Axel Sikora

dblp:67/6275 · DBLP profile ↗
← Back
37ranked-venue papers
2as first author
27since 2021 · last 2026
0000-0003-0878-2919ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 21 · 2 first-author · 17 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 5 since 2021Artificial intelligence and machine learning · 5 · 4 since 2021Computer networks · 4 · 3 since 2021Security and privacy · 2 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Provably Relevant HAL Interface Requirements for Embedded Systems
Manuel Bentele, Andreas Podelski, Axel Sikora, Bernd Westphal
REFSQ3
2025 A Novel PUF Key Generation Method via Variable-Length Subkeys: An Application with Inertial MEMS Sensors
abstract
In this work, a novel PUF key generation algorithm is introduced that leverages the inherent variability in sensor properties to produce highly entropic keys for security applications. The approach uses variable-length subkeys, which are encoded into a fixed-length final key. The encoding is specifically designed to preserve the subkey length information during key generation. Real-world measurements from high-fidelity inertial MEMS sensors (gyroscopes and accelerometers) were used to verify the proposed technology. Our experimental evaluation demonstrates strong uniqueness and reliability with stable performance under controlled conditions.
Wacime Hadrich, Lukas Zimmermann, Patrick Tritschler, Axel Sikora
CASES4
2025 Automated Security Configuration Verification for OT Networks: An Architecture and AutomationML Approach
abstract
Security configurations in operational technology (OT) networks are increasingly critical yet complex and error-prone when managed manually, often due to intricate certificate management and protocol-specific processes.This paper proposes a novel approach to automate the verification of OT security configurations, minimizing misconfigurations and enhancing the correct application of protection mechanisms. We introduce an AutomationML-based architecture to model OT environments as a digital twin, a data model capturing security configuration parameters exemplified with PROFINET including a proposed configuration for the unspecified entities, and a formal language extending predicate logic for protocol-independent rule verification. Using a Python-Prolog implementation, our automated verification tool processes an AutomationML InstanceHierarchy to detect incomplete and inconsistent configurations that preclude the establishment of secure communications. Applied to PROFINET, our prototype successfully identifies issues like unsupported algorithms or missing certificates, demonstrating applicability while remaining extensible to other protocols.
Julian Göppert, Axel Sikora
ETFA2
2025 A Combination of Bluetooth Physical Layer Key Generation and Physically Unclonable Functions for Lightweight Security in IoT Edge Nodes
abstract
The proliferation of Internet of Things (IoT) and embedded systems across various domains has heightened the need for secure, lightweight cryptographic mechanisms tailored to resource-constrained devices. Traditional encryption protocols are often too computationally intensive for these applications, prompting exploration into alternative security methods. This study presents a novel lightweight cryptographic Physical Layer Key Generation (PLKG) approach that leverages Bluetooth Low Energy (BLE) channel entropy to generate secure session keys. To enhance system security further, Physically Unclonable Functions (PUFs) are integrated, providing device-specific authentication and protection against cloning attacks. To our knowledge, this is the first system that combines wireless channel randomness and PUFs as hybrid entropy sources. Experimental results demonstrate that this BLE-based key derivation method, combined with PUF technology, yields a unique, lightweight security solution suitable for automotive and IoT applications. The proposed BLE-based key generation method successfully passes the National Institute of Standards and Technology (NIST) Statistical Test Suite.
Wacime Hadrich, Axel Sikora
ETFA2
2025 DRIP: DRop unImportant data Points - Enhancing Machine Learning Efficiency with Grad-CAM-Based Streaming Data Prioritization for On-Device Training
abstract
Selecting data points for model training is critical in machine learning. Effective selection methods can reduce the labeling effort, optimize on-device training for embedded systems with limited data storage, and enhance the model performance. This paper introduces a novel algorithm that uses Grad-CAM to make online decisions about retaining or discarding data points. Optimized for embedded devices, the algorithm computes a unique DRIP Score to quantify the importance of each data point. This enables dynamic decision-making on whether a data point should be stored for potential retraining or discarded without compromising model performance. Experimental evaluations on four benchmark datasets demonstrate that our approach can match or even surpass the accuracy of models trained on the entire dataset, while achieving storage savings of up to 39%. To our knowledge, this is the first algorithm to make online decisions about data point retention without requiring access to the entire dataset.
Marcus Rüb, Daniel Konegen, Axel Sikora, Daniel Mueller-Gritschneder
IJCNN3
2025 Monitoring and Management of Heterogeneous TSN Networks for Industry 4.0: A Survey
abstract
The growing complexity of industrial communication networks, driven by Industry 4.0, necessitates the integration of Time-Sensitive Networking (TSN) into heterogeneous networks to ensure deterministic, low-latency, and high-reliability communication. This survey provides a comprehensive review of existing research on TSN in heterogeneous networks, focusing on monitoring and network management. We analyze key TSN management frameworks, control mechanisms, and monitoring strategies while identifying challenges in interoperability, synchronization, scalability, and real-time control. By highlighting existing research gaps, this work proposes potential directions for future research to advance TSN deployment in heterogeneous industrial environments.
Seyedali Hadian, Manuel Schappacher, Dominik Welte, Axel Sikora
INDIN4
2025 A Wireless TSN Scheduling Algorithm Based on Strict Priority with Dynamic Queues
abstract
Time-Sensitive Networking (TSN) is an IEEE 802.1 standard set to provide deterministic data transmission over Ethernet-based networks. In TSN, Strict Priority (SP) scheduling is a fundamental technique ensuring high-priority traffic to be transmitted before low-priority traffic. This prioritization strives for low-latency communication for critical applications, such as industrial automation and automotive systems. This scheduling algorithm operates by assigning each frame a priority level of eight priorities and processing frames in descending order of priority, effectively creating a hierarchical transmission model with a constant queue number (8 queues). This paper investigates the performance of standard SP. In addition, it proposes a novel Synchronized Strict Priority with Dynamic Queues (S-SPDQ) scheduling for optimizing the processing delay as a part of the overall system latency, which is especially relevant for Wireless TSN (WTSN). The proposed algorithm was implemented as a bare-metal program on ESP32S2 which is a 32-bit Xtensa LX7 microcontroller. The SS-PDQ scheduling improves the SP model by introducing queue dynamicity to minimize overall latency and implementing time-based synchronization to ensure precise transmission delay estimation, paving the way for future enhancements in time-aware algorithms. Compared with the standard SP, the S-SPDQ introduced an average reduction in memory consumption by 50%, in the dequeuing process time by 49%, and the transmission delay by 12%. For the end-to-end latencies in selected use cases, the average reduction is 17% for 1 -queue, $\mathbf{1 5 \%}$ for $\mathbf{4}$-queues and $\mathbf{1 2 \%}$ for $\mathbf{7}$-queues.
Mohammed Wahhab Abdulrazzaq, Axel Sikora, Abdulkareem A. Kadhim
WFCS2
2025 A YANG Model-Based Approach for Configuration and Management of 5G-TSN Bridges
abstract
Time-Sensitive Networking (TSN) and especially its integration into private 5 G networks is becoming increasingly important for industrial applications. By introducing 5G-TSN bridges, the combination of the strengths from both technologies would allow high-performance, reliable deterministic wireless networks, which are flexible in the sense of the network topology and its dynamic behavior. In addition, converged networks become real, avoiding the need of separation between Operation Technology and Information Technology. The basic mechanisms of TSN, such as time synchronization or scheduling inside a private 5 G network and through a 5 G TSN bridge, have already been specified, investigated and proven in different research and prototype works. However, to make use of these features in a fully operational environment, such a bridge must be properly configured. Starting from declaring, enabling and configuring available ports, other processes, such as port and device discovery, need to be covered to allow a seamless integration of a 5G-TSN bridge into the overall network. At least from the design and implementation side, the internal configuration of such a 5 G -TSN bridge is not yet fully available. This work proposes a novel standard-compatible YANG (Yet Another Modeling Language) model-based approach and architecture to model and access the configuration and maintenance of a 5G-TSN bridge within a TSN network. We break down the single processes and structures at the involved entities and present a reference design for the practical implementation of such a configuration and management interface, while corresponding to the YANG model-based configuration methods from TSN networks.
Manuel Schappacher, Dominik Welte, Axel Sikora, Christopher Lehmann
WFCS3
2025 Hybrid Consensus Mechanisms in Blockchain: A Comprehensive Review
abstract
Blockchain technology, renowned for its foundational attributes of decentralization, security, and immutability, offers substantial potential for diverse applications. At the heart of blockchain functionality are consensus mechanisms, crucial for preserving the decentralized integrity of the network. However, traditional consensus algorithms like Proof of Work (PoW), Proof of Stake (PoS), and Byzantine Fault Tolerance (BFT) typically require significant computational and communication resources, which may not be feasible for resource‐limited environments. The purpose of this paper is to explore hybrid consensus algorithms that integrate conventional consensus mechanisms with advanced nonlinear data structures. We comprehensively analyze a wide range of hybrid consensus mechanisms, emphasizing their architectural design, operational efficiencies, and ability to address both consensus‐specific vulnerabilities and network‐level threats, such as Sybil attacks, double‐spending, and partitioning attacks. To achieve this, we employ a set of comprehensive evaluation criteria for blockchain technologies, namely, validation, IoT, real‐time processing, application suitability, security, and implementation. These criteria help assess the adaptability and efficacy of each mechanism in diverse operational contexts. Through this examination, the paper seeks to illuminate the significant contributions and implications of hybrid consensus mechanisms, guiding stakeholders, researchers, and developers toward making informed decisions about optimizing blockchain technology for their specific needs and inspiring the development of innovative solutions.
Ali Ahmed Al-awamy, Nagi Al-shaibany, Axel Sikora, Dominik Welte
Int. J. Intell. Syst.3
2024 Monitoring Time Synchronization Precision: Implementation, Validation, and Low Cost PPS Measurement Mechanism for gPTP Monitoring
abstract
Time-Sensitive Networking (TSN) promises deterministic, seamless and vendor independent communication in modern networked systems, utilizing the generalized Precision Time Protocol (gPTP) as governed by IEEE 802.1AS for precise time synchronization. As network complexity increases, effective monitoring of synchronization accuracy, incorporating both advanced and traditional methods, becomes crucial. This paper examines the implementation and performance of time synchronization monitoring methods for gPTP, including Monitoring Type Length Value (TLV) for Ingress & Egress messages, Reverse Sync, and Pulse per Second (PPS) techniques across varied hardware environments and operational conditions. We detail the integration process, discuss the adaptability of these methods under stress tests, and evaluate their effectiveness through rigorous assessments. The findings contribute to refining monitoring deployment strategies by identifying the most effective combinations of monitoring techniques to enhance synchronization accuracy and network reliability.
Kedar Naik, Manuel Schappacher, Dominik Welte, Axel Sikora
ETFA4
2024 Advancing On-Device Neural Network Training with TinyPropv2: Dynamic, Sparse, and Efficient Backpropagation
abstract
This study introduces EmbeddedTrain, an innovative algorithm optimized for on-device learning in deep neural networks, specifically designed for low-power microcontroller units. EmbeddedTrain refines sparse backpropagation by dynamically adjusting the level of sparity, including the ability to selectively skip training steps. This feature significantly lowers computational effort without substantially compromising accuracy. Our comprehensive evaluation across diverse datasets—CIFAR 10, CIFAR100, Flower, Food, Speech Command, MNIST, HAR, and DCASE2020—reveals that EmbeddedTrain achieves near-parity with full training methods, with an average accuracy drop of only around 1% in most cases. For instance, against full training, EmbeddedTrain’s accuracy drop is minimal, for example, only 0.82% on CIFAR 10 and 1.07% on CIFAR100. In terms of computational effort, EmbeddedTrain shows a marked reduction, requiring as little as 10% of the computational effort needed for full training in some scenarios, and consistently outperforms other sparse training methodologies. These findings underscore EmbeddedTrain’s capacity to efficiently manage computational resources while maintaining high accuracy, positioning it as an advantageous solution for advanced embedded device applications in the IoT ecosystem.
Marcus Rüb, Axel Sikora, Daniel Mueller-Gritschneder
IJCNN2
2024 Evaluation of the Secure PROFINET Application Relation Establishment Performance
abstract
With the advent of the cryptographic security ex-tensions for PROFINET Security Class 2/3, as specified by PROFIBUS & PROFINET International, there arises a signif-icant difference between the establishment of a conventional (insecure) and a secure application relation (AR). However, to the best of our knowledge, there is no study yet that numeralizes how much delay is induced by the computational and communication overhead of the secure AR establishment. Therefore, we study its performance by runtime measurements using an experimental hardware setup. We answer two research questions: (1) how much additional runtime delay is induced by the currently specified security extensions when performing a secure AR establishment, and (2) what is the impact of currently unspecified options to reduce this delay? In particular, we study the options to use the Extensible Authentication Protocol (EAP) with Transport Layer Security (TLS) for full handshakes and session resumption, version 1.2 and 1.3, certificate-based and pre-shared-key-based (PSK) ciphersuites, as well as EAP-PSK. We gain the insight that the currently specified extensions lead to a best case delay of 17.5 ms and a worst case delay of 288.6 ms for full handshakes and to 7.3 and 9.8 ms for resumed sessions. With the currently unspecified option to use pre-shared-key-based ciphersuites, yet providing perfect forward security, the best case delay for full handshakes is reduced by 25.7 % and the worst case delay by 91.1 %. With the currently unspecified EAP-PSK option, which does not provide PFS, the largest reduction is achieved by 78.4 and 98.7 % related to best and worst case full handshakes. The authors are members of the PROFINET Working Group CBIPG 10 Security.
Julian Göppert, Axel Sikora
INDIN2
2024 TSN over 5G: Overcoming Challenges and Realizing Integration
abstract
Time-Sensitive Networking (TSN) is becoming increasingly important. Especially in the field of industrial applications, the demand for uniform, converged real-time networks is continuously increasing. Furthermore, the request to integrate wireless, mobile, and real-time capable network elements is getting more and more relevant to industrial automation use cases. To address these requests, the 3rd Generation Partnership Project (3GPP) has extended their specifications for mobile telecommunication protocols by descriptions to integrate 5G mobile networks into TSN starting from Release 16 onwards. While the specifications provide a good theoretical overview, there is still a lack of real implementations or even proof of concepts. Therefore, we started an implementation of a 5G network that is ready to be integrated into existing TSN. This work gives an overview of the current work in progress, mainly focusing on the implementation of the TSN Application Function (TSN AF) and the time synchronization features within the TSN Translators (DS-TT and NW-TT). It also shows current limitations and difficulties and how we have overcome them with our setup.
Dominik Welte, Christopher Lehmann, Manuel Schappacher, Thomas Höschele, Axel Sikora, Frank H. P. Fitzek
WFCS5
2024 Output Positioning to Derive Maximum Entropy From Physical Unclonable Functions
abstract
Physical unclonable functions (PUFs) are increasingly generating attention in the field of hardware-based security for the Internet of Things (IoT). A PUF, as its name implies, is a physical element with a special and unique inherent characteristic and can act as the security anchor for authentication and cryptographic applications. Keeping in mind that the PUF outputs are prone to change in the presence of noise and environmental variations, it is critical to derive reliable keys from the PUF and to use the maximum entropy at the same time. In this work, the PUF output positioning (POP) method is proposed, which is a novel method for grouping the PUF outputs in order to maximize the extracted entropy. To achieve this, an offset data is introduced as helper data, which is used to relax the constraints considered for the grouping of PUF outputs, and deriving more entropy, while reducing the secret key error bits. To implement the method, the key enrollment and key generation algorithms are presented. Based on a theoretical analysis of the achieved entropy, it is proven that POP can maximize the achieved entropy, while respecting the constraints induced to guarantee the reliability of the secret key. Moreover, a detailed security analysis is presented, which shows the resilience of the method against cyber-security attacks. The findings of this work are evaluated by applying the method on a hybrid printed PUF, where it can be practically shown that the proposed method outperforms other existing group-based PUF key generation methods.
Saeed Abdolinezhad, Lukas Zimmermann, Axel Sikora
IEEE Trans. Inf. Forensics Secur.3
2023 Detailed Study of Different Degradation Stages of Bearings in a Practical Reference Dataset
abstract
The often-occurring short-term orders of manufactured products require a high machine availability. This requirement increases the importance of predictive maintenance solutions for bearings used in machines. There are, among others, hybrid solutions that rely on a physical model. For their usage, knowing the different degradation stages of bearings is essential. This research analyzes the underlying failure mechanisms of these stages theoretically and in a practical example of the well-known FEMTO dataset used for the IEEE PHM 2012 Data Challenge to provide this knowledge. In addition, it shows for which use cases the usage of low-frequency accelerometers is sufficient. The analysis provides that the degradation stages toward the end of the bearing life can also be detected with low-frequency accelerometers. Further, the importance of high-frequency accelerometers to detect bearing faults in early degradation stages is pointed out. These aspects have not been paid attention to by industry and research until now, despite providing a considerable cost-saving potential.
Sebastian Schwendemann, Andreas Rausch 0001, Axel Sikora
ETFA3
2023 A NETCONF-Based Solution for Credential Management in Time-Sensitive Networks
abstract
As cyber-attacks and functional safety requirements increase in Operational Technology (OT), implementing security measures becomes crucial. The IEC/IEEE 60802 draft standard addresses the security convergence in Time-Sensitive Networks (TSN) for industrial automation.We present the standard’s security architecture and its goals to establish end-to-end security with resource access authorization in OT systems. We compare the standard to our abstract technology-independent model for the management of cryptographic credentials during the lifecycles of OT systems. Additionally, we implemented the processes, mechanisms, and protocols needed for IEC/IEEE 60802 and extended the architecture with public key infrastructure (PKI) functionalities to support complete security management processes.
Adian Shubbar, Andreas Walz, Julian Göppert, Axel Sikora
ETFA4
2023 Methodology and Implementation for Monitoring Precise Time Synchronisation in TSN
abstract
TSN, or Time Sensitive Networking, is becoming an essential technology for integrated networks, enabling deterministic and best effort traffic to coexist on the same infrastructure. In order to properly configure, run and secure such TSN, monitoring functionality is a must. The TSN standard already has some preparations to provide such functionality and there are different methods to choose from. We implemented different methods to measure the time synchronisation accuracy between devices as a C library and compared the measurement results. Furthermore, the library has been integrated into the ControlTSN engineering framework.
Kedar Naik, Dominik Welte, Stefan Oechsle, Florian Frick, Armin Lechler, Manuel Schappacher, Axel Sikora
INDIN7
2023 Automated Physical TestBeds (APTB 2.0): Enabling Reliable and Efficient Testing of Wireless Communication Networks for IoT and Industry 4.0
abstract
Wireless communication networks are crucial for enabling megatrends like the Internet of Things (IoT) and Industry 4.0. However, testing these networks can be challenging due to the complex network topology and RF characteristics, requiring a multitude of scenarios to be tested. To address this challenge, the authors developed and extended an automated testbed called Automated Physical TestBed (APTB). This testbed provides the means to conduct controlled tests, analyze coexistence, emulate multiple propagation paths, and model dependable channel conditions. Additionally, the platform supports test automation to facilitate efficient and systematic experimentation. This paper describes the extended architecture, implementation, and performance evaluation of the APTB testbed. The APTB testbed provides a reliable and efficient solution for testing wireless communication networks under various scenarios. The implementation and performance verification of the testbed demonstrate its effectiveness and usefulness for researchers and industry practitioners.
Axel Sikora, Fabian Sowieja, E. Jubin Sebastian, Manuel Schappacher, Wacime Hadrich
INDIN1
2023 Trust Management System for Hybrid Industrial Blockchains
abstract
As industrial networks continue to expand and connect more devices and users, they face growing security challenges such as unauthorized access and data breaches. This paper delves into the crucial role of security and trust in industrial networks and how trust management systems (TMS) can mitigate malicious access to these networks.The TMS presented in this paper leverages distributed ledger technology (blockchain) to evaluate the trustworthiness of blockchain nodes, including devices and users, and make access decisions accordingly. While this approach is applicable to blockchain, it can also be extended to other areas. This approach can help prevent malicious actors from penetrating industrial networks and causing harm. The paper also presents the results of a simulation to demonstrate the behavior of the TMS and provide insights into its effectiveness.
Christina Stodt, Christoph Reich, Axel Sikora, Dominik Welte
INDIN3
2023 PROFINET Security: A Look on Selected Concepts for Secure Communication in the Automation Domain
abstract
We provide a brief overview of the cryptographic security extensions for PROFINET, as defined and specified by PROFIBUS & PROFINET International (PI). These come in three hierarchically defined Security Classes, called Security Class 1,2 and 3. Security Class 1 provides basic security improvements with moderate implementation impact on PROFINET components. Security Classes 2 and 3, in contrast, introduce an integrated cryptographic protection of PROFINET communication. We first highlight and discuss the security features that the PROFINET specification offers for future PROFINET products. Then, as our main focus, we take a closer look at some of the technical challenges that were faced during the conceptualization and design of Security Class 2 and 3 features. In particular, we elaborate on how secure application relations between PROFINET components are established and how a disruption-free availability of a secure communication channel is guaranteed despite the need to refresh cryptographic keys regularly. The authors are members of the PI Working Group CB/PG10 Security.
Andreas Walz, Karl-Heinz Niemann, Julian Göppert, Kai Fischer, Simon Merklin, Dominik Ziegler 0001, Axel Sikora
INDIN7
2023 Blockchain interoperability: the state of heterogenous blockchain-to-blockchain communication
abstract
Abstract Blockchain technology has been increasingly adopted over the past few years since the introduction of Bitcoin, with several blockchain architectures and solutions being proposed. Most proposed solutions have been developed in isolation, without a standard protocol or cryptographic structure to work with. This has led to the problem of interoperability, where solutions running on different blockchain platforms are unable to communicate, limiting the scope of use. With blockchains being adopted in a variety of fields such as the Internet of Things, it is expected that the problem of interoperability if not addressed quickly, will stifle technology advancement. This paper presents the current state of interoperability solutions proposed for heterogenous blockchain systems. A look is taken at interoperability solutions, not only for cryptocurrencies, but also for general data‐based use cases. Current open issues in heterogenous blockchain interoperability are presented. Additionally, some possible research directions are presented to enhance and to extend the existing blockchain interoperability solutions. It was discovered that though there are a number of proposed solutions in literature, few have seen real‐world implementation. The lack of blockchain‐specific standards has slowed the progress of interoperability. It was also realized that most of the proposed solutions are developed targeting cryptocurrency‐based applications.
Seth Djane Kotey, Eric Tutu Tchao, Abdul-Rahman Ahmed, Andrew Selasi Agbemenu, Henry Nunoo-Mensah, Axel Sikora, Dominik Welte, Eliel Keelson
IET Commun.6
2023 Enabling Time-Synchronized Hybrid Networks With Low-Cost IoT Modules
abstract
Precisely synchronized communication is a major precondition for many industrial applications. At the same time, hardware cost and power consumption need to be kept as low as possible in the Internet of Things (IoT) paradigm. While many wired solutions on the market achieve these requirements, wireless alternatives are an interesting field for research and development. This article presents a novel IEEE802.11n/ac wireless solution, exhibiting several advantages over state-of-the-art competitors. It is based on a market-available wireless System on a Chip with modified low-level communication firmware combined with a low-cost field-programmable gate array. By achieving submicrosecond synchronization accuracy, our solution outperforms the precision of low-cost products by almost four orders of magnitude. Based on inexpensive hardware, the presented wireless module is up to 20 times cheaper than software-defined-radio solutions with comparable timing accuracy. Moreover, it consumes three to five times less power. To back up our claims, we report data that we collected with a high sampling rate (2000 samples per second) during an extended measurement campaign of more than 120 h, which makes our experimental results far more representative than others reported in the literature. Additional support is provided by the size of the testbed we used during the experiments, composed of a hybrid network with nine nodes divided into two independent wireless segments connected by a wired backbone. In conclusion, we believe that our novel Industrial IoT module architecture will have a significant impact on the future technological development of high-precision time-synchronized communication for the cost-sensitive industrial IoT market.
Alexey M. Romanov, Francesco Gringoli, Kamil Alkhouri, Pavel E. Tripolskiy, Axel Sikora
IEEE Internet Things J.5
2021 Cryptographic Protection of Cyclic Real-Time Communication in Ethernet-Based Fieldbuses: How Much Hardware is Required?
abstract
It seems to be a widespread impression that the use of strong cryptography inevitably imposes a prohibitive burden on industrial communication systems, at least inasmuch as real-time requirements in cyclic fieldbus communications are concerned. AES-GCM is a leading cryptographic algorithm for authenticated encryption, which protects data against disclosure and manipulations. We study the use of both hardware and software-based implementations of AES-GCM. By simulations as well as measurements on an FPGA-based prototype setup we gain and substantiate an important insight: for devices with a 100 Mbps full-duplex link, a single low-footprint AES-GCM hardware engine can deterministically cope with the worst-case computational load, i.e., even if the device maintains a maximum number of cyclic communication relations with individual cryptographic keys. Our results show that hardware support for AES-GCM in industrial fieldbus components may actually be very lightweight.
Matthias Skuballa, Andreas Walz, Heiko Bühler, Axel Sikora
ETFA4
2021 A Mechanism for Seamless Cryptographic Rekeying in Real-Time Communication Systems
abstract
Cryptographic protection of messages requires frequent updates of the symmetric cipher key used for encryption and decryption, respectively. Protocols of legacy IT security, like TLS, SSH, or MACsec implement rekeying under the assumption that, first, application data exchange is allowed to stall occasionally and, second, dedicated control messages to orchestrate the process can be exchanged. In real-time automation applications, the first is generally prohibitive, while the second may induce problematic traffic patterns on the network. We present a novel seamless rekeying approach, which can be embedded into cyclic application data exchanges. Although, being agnostic to the underlying real-time communication system, we developed a demonstrator emulating the widespread industrial Ethernet system PROFINET IO and successfully use this rekeying mechanism.
Heiko Bühler, Andreas Walz, Axel Sikora
WFCS3
2021 Bearing fault diagnosis with intermediate domain based Layered Maximum Mean Discrepancy: A new transfer learning approach
Sebastian Schwendemann, Zubair Amjad, Axel Sikora
Eng. Appl. Artif. Intell.3
2021 A Precise Synchronization Method for Future Wireless TSN Networks
abstract
Time-sensitive networking (TSN) is the most promising time-deterministic wired communication approach for industrial applications. To extend TSN to “IEEE 802.11” wireless networks, two challenging problems must be solved: synchronization and scheduling. This article is focused on the first one. Even though a few solutions already meet the required synchronization accuracies, they are built on expensive hardware that is not suited for mass market products. While next Wi-Fi generation might support the required functionalities, this article proposes a novel method that makes high-precision wireless synchronization using commercial low-cost components possible. With the proposed solution, a standard deviation of synchronization error of less than 500 ns can be achieved for many use cases and system loads on both CPU and network. This performance is comparable to modern wired real-time field buses, which makes the developed method a significant contribution for the extension of the TSN protocol to the wireless domain.
Alexey M. Romanov, Francesco Gringoli, Axel Sikora
IEEE Trans. Ind. Informatics3
2021 Latency reduction for narrowband URLLC networks: a performance evaluation
abstract
Abstract Fifth-generation (5G) cellular mobile networks are expected to support mission-critical low latency applications in addition to mobile broadband services, where fourth-generation (4G) cellular networks are unable to support Ultra-Reliable Low Latency Communication (URLLC). However, it might be interesting to understand which latency requirements can be met with both 4G and 5G networks. In this paper, we discuss (1) the components contributing to the latency of cellular networks and (2) evaluate control-plane and user-plane latencies for current-generation narrowband cellular networks and point out the potential improvements to reduce the latency of these networks, (3) present, implement and evaluate latency reduction techniques for latency-critical applications. The two elements we detected, namely the short transmission time interval and the semi-persistent scheduling are very promising as they allow to shorten the delay to processing received information both into the control and data planes. We then analyze the potential of latency reduction techniques for URLLC applications. To this end, we develop these techniques into the long term evolution (LTE) module of ns-3 simulator and then evaluate the performance of the proposed techniques into two different application fields: industrial automation and intelligent transportation systems. Our detailed evaluation results from simulations indicate that LTE can satisfy the low-latency requirements for a large choice of use cases in each field.
Zubair Amjad, Kofi Atta Nsiah, Benoît Hilt, Jean-Philippe Lauffenburger, Axel Sikora
Wirel. Networks5
2020 Exploiting Dissent: Towards Fuzzing-Based Differential Black-Box Testing of TLS Implementations
abstract
The Transport Layer Security (TLS) protocol is one of the most widely used security protocols on the internet. Yet do implementations of TLS keep on suffering from bugs and security vulnerabilities. In large part is this due to the protocol's complexity which makes implementing and testing TLS notoriously difficult. In this paper, we present our work on using differential testing as effective means to detect issues in black-box implementations of the TLS handshake protocol. We introduce a novel fuzzing algorithm for generating large and diverse corpuses of mostly-valid TLS handshake messages. Stimulating TLS servers when expecting a ClientHello message, we find messages generated with our algorithm to induce more response discrepancies and to achieve a higher code coverage than those generated with American Fuzzy Lop, TLS-Attacker, or NEZHA. In particular, we apply our approach to OpenSSL, BoringSSL, WolfSSL, mbedTLS, and MatrixSSL, and find several real implementation bugs; among them a serious vulnerability in MatrixSSL 3.8.4. Besides do our findings point to imprecision in the TLS specification. We see our approach as presented in this paper as the first step towards fully interactive differential testing of black-box TLS protocol implementations. Our software tools are publicly available as open source projects.
Andreas Walz, Axel Sikora
IEEE Trans. Dependable Secur. Comput.2
2019 Test and Measurement of LPWAN and Cellular IoT Networks in a Unified Testbed
abstract
One of the main requirements of spatially distributed Internet of Things (IoT) solutions is to have networks with wider coverage to connect many low-power devices. Low-Power Wide-Area Networks (LPWAN) and Cellular IoT(cIOT) networks are promising candidates in this space. LPWAN approaches are based on enhanced physical layer (PHY) implementations to achieve long range such as LoRaWAN, SigFox, MIOTY. Narrowband versions of cellular network offer reduced bandwidth and, simplified node and network management mechanisms, such as Narrow Band IoT (NB-IoT) and Long-Term Evolution for Machines (LTE-M). Since the underlying use cases come with various requirements it is essential to perform a comparative analysis of competing technologies. This article provides systematic performance measurement and comparison of LPWAN and NB-IoT technologies in a unified testbed, also discusses the necessity of future fifth generation (5G) LPWAN solutions.
E. Jubin Sebastian, Axel Sikora, Manuel Schappacher, Zubair Amjad
INDIN2
2019 Performance Evaluation of Latency for NB-LTE Networks in Industrial Automation
abstract
Low latency communication is essential to enable mission-critical machine-type communication (mMTC) use cases in cellular networks. Factory and process automation are major areas that require such low latency communication. In this paper, we investigate the potential of adopting the semi-persistent scheduling (SPS) latency reduction technique in narrowband LTE (NB-LTE) networks and provide a comprehensive performance evaluation. First, we investigate and implement SPS in an open-source network simulator (NS3). We perform simulations with a focus on LTE-M and Narrowband IoT (NB-IoT) systems and evaluate the impact of the SPS technique on the uplink latency of these narrowband systems in real industrial automation scenarios. The performance gain of adopting SPS is analyzed and the results is compared with the legacy dynamic scheduling. Our results show that SPS has the potential to reduce the latency of cellular Internet of Things (cIoT) networks. We believe that SPS can be integrated into LTE-M and NB-IoT systems to support low-latency industrial applications.
Kofi Atta Nsiah, Zubair Amjad, Axel Sikora, Benoît Hilt
PIMRC3
2019 Design and Evaluation of a Printed Analog-Based Differential Physical Unclonable Function
abstract
A physical unclonable function (PUF) is a hardware circuit that produces a random sequence based on its manufacturing-induced intrinsic characteristics. In the past decade, silicon-based PUFs have been extensively studied as a security primitive for identification and authentication. The emerging field of printed electronics (PE) enables novel application fields in the scope of the Internet of Things (IoT) and smart sensors. In this paper, we design and evaluate a printed differential circuit PUF (DiffC-PUF). The simulation data are verified by Monte Carlo analysis. Our design is highly scalable while consisting of a low number of printed transistors. Furthermore, we investigate the best operating point by varying the PUF challenge configuration and analyzing the PUF security metrics in order to achieve high robustness. At the best operating point, the results show areliability of 98.37% and a uniqueness of 50.02%, respectively. This analysis also provides useful and comprehensive insights into the design of hybrid or fully printed PUF circuits. In addition, the proposed printed DiffC-PUF core has been fabricated with electrolyte-gated field-effect transistor technology to verify our design in hardware.
Lukas Zimmermann, Alexander Scholz, Mehdi Baradaran Tahoori, Jasmin Aghassi-Hagmann, Axel Sikora
IEEE Trans. Very Large Scale Integr. Syst.5
2018 Low Latency V2X Applications and Network Requirements: Performance Evaluation
abstract
Vehicle-to-Everything (V2X) communication promises improvements in road safety and efficiency by enabling low-latency and reliable communication services for vehicles. Besides using Mobile Broadband (MBB), there is a need to develop Ultra Reliable Low Latency Communications (URLLC) applications with cellular networks especially when safety-related driving applications are concerned. Future cellular networks are expected to support novel latencysensitive use cases. Many applications of V2X communication, like collaborative autonomous driving requires very low latency and high reliability in order to support real-time communication between vehicles and other network elements. In this paper, we classify V2X use-cases and their requirements in order to identify cellular network technologies able to support them. The bottleneck problem of the medium access in 4G Long Term Evolution(LTE) networks is random access procedure. It is evaluated through simulations to further detail the future limitations and requirements. Limitations and improvement possibilities for next generation of cellular networks are finally detailed. Moreover, the results presented in this paper provide the limits of different parameter sets with regard to the requirements of V2X-based applications. In doing this, a starting point to migrate to Narrowband IoT (NB-IoT) or 5G - solutions is given.
Zubair Amjad, Axel Sikora, Benoît Hilt, Jean-Philippe Lauffenburger
Intelligent Vehicles Symposium2
2013 A localization system using inertial measurement units from wireless commercial hand-held devices
abstract
This paper describes a newly developed technology for the calculation of trajectories of mobile objects, which is based on commercially available sensors being integrated into modern mobile phones and other gadgets. First, a step counting technique was implemented. Second, a novel step length estimator is proposed. These two algorithms utilize the data from accelerometer sensor only. Third, the heading information was obtained using a gyroscope with complementary filter in quaternion form. The combined algorithm was implemented on a low-power ARM processor to provide the trajectory points relative to an initial point. The proposed technique was tested by 10 subjects, in different shoes with different paces. The dependence of the performance of the technology on the attaching point of the mobile device is weak. The proposed algorithms have better balance and estimation accuracy and depend in less degree on the variety in physical parameters of people in comparison with the existing techniques. In experiments inertial measurement units were mounted in different places, i.e. in the hand, in trousers or in T-shirt pockets. The return position error did not exceed 5% of the total travelled distance for all performed tests.
Aleksandr Mikov, Alex P. Moschevikin, Axel Sikora
IPIN4
2012 COARSE: a cluster-based quality-oriented adaptive radio resource allocation scheme
abstract
There is an increasing demand by an ever-growing number of mobile customers for transfer of rich media content. This requires very high bandwidth which either cannot be provided by the current cellular systems or puts pressure on the wireless networks, affecting customer service quality. This study introduces COARSE – a novel cluster-based quality-oriented adaptive radio resource allocation scheme, which dynamically and adaptively manages the radio resources in a cluster-based two-hop multi-cellular network, having a frequency reuse of one. COARSE is a cross-layer approach across physical layer, link layer and the application layer. COARSE gathers data delivery-related information from both physical and link layers and uses it to adjust bandwidth resources among the video streaming end-users. Extensive analysis and simulations show that COARSE enables a controlled trade-off between the physical layer data rate per user and the number of users communicating using a given resource. Significantly, COARSE provides 25–75% improvement in the computed user-perceived video quality compared with that obtained from an equivalent single-hop network.
Hrishikesh Venkataraman, A. Chowdhary, Axel Sikora, Gabriel-Miro Muntean
IET Commun.3
2009 A distributed embedded web based automated testbed for wireless sensor networks
abstract
Tests of distributed wireless networks pose various challenges with regard to node, link, path, and management problems. In this contribution a novel testbed architecture is presented, which helps in the development of distributed wireless networks. In the case of our project, it helped with the development of a routing protocol for energy autarkic network nodes. The testbed contains various elements: The major part is an embedded web server using web and AJAX technology. Thus, the management servers resources can be kept extremely lean, and a large number of those nodes can potentially be dislocated throughout the network. The server includes an extremely streamlined JavaScript-library for use on very lean microcontrollers. Further elements include a wave-guided bread-board RF installation, fully controlled by software in order to automatically run as many test-cases as possible and automatic test routines in the wireless nodes to significantly reduce the effort of regression tests.
Lars Möllendorf, David Rahusen, Daniel Schauenberg, Axel Sikora
IWCMC4
2008 Wireless technologies for safe automation - insights in protocol development
abstract
Short-range wireless networks (SRWN) are becoming more and more popular for sensor and actuator connectivity in industrial, building and home automation. These markets are evolving rapidly with many market players developing technologies and providing products. However, wireless networks still suffer from their lower degree of short-term reliability, and pose additional requirements to the use of wireless communication into hard real-time and safety relevant systems. This contribution discusses the most important aspects of the integration of wireless communication into hard real-time and safety relevant systems. It also gives insights into the development of a protocol for a sub 5 ms class wireless communication.
Dirk Lill, Axel Sikora
ETFA2
2003 Virtual Private Infrastructure (VPI) initiative - an industry consortium for unified and secure Web control with embedded devices
abstract
Remote maintenance and control is already widely used in industrial automation and building automation and gains acceptance for many other applications, e.g. smart home appliances, consumer electronics, networking devices. Internet and Web-based connectivity is playing a major part in unifying network infrastructure and company information flow. However, a number of different implementations hinder a true interoperability of devices and exchangeability of suppliers in the different business levels. Virtual Private Infrastructure (VPI) Initiative is an industry consortium providing basic guidelines for unified and secure Web-based control with embedded devices.
Axel Sikora, Peter Brügger
ETFA (1)1