is determined by the entropy of the required knowledge. We consequently analyze the efficiency of an informed dictionary attack and assess the entropy to be on par with common passwords. A fully functional implementation is used for performance evaluations, and available for download on the Web.
Frederik Armknecht, Manuel Hauptmann, Stefanie Roos, Thorsten Strufe
ICC1
2014 Revisiting a Recent Resource-efficient Technique for Increasing the Throughput of Stream Ciphers
abstract
At CT-RSA 2014, Armknecht and Mikhalev presented a new technique for increasing the throughput of stream ciphers that are based on Feedback Shift Registers (FSRs) which requires practically no additional memory. The authors provided concise sufficient conditions for the applicability of this technique and demonstrated its usefulness on the stream cipher Grain-128. However, as these conditions are quite involved, the authors raised as an open question if and to what extent this technique can be applied to other ciphers as well. In this work, we revisit this technique and examine its applicability to other stream ciphers. On the one hand we show on the example of Grain-128a that the technique can be successfully applied to other ciphers as well. On the other hand we list several stream ciphers where the technique is not applicable for different structural reasons.
Frederik Armknecht, Vasily Mikhalev
SECRYPT1
2013 Third international workshop on trustworthy embedded devices (TrustED 2013)
abstract
Cyber physical systems (CPS) feature a tight combination of and coordination between the system's computational and physical elements. A current NIST report estimates that "by the end of the decade, embedded networking and computing components are projected to account for more than half of the value share in diverse sectors, including automotive, consumer electronics, avionics and aerospace, manufacturing, telecommunications, intelligent buildings, and health and medical equipment" and further conjectures that "future applications of CPS are more transformative than the IT revolution of the past three decades". While the increasing proliferation of embedded systems in general and CPS in particular provide a variety of new possibilities, new risks and challenges emerge. Due to the strong interdisciplinary character, advancement in CPS requires a new systems science that encompasses both physical and computational aspects.
Frederik Armknecht, Jean-Pierre Seifert
CCS1
2013 A security framework for the analysis and design of software attestation
abstract
Software attestation has become a popular and challenging research topic at many established security conferences with an expected strong impact in practice. It aims at verifying the software integrity of (typically) resource-constrained embedded devices. However, for practical reasons, software attestation cannot rely on stored cryptographic secrets or dedicated trusted hardware. Instead, it exploits side-channel information, such as the time that the underlying device needs for a specific computation. As traditional cryptographic solutions and arguments are not applicable, novel approaches for the design and analysis are necessary. This is certainly one of the main reasons why the security goals, properties and underlying assumptions of existing software attestation schemes have been only vaguely discussed so far, limiting the confidence in their security claims. Thus, putting software attestation on a solid ground and having a founded approach for designing secure software attestation schemes is still an important open problem.
Frederik Armknecht, Ahmad-Reza Sadeghi, Steffen Schulz 0001, Christian Wachsmann
CCS1
2013 Group homomorphic encryption: characterizations, impossibility results, and applications
Frederik Armknecht, Stefan Katzenbeisser 0001, Andreas Peter 0001
Des. Codes Cryptogr.1
2011 The Preimage Security of Double-Block-Length Compression Functions
Frederik Armknecht, Ewan Fleischmann, Matthias Krause 0001, Jooyoung Lee 0001, Martijn Stam, John P. Steinberger
ASIACRYPT1
2011 On Constructing Homomorphic Encryption Schemes from Coding Theory
Frederik Armknecht, Daniel Augot, Ludovic Perret, Ahmad-Reza Sadeghi
IMACC1
2011 A Formalization of the Security Features of Physical Functions
abstract
Physical attacks against cryptographic devices typically take advantage of information leakage (e.g., side-channels attacks) or erroneous computations (e.g., fault injection attacks). Preventing or detecting these attacks has become a challenging task in modern cryptographic research. In this context intrinsic physical properties of integrated circuits, such as Physical(ly) Unclonable Functions (PUFs), can be used to complement classical cryptographic constructions, and to enhance the security of cryptographic devices. PUFs have recently been proposed for various applications, including anti-counterfeiting schemes, key generation algorithms, and in the design of block ciphers. However, currently only rudimentary security models for PUFs exist, limiting the confidence in the security claims of PUF-based security primitives. A useful model should at the same time (i) define the security properties of PUFs abstractly and naturally, allowing to design and formally analyze P UF-based security solutions, and (ii) provide practical quantification tools allowing engineers to evaluate PUF instantiations. In this paper, we present a formal foundation for security primitives based on PUFs. Our approach requires as little as possible from the physics and focuses more on the main properties at the heart of most published works on PUFs: robustness (generation of stable answers), unclonability (not provided by algorithmic solutions), and unpredictability. We first formally define these properties and then show that they can be achieved by previously introduced PUF instantiations. We stress that such a consolidating work allows for a meaningful security analysis of security primitives taking advantage of physical properties, becoming increasingly important in the development of the next generation secure information systems.
Frederik Armknecht, Roel Maes, Ahmad-Reza Sadeghi, François-Xavier Standaert, Christian Wachsmann
IEEE Symposium on Security and Privacy1
2010 On RFID Privacy with Mutual Authentication and Tag Corruption
Frederik Armknecht, Ahmad-Reza Sadeghi, Ivan Visconti, Christian Wachsmann
ACNS1
2009 Memory Leakage-Resilient Encryption Based on Physically Unclonable Functions
Frederik Armknecht, Roel Maes, Ahmad-Reza Sadeghi, Berk Sunar, Pim Tuyls
ASIACRYPT1
2009 Hide and Seek in Time - Robust Covert Timing Channels
Dipak Ghosal, Frederik Armknecht, Ahmad-Reza Sadeghi, Steffen Schulz 0001, Stefan Katzenbeisser 0001
ESORICS3
2009 Using Merkle's Puzzle for key agreement with low-end devices
abstract
Due to severe resource restrictions, many established cryptographic schemes are not executable in sensor and actuator networks. Especially for key exchange algorithms (KE), the foundation of many cryptographic protocols, the situation is extremely challenging as most KE rely on elaborate computations and/or huge data. Hence, there is a continuous search for KE with reduced complexity. Observe that most KE burden the same workload on both communication partners. In this paper, we follow a different approach that respects the usually asymmetric capabilities of network nodes and users. We describe a key agreement protocol that allows for pushing the workload almost completely to the stronger device, e.g., the user. This allows to get any desired security level, independent of the capabilities of the weak device.
Frederik Armknecht, Dirk Westhoff
LCN1
2008 Secure Multi-Coupons for Federated Environments: Privacy-Preserving and Customer-Friendly
Frederik Armknecht, Alberto N. Escalante, Hans Löhr, Mark Manulis, Ahmad-Reza Sadeghi
ISPEC1
2008 A lifetime-optimized end-to-end encryption scheme for sensor networks allowing in-network processing
Frederik Armknecht, Dirk Westhoff, Joao Girão, Alban Hessler
Comput. Commun.1
2007 Who Said That? Privacy at Link Layer
abstract
Wireless LAN and other radio broadcast technologies are now in full swing. However, the widespread usage of these technologies comes at the price of location privacy, be it by observing the communication patterns or the interface identifiers. Although a number of network level solutions have been proposed , this paper describes a novel approach to location privacy at the link layer level. We present a generic mechanism and then map it to a real protocol, IEEE 802.11. The work also provides an analysis of the protocol in terms of privacy and performance considerations.
Frederik Armknecht, Joao Girão, Alfredo Matos, Rui L. Aguiar
INFOCOM1
2006 Efficient Computation of Algebraic Immunity for Algebraic and Fast Algebraic Attacks
Frederik Armknecht, Claude Carlet, Philippe Gaborit, Simon Fischer 0002, Willi Meier, Olivier Ruatta
EUROCRYPT1
2006 Constructing Single- and Multi-output Boolean Functions with Maximal Algebraic Immunity
Frederik Armknecht, Matthias Krause 0001
ICALP (2)1
2004 Improving Fast Algebraic Attacks
Frederik Armknecht
FSE1
2003 Algebraic Attacks on Combiners with Memory
Frederik Armknecht, Matthias Krause 0001
CRYPTO1