EDBT 2026 Demo / reviewers in the wild / expert
Shahid Raza
dblp:83/9341
· DBLP profile ↗
40ranked-venue papers
10as first author
16since 2021 · last 2026
0000-0001-8192-0893ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 14 · 4 first-author · 3 since 2021Security and privacy · 13 · 1 first-author · 7 since 2021Systems, architecture and hardware · 4 · 2 first-author · 1 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Edge-Assisted Trust Establishment and Pre-Authentication for 6G Networksabstract6G network is expected to support a high number of devices, which require adopting decentralized architectures and lightweight protocols, to allow the systems to effectively meet the demands of such networks. However, the authentication is performed only after an initial connection has already been established, leaving the network exposed to unauthenticated devices during the initial phase. In this paper, we propose an edge-assisted trust establishment scheme for B5G/6G networks that shifts the pre-authentication process closer to the edge, particularly when establishing end-to-end communication with an external Application Function. It starts the trust establishment process from the initial access request sent by the User Equipment (UE). This enables the gNB to verify UE attributes before engaging in full authentication procedures. Such an approach will reduce the attack surface and unnecessary resource usage. The proposed scheme has been evaluated, and the results demonstrated that the proposed approach is both secure and efficient in edge nodes. A formal verification of the scheme has also been conducted using the TAMARIN prover, which confirmed its security guarantees. Mohammed B. Alshawki, Janneke Van Oosterhout, Yehao Zhou, Daniel Hindemburg de Miranda Marques, Sándor Laki, Péter Ligeti, Dalton C. G. Valadares, Shahid Raza |
NetSoft | 8 |
| 2025 | Cyber Threat Intelligence meets the Analytic TradecraftabstractThe volumes and sophistication of cyber threats in today’s cyber threat landscape have risen to levels where automated quantitative tools for Cyber Threat Intelligence (CTI) have become an indispensable part in the cyber defense arsenals. The AI and cyber security research communities are producing novel automated tools for CTI that quickly find their ways into commercial products. However, the quality of such automated intelligence products is being questioned by the intelligence community. Cyber security operators are forced to complement the automated tools with costly and time-consuming human intelligence analysis in order to improve the quality of the end product. For improving the quality, it has been suggested that researchers should incorporate methods from traditional intelligence analysis into the quantitative algorithms. This article presents a novel approach to cyber intelligence analysis called AMBARGO, which takes the inherent ambiguity of evidence into account in the analysis, using the Choquet integral, in formalizing the re-evaluation of evidence and hypotheses made by human analysts. The development of AMBARGO revolves around a cyber attribution use case, one of the hardest problems in CTI. The results of our evaluating experiments show that the robustness of AMBARGO outperforms state-of-the-art quantitative approaches to CTI in the presence of ambiguous evidence and potentially deceptive threat actor tactics. AMBARGO has thus the potential to fill a gap in the CTI state-of-the-art, which currently handles ambiguity poorly. The findings are also confirmed in a large-scale realistic experimental setting based on data from an APT campaign obtained from the MITRE ATT&CK Framework. Björn Bjurling, Shahid Raza |
ACM Trans. Priv. Secur. | 2 |
| 2024 | BMI: Bounded Mutual Information for Efficient Privacy-Preserving Feature Selection
David Eklund, Alfonso Iacovazzi, Han Wang 0031, Apostolos Pyrgelis, Shahid Raza |
ESORICS (2) | 5 |
| 2024 | CLEVER: Crafting Intelligent MISP for Cyber Threat IntelligenceabstractCyber Threat Intelligence (CTI) is crucial for modern cybersecurity because it provides the knowledge and insights needed to defend against a wide range of cyber threats. However, there are issues associated with incomplete and inconsistent CTI data that can lead to inaccurate threat assessments, increasing the risk of both false alarms and undetected threats. This paper introduces CLEVER, an extended version of the Malware Information Sharing Platform (MISP) platform that includes machine learning (ML) models to support the management and processing of CTI data. The models are designed to address specific challenges such as (i) prioritizing and ranking Indicators of Compromise (IoCs) based on severity and potential impact, (ii) classifying IoCs by attack type or threat, and (iii) aggregating similar IoCs into clusters. The effectiveness of the ML models employed in CLEVER has been thoroughly tested on three public CTI datasets, and the results provide encouraging outcomes in enhancing CTI management and analysis. Han Wang 0031, Alfonso Iacovazzi, Seonghyun Kim, Shahid Raza |
LCN | 4 |
| 2024 | Enhancing Software-Defined Networking With Dynamic Load Balancing and Fault Tolerance Using a Q-Learning ApproachabstractABSTRACT The Software‐Defined Networking (SDN) paradigm represents a fundamental shift in networking by decoupling the control plane from the data plane in network devices. This architectural change offers numerous advantages, including network programmability and centralized management capabilities, which improve scalability and efficiency compared to conventional network architectures. However, the dynamic nature of network traffic presents overload challenges, both temporally and spatially, especially in multi‐controller SDN settings. To address these challenges, this paper presents an approach leveraging network traffic patterns for dynamic load balancing. The proposed framework optimizes migration strategies to reduce costs and enhance in‐packet request‐response rates. By exploiting load ratio variance across controllers, the architecture identifies optimal migration triplets, encompassing migration‐in and migration‐out domains by selecting a subset of switches. The architecture utilizes online Q‐learning technology to achieve optimal controller load balancing while minimizing associated expenses. The proposed approach ensures stability and scalability by imposing limits to maintain maximum efficiency and reduce migration conflicts. It iteratively converges to an optimal policy through a comprehensive set of simulations performed on switches under a wide range of load distribution situations. These results highlight the effectiveness and adaptability of the proposed methodology in addressing the intricacies present in dynamic network settings, encouraging further progress in the field of SDN technologies and their real‐world applications. Ankit Kumar Jain, Rajat Dhull, Krish Jindal, Shahid Raza |
Concurr. Comput. Pract. Exp. | 5 |
| 2024 | Can serious gaming tactics bolster spear-phishing and phishing resilience? : Securing the human hacking in Information SecurityabstractIn the digital age, there is a notable increase in fraudulent activities perpetrated by social engineers who exploit individuals’ limited knowledge of digital devices. These actors strategically manipulate human psychology, targeting IT devices to gain unauthorized access to sensitive data. Our study is centered around two distinct objectives to be accomplished through the utilization of a serious game: (i) The primary objective entails delivering training and educational content to participants with a focus on phishing attacks; (ii) The secondary objective aims to heighten participants’ awareness regarding the perils associated with divulging excessive information online. To address these objectives, we have employed the following techniques and methods: (i) A comprehensive literature review was conducted to establish foundational knowledge in areas such as social engineering, game design, learning principles, human interaction, and game-based learning; (ii) We meticulously aligned the game design with the philosophical concept of social engineering attacks; (iii) We devised and crafted an advanced hybrid version of the game, incorporating the use of QR codes to generate game card data; (iv) We conducted an empirical evaluation encompassing surveys, observations, discussions, and URL assessments to assess the effectiveness of the proposed hybrid game version. Quantitative data and qualitative observations suggest the “PhishDefend Quest” game successfully improved players’ comprehension of phishing threats and how to detect them through an interactive learning experience. The results highlight the potential of serious games to educate people about social engineering risks. Through the evaluation, we can readily arrive at the following conclusions: (i) Game-based learning proves to be a viable approach for educating participants about phishing awareness and the associated risks tied to the unnecessary disclosure of sensitive information online; (ii) Furthermore, game-based learning serves as an effective means of disseminating awareness among participants and players concerning prevalent phishing attacks. Affan Yasin, Rubia Fatima, Wasif Afzal, Shahid Raza |
Inf. Softw. Technol. | 5 |
| 2023 | AutoCert: Automated TOCTOU-secure digital certification for IoT with combined authentication and assuranceabstractThe Internet of Things (IoT) network is comprised of heterogeneous devices which are part of critical infrastructures throughout the world. To enable end-to-end security, the Public Key Infrastructure (PKI) is undergoing advancements to incorporate IoT devices globally which primarily provides device authentication. In addition to this, integrity of the software-state is vital, where Remote Attestation (RA) and Integrity Certificates play an important role. Though, Integrity Certificate verifies the software-state integrity of the device at the time of execution of the remote attestation process, it does not provide mechanisms to validate that the current software-state corresponds to the attested state. This issue is referred to as the Time-Of-Check to Time-Of-Use (TOCTOU) problem and remains unsolved in the context of Integrity Certificates. In this paper, we propose AutoCert, the first TOCTOU-secure mechanism to combine software-state integrity with PKI for IoT which resolves the TOCTOU problem in RA and Integrity Certificates. To this end, we utilize the IETF Remote Attestation Procedures architecture and standard X509 IoT profile certificates to ensure both device authentication and software assurance for IoT. We implement and evaluate the performance of the AutoCert proof-of-concept on a real IoT device, the OPTIGA TPM Evaluation Kit, to show its practicality and usability. AutoCert can validate the attested state of an IoT device in approximately 4746 milliseconds, with a minimal network overhead of 350 bytes. Anum Khurshid, Shahid Raza |
Comput. Secur. | 2 |
| 2023 | SparSFA: Towards robust and communication-efficient peer-to-peer federated learningabstractFederated Learning (FL) has emerged as a powerful paradigm to train collaborative machine learning (ML) models, preserving the privacy of the participants’ datasets. However, standard FL approaches present some limitations that can hinder their applicability in some applications. Thus, the need of a server or aggregator to orchestrate the learning process may not be possible in scenarios with limited connectivity, as in some IoT applications, and offer less flexibility to personalize the ML models for the different participants. To sidestep these limitations, peer-to-peer FL (P2PFL) provides more flexibility, allowing participants to train their own models in collaboration with their neighbors. However, given the huge number of parameters of typical Deep Neural Network architectures, the communication burden can also be very high. On the other side, it has been shown that standard aggregation schemes for FL are very brittle against data and model poisoning attacks. In this paper, we propose SparSFA, an algorithm for P2PFL capable of reducing the communication costs. We show that our method outperforms competing sparsification methods in P2P scenarios, speeding the convergence and enhancing the stability during training. SparSFA also includes a mechanism to mitigate poisoning attacks for each participant in any random network topology. Our empirical evaluation on real datasets for intrusion detection in IoT, considering both balanced and imbalanced-dataset scenarios, shows that SparSFA is robust to different indiscriminate poisoning attacks launched by one or multiple adversaries, outperforming other robust aggregation methods whilst reducing the communication costs through sparsification. Han Wang 0031, Luis Muñoz-González, Muhammad Zaid Hameed, David Eklund, Shahid Raza |
Comput. Secur. | 5 |
| 2023 | Secure Equality Test Technique Using Identity-Based Signcryption for Telemedicine SystemsabstractFor telemedicine, Wireless Body Area Network (WBAN) offers enormous benefits where a patient can be remotely monitored without compromising the mobility of remote treatments. With the advent of high capacity and reliable wireless networks, WBANs are used in several remote monitoring systems, limiting the COVID-19 spread. The sensitivity of telemedicine applications mandates confidentiality and privacy requirements. In this paper, we propose a secure WBAN-19 telemedicine system to overcome the pervasiveness of contagious deceases utilizing a novel aggregate identity-based signcryption scheme with an equality test feature. We demonstrate a security analysis regarding indistinguishable adaptive chosen-ciphertext attack (IND-CCA2), one-way security against adaptive chosen-ciphertext attack (OW-CCA2), and unforgeability against adaptive chosen-message attack (EUF-CMA) under the random oracle model. The security analysis of the scheme is followed by complexity evaluations where the computation cost and communication overhead are measured. The evaluation demonstrates that the proposed model is efficient and applicable in telemedicine systems with high-performance capacities. Mohammed Ramadan, Shahid Raza |
IEEE Internet Things J. | 2 |
| 2023 | Lightweight certificate revocation for low-power IoT with end-to-end securityabstractPublic key infrastructure (PKI) provides the basis of authentication and access control in most networked systems. In the Internet of Things (IoT), however, security has predominantly been based on pre-shared keys (PSK), which cannot be revoked and do not provide strong authentication. The prevalence of PSK in the IoT is due primarily to a lack of lightweight protocols for accessing PKI services. Principal among these services are digital certificate enrollment and revocation, the former of which is addressed in recent research and is being pushed for standardization in IETF. However, no protocol yet exists for retrieving certificate status information on constrained devices, and revocation is not possible unless such a service is available. In this work, we start with implementing the Online Certificate Status Protocol (OCSP), the de facto standard for certificate validation on the Web, on state-of-the-art constrained hardware. In doing so, we demonstrate that the resource overhead of this protocol is unacceptable for highly constrained environments. We design, implement and evaluate a lightweight alternative to OCSP, TinyOCSP, which leverages recently standardized IoT protocols, such as CoAP and CBOR. In our experiments, validating eight certificates with TinyOCSP required 41% less energy than validating just one with OCSP on an ARM Cortex-M3 SoC. Moreover, validation transactions encoded with TinyOCSP are at least 73% smaller than the OCSP equivalent. We design a protocol for compressed certificate revocation lists (CCRL) using Bloom filters which together with TinyOCSP can further reduce validation overhead. We derive a set of equations for computing the optimal filter parameters, and confirm these results through empirical evaluation. Joel Höglund, Martin Furuhed, Shahid Raza |
J. Inf. Secur. Appl. | 3 |
| 2023 | ShieLD: Shielding Cross-Zone Communication Within Limited-Resourced IoT Devices Running Vulnerable Software StackabstractSecuring IoT devices is gaining attention as the security risks associated with these devices increase rapidly. TrustZone-M, a Trusted Execution Environment (TEE) for Cortex-M processors, ensures stronger security within an IoT device by allowing isolated execution of security-critical operations, without trusting the entire software stack. However, TrustZone-M does not guarantee secure cross-world communication between applications in the Normal and Secure worlds. The cryptographic protection of the communication channel is an obvious solution; however, within a low-power IoT device, it incurs high overhead if applied to each cross-world message exchange. We present ShieLD, a framework that enables a secure communication channel between the two TrustZone-M worlds by leveraging the Memory Protection Unit (MPU). ShieLD guarantees confidentiality, integrity and authentication services without requiring any cryptographic operations. We implement and evaluate ShieLD using a Musca-A test chip board with Cortex-M33 that supports TrustZone-M. Our empirical evaluation shows, among other gains, the cross-zone communication protected with ShieLD is5 timesfaster than the conventional crypto-based communication. Anum Khurshid, Sileshi Demesie Yalew, Mudassar Aslam, Shahid Raza |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | FL4IoT: IoT Device Fingerprinting and Identification Using Federated LearningabstractUnidentified devices in a network can result in devastating consequences. It is, therefore, necessary to fingerprint and identify IoT devices connected to private or critical networks. With the proliferation of massive but heterogeneous IoT devices, it is getting challenging to detect vulnerable devices connected to networks. Current machine learning-based techniques for fingerprinting and identifying devices necessitate a significant amount of data gathered from IoT networks that must be transmitted to a central cloud. Nevertheless, private IoT data cannot be shared with the central cloud in numerous sensitive scenarios. Federated learning (FL) has been regarded as a promising paradigm for decentralized learning and has been applied in many different use cases. It enables machine learning models to be trained in a privacy-preserving way. In this article, we propose a privacy-preserved IoT device fingerprinting and identification mechanisms using FL; we call it FL4IoT. FL4IoT is a two-phased system combining unsupervised-learning-based device fingerprinting and supervised-learning-based device identification. FL4IoT shows its practicality in different performance metrics in a federated and centralized setup. For instance, in the best cases, empirical results show that FL4IoT achieves ∼99% accuracy and F1-Score in identifying IoT devices using a federated setup without exposing any private data to a centralized cloud entity. In addition, FL4IoT can detect spoofed devices with over 99% accuracy . Han Wang 0031, David Eklund, Alina Oprea, Shahid Raza |
ACM Trans. Internet Things | 4 |
| 2022 | A Look-ahead Towards 6G Security (Abstract)abstract6G system is in an active race to be fully deployed by 2030. 6G system is expected to provide ultra-low latency, low power consumption, ultra-high capacity, seamless coverage, high localization precision, massive MIMO (small cell and cell-free) techniques, millimeter- wave (mmWave), and terahertz (THz) bands. The high-performance specifications will enable new technologies within 6G systems. Consequently, these new technologies will significantly impact the security and privacy of the upcoming 6G system. Therefore, novel security techniques (encryption, authentication, privacy-preserving, key agreement, access control, or some fundamental changes must be considered; for instance, distributed mutual authentication protocols are highly needed for some new 6G-based technologies (e.g., HWN), whereas end-to-end security and encryption protocols are essential for some others. Thus, extensive research must be carried out to meet all system/security requirements and ensure the reliability and functionality of the upcoming 6G system. Mohammed Ramadan, Shahid Raza |
CW | 2 |
| 2022 | Attestation Mechanisms for Trusted Execution Environments DemystifiedabstractAttestation is a fundamental building block to establish trust over software systems. When used in conjunction with trusted execution environments, it guarantees the genuineness of the code executed against powerful attackers and threats, paving the way for adoption in several sensitive application domains. This paper reviews remote attestation principles and explains how the modern and industrially well-established trusted execution environments Intel SGX, Arm TrustZone and AMD SEV, as well as emerging RISC-V solutions, leverage these mechanisms. Jämes Ménétrey, Christian Göttel, Anum Khurshid, Marcelo Pasin, Pascal Felber, Valerio Schiavoni, Shahid Raza |
DAIS | 7 |
| 2021 | Establishing End-to-End Secure Channel for IoT Devices through an Untrusted C-ITS Network
Simon Bouget, Shahid Raza, Martin Furuhed |
VEHITS | 2 |
| 2021 | Non-IID data re-balancing at IoT edge with peer-to-peer federated learning for anomaly detectionabstractThe increase of the computational power in edge devices has enabled the penetration of distributed machine learning technologies such as federated learning, which allows to build collaborative models performing the training locally in the edge devices, improving the efficiency and the privacy for training of machine learning models, as the data remains in the edge devices. However, in some IoT networks the connectivity between devices and system components can be limited, which prevents the use of federated learning, as it requires a central node to orchestrate the training of the model. To sidestep this, peer-to-peer learning appears as a promising solution, as it does not require such an orchestrator. On the other side, the security challenges in IoT deployments have fostered the use of machine learning for attack and anomaly detection. In these problems, under supervised learning approaches, the training datasets are typically imbalanced, i.e. the number of anomalies is very small compared to the number of benign data points, which requires the use of re-balancing techniques to improve the algorithms' performance. In this paper, we propose a novel peer-to-peer algorithm,P2PK-SMOTE, to train supervised anomaly detection machine learning models in non-IID scenarios, including mechanisms to locally re-balance the training datasets via synthetic generation of data points from the minority class. To improve the performance in non-IID scenarios, we also include a mechanism for sharing a small fraction of synthetic data from the minority class across devices, aiming to reduce the risk of data de-identification. Our experimental evaluation in real datasets for IoT anomaly detection across a different set of scenarios validates the benefits of our proposed approach. Han Wang 0031, Luis Muñoz-González, David Eklund, Shahid Raza |
WISEC | 4 |
| 2020 | FoNAC - An automated Fog Node Audit and Certification scheme
Mudassar Aslam, Bushra Mohsin, Abdul Nasir Khan, Shahid Raza |
Comput. Secur. | 4 |
| 2020 | PKI4IoT: Towards public key infrastructure for the Internet of ThingsabstractPublic Key Infrastructure is the state-of-the-art credential management solution on the Internet. However, the millions of constrained devices that make of the Internet of Things currently lack a centralized, scalable system for managing keys and identities. Modern PKI is built on a set of protocols which were not designed for constrained environments, and as a result many small, battery-powered IoT devices lack the required computing resources. In this paper, we develop an automated certificate enrollment protocol light enough for highly constrained devices, which provides end-to-end security between certificate authorities (CA) and the recipient IoT devices. We also design a lightweight profile for X.509 digital certificates with CBOR encoding, called XIOT. Existing CAs can now issue traditional X.509 to IoT devices. These are converted to and from the XIOT format by edge devices on constrained networks. This procedure preserves the integrity of the original CA signature, so the edge device performing certificate conversion need not be trusted. We implement these protocols within the Contiki embedded operating system and evaluate their performance on an ARM Cortex-M3 platform. Our evaluation demonstrates reductions in energy expenditure and communication latency. The RAM and ROM required to implement these protocols are on par with the other lightweight protocols in Contiki’s network stack. Joel Höglund, Samuel Lindemer, Martin Furuhed, Shahid Raza |
Comput. Secur. | 4 |
| 2020 | Application Layer Key Establishment for End-to-End Security in IoTabstractIn most Internet of Things (IoT) deployments, intermediate entities are usually employed for efficiency and scalability reasons. These intermediate proxies break end-to-end security when using even the state-of-the-art transport layer security (TLS) solutions. In this direction, the recent object security for constrained RESTful environments (OSCORE) has been standardized to enable end-to-end security even in the presence of malicious proxies. In this article, we focus on the key establishment process based on application-layer techniques. In particular, we evaluate the ephemeral Diffie-Hellman over COSE (EDHOC), the de facto key establishment protocol for OSCORE. Based on EDHOC, we propose CompactEDHOC, as a lightweight alternative, in which negotiation of security parameters is extracted from the core protocol. In addition to providing end-to-end security properties, we perform extensive evaluation using real IoT hardware and simulation tools. Our evaluation results prove EDHOC-based proposals as an effective and efficient approach for the establishment of a security association in IoT-constrained scenarios. Salvador Pérez, José Luis Hernández-Ramos, Shahid Raza, Antonio F. Skarmeta |
IEEE Internet Things J. | 3 |
| 2019 | FDTLS: Supporting DTLS-Based Combined Storage and Communication Security for IoT DevicesabstractThis work presents FDTLS, a security framework that combines storage and network/communication-level security on resource limited Internet of Things (IoT) devices using Datagram Transport Layer Security (DTLS). While coalescing the storage and networking security schemes can reduce redundant and unnecessary cryptographic operations, we identify security-and system-level challenges that can occur when applying DTLS towards such concept. FDTLS addresses these challenges by employing an asymmetric key generation scheme, a virtual peer-based handshaking mechanism, and a header size reduction scheme. Our results obtained using Contiki-based implementations on OpenMote devices show that compared to using storage and networking security separately, FDTLS can reduce the network response latency and improve energy savings. EunSeong Boo, Shahid Raza, Joel Höglund, JeongGil Ko |
MASS | 2 |
| 2019 | Towards Supporting IoT Device Storage and Network Security Using DTLSabstractThis work presents FDTLS, a security framework that combines storage and network/communication-level security for resource limited Internet of Things (IoT) devices using Datagram Transport Layer Security (DTLS). While coalescing storage and networking security scheme can reduce redundent and unnecessary operations, we identify security- and system-level challenges that can occur when applying DTLS. FDTLS addresses these challenges by employing asymmetric key generation, a virtual peer, and header reduction-based storage optimization. Our results obtained using a Contiki-based implementation on OpenMote platforms show that compared to using storage and networking security separately, FDTLS can reduce the latency of packet transmission responses and also contribute to saving energy. EunSeong Boo, Shahid Raza, Joel Höglund, JeongGil Ko |
MobiSys | 2 |
| 2019 | Indraj: digital certificate enrollment for battery-powered wireless devicesabstractA public key infrastructure (PKI) has been widely deployed and well tested on the Internet. However, this standard practice of delivering scalable security has not yet been extended to the rapidly growing Internet of Things (IoT). Thanks to vendor hardware support and standardization of resource-efficient communication protocols, asymmetric cryptography is no longer unfeasible on small devices. To migrate IoT from poorly scalable, pair-wise symmetric encryption to PKI, a major obstacle remains: how do we certify the public keys of billions of small devices without manual checks or complex logistics? The process of certifying a public key in form of a digital certificate is called enrollment. In this paper, we design an enrollment protocol, called Indraj, to automate enrollment of certificate-based digital identities on resource-constrained IoT devices. Reusing the semantics of the Enrollment over Secure Transport (EST) protocol designed for Internet hosts, Indraj optimizes resource usage by leveraging an IoT stack consisting of Constrained Application Protocol (CoAP), Datagram Transport Layer Security (DTLS) and IPv6 over Low-Power Wireless Personal Area Networks (6LoWPAN). We evaluate our implementation on a low power 32-bit MCU, showing the feasibility of our protocol in terms of latency, power consumption and memory usage. Asymmetric cryptography enabled by automatic certificate enrollment will finally turn IoT devices into well behaved, first-class citizens on the Internet. Martin Furuhed, Shahid Raza |
WiSec | 3 |
| 2019 | TinyIKE: Lightweight IKEv2 for Internet of ThingsabstractThere is unanimous consensus that cyber security in the Internet of Things (IoT) is necessary. In cyber security, key establishment is one of the toughest problems. It is even more challenging in resource-constrained but Internet-connected IoT devices that use low-power wireless communication. A number of IoT communication protocols define cryptographic mechanisms for confidentiality and integrity services but do not specify key management. For example, IEEE 802.15.4, RPL, and object security all rely on external key management protocols. Due to the lack of automatic key management support, IoT devices either end up using preshared keys or no security at all. In this paper, we overcome these challenges and present TinyIKE, a lightweight adaptation of Internet Key Exchange version 2 (IKEv2) for the IoT. Using TinyIKE, we solve the key establishment problem for multiple IoT protocols using a single IKEv2-based solution. We implement TinyIKE for resource-constrained IoT devices that run the Contiki OS. The TinyIKE implementation supports full certificate-based IKEv2 that uses elliptic curve cryptography. In order to ensure the feasibility of TinyIKE in the IoT, we perform an extensive evaluation of TinyIKE using a setup consisting of real IoT hardware. Shahid Raza, Runar Mar Magnusson |
IEEE Internet Things J. | 1 |
| 2018 | POSTER: On Compressing PKI Certificates for Resource Limited Internet of Things DevicesabstractCertificate-based Public Key Infrastructure (PKI) schemes are used to authenticate the identity of distinct nodes on the Internet. Using certificates for the Internet of Things (IoT) can allow many privacy sensitive applications to be trusted over the larger Internet architecture. However, since IoT devices are typically resource limited, full sized PKI certificates are not suitable for use in the IoT domain. This work outlines our approach in compressing standards-compliant X.509 certificates so that their sizes are reduced and can be effectively used on IoT nodes. Our scheme combines the use of Concise Binary Object Representation (CBOR) and also a scheme that compresses all data that can be implicitly inferenced within the IoT sub-network. Our scheme shows a certificate compression rate of up to ~30%, which allows effective energy reduction when using X.509-based certificates on IoT platforms. HyukSang Kwon, Shahid Raza, JeongGil Ko |
AsiaCCS | 2 |
| 2018 | Towards Formal Verification of Contiki: Analysis of the AES-CCM* Modules with Frama-C
Alexandre Peyrard, Nikolai Kosmatov, Simon Duquennoy, Shahid Raza |
EWSN | 4 |
| 2017 | Protecting Glossy-Based Wireless Networks from Packet Injection AttacksabstractGlossy is a flooding-based communication primitive for low-power wireless networks that leverages constructive interference to achieve high reliability. The Low-power Wireless Bus (LWB) uses Glossy to abstract an entire wireless network into a shared bus like topology. As Glossy is not designed as a secure communication protocol, Glossy and hence LWB are vulnerable to unauthorised eavesdropping and packet injection attacks. In this paper, we propose several security mechanisms to protect Glossy and LWB communication and evaluate their effectiveness in real-world settings. The evaluation of the proposed security mechanisms shows that we can confine the effect of the packet injection attacks on Glossy networks into single hop nodes from the attacker. Kasun Hewage, Shahid Raza, Thiemo Voigt |
MASS | 2 |
| 2017 | Building the Internet of Things with bluetooth smart
Shahid Raza, Prasant Misra, Thiemo Voigt |
Ad Hoc Networks | 1 |
| 2017 | SecureSense: End-to-end secure communication architecture for the cloud-connected Internet of Things
Shahid Raza, Tómas Helgason, Panagiotis Papadimitratos, Thiemo Voigt |
Future Gener. Comput. Syst. | 1 |
| 2017 | Axiom: DTLS-Based Secure IoT Group CommunicationabstractThis article presents Axiom, a DTLS-based approach to efficiently secure multicast group communication among IoT-constrained devices. Axiom provides an adaptation of the DTLS record layer, relies on key material commonly shared among the group members, and does not require one to perform any DTLS handshake. We made a proof-of-concept implementation of Axiom based on the tinyDTLS library for the Contiki OS and used it to experimentally evaluate performance of our approach on real IoT hardware. Results show that Axiom is affordable on resource-constrained platforms and performs significantly better than related alternative approaches. Marco Tiloca, Kirill Nikitin 0001, Shahid Raza |
ACM Trans. Embed. Comput. Syst. | 3 |
| 2016 | Fusion: coalesced confidential storage and communication framework for the IoTabstractAbstract Comprehensive security mechanisms are required for a successful implementation of the Internet of Things (IoT). Existing solutions focus mainly on securing the communication links between Internet hosts and IoT devices. However, as most IoT devices nowadays provide vast amounts of flash storage space, it is as well required to consider storage security within a comprehensive security framework. Instead of developing independent security solutions for storage and communication, we propose Fusion, a framework that provides coalesced confidential storage and communication. Fusion uses existing secure communication protocols for the IoT such as Internet protocol security (IPsec) and datagram transport layer security (DTLS) and re‐uses the defined communication security mechanisms within the storage component. Thus, trusted mechanisms developed for communication security are extended into the storage space. Notably, this mechanism allows us to transmit requested data directly from the file system without decrypting read data blocks and then re‐encrypting these for transmission. Thus, Fusion provides benefits in terms of processing speed and energy efficiency, which are important aspects for resource‐constrained IoT devices. This paper describes the Fusion architecture and its instantiation for IPsec‐based and DTLS‐based systems. We describe Fusion's implementation and evaluate its storage overheads, communication performance, and energy consumption. Copyright © 2015 John Wiley & Sons, Ltd. Ibrahim Ethem Bagci, Shahid Raza, Utz Roedig, Thiemo Voigt |
Secur. Commun. Networks | 2 |
| 2016 | S3K: Scalable Security With Symmetric Keys - DTLS Key Establishment for the Internet of ThingsabstractDTLS is becoming the de facto standard for communication security in the Internet of Things (IoT). In order to run the DTLS protocol, one needs to establish keys between the communicating devices. The default method of key establishment requires X.509 certificates and a Public Key Infrastructure, an approach which is often too resource consuming for small IoT devices. DTLS also supports the use of preshared keys and raw public keys. These modes are more lightweight, but they are not scalable to a large number of devices. Shahid Raza, Ludwig Seitz, Denis Sitenkov, Göran Selander |
IEEE Trans Autom. Sci. Eng. | 1 |
| 2015 | Bluetooth smart: An enabling technology for the Internet of ThingsabstractThe past couple of years have seen a heightened interest in the Internet of Things (IoT), transcending industry, academia and government. As with new ideas that hold immense potential, the optimism of IoT has also exaggerated the underlying technologies well before they can mature into a sustainable ecosystem. While 6LoWPAN has emerged as a disruptive technology that brings IP capability to networks of resource constrained devices, a suitable radio technology for this device class is still debatable. In the recent past, Bluetooth Low Energy (LE) — a subset of the Bluetooth v4.0 stack — has surfaced as an appealing alternative that provides a low-power and loosely coupled mechanism for sensor data collection with ubiquitous units (e.g., smartphones and tablets). When Bluetooth 4.0 was first released, it was not targeted for IP-connected devices but for communication between two neighboring peers. However, the latest release of Bluetooth 4.2 offers features that makes Bluetooth LE a competitive candidate among the available low-power communication technologies in the IoT space. In this paper, we discuss the novel features of Bluetooth LE and its applicability in 6LoWPAN networks. We also highlight important research questions and pointers for potential improvement for its greater impact. Shahid Raza, Prasant Misra, Thiemo Voigt |
WiMob | 1 |
| 2014 | Delegation-based authentication and authorization for the IP-based Internet of ThingsabstractIP technology for resource-constrained devices enables transparent end-to-end connections between a vast variety of devices and services in the Internet of Things (IoT). To protect these connections, several variants of traditional IP security protocols have recently been proposed for standardization, most notably the DTLS protocol. In this paper, we identify significant resource requirements for the DTLS handshake when employing public-key cryptography for peer authentication and key agreement purposes. These overheads particularly hamper secure communication for memory-constrained devices. To alleviate these limitations, we propose a delegation architecture that offloads the expensive DTLS connection establishment to a delegation server. By handing over the established security context to the constrained device, our delegation architecture significantly reduces the resource requirements of DTLS-protected communication for constrained devices. Additionally, our delegation architecture naturally provides authorization functionality when leveraging the central role of the delegation server in the initial connection establishment. Hence, in this paper, we present a comprehensive, yet compact solution for authentication, authorization, and secure data transmission in the IP-based IoT. The evaluation results show that compared to a public-key-based DTLS handshake our delegation architecture reduces the memory overhead by 64 %, computations by 97 %, network transmissions by 68 %. René Hummen, Hossein Shafagh, Shahid Raza, Thiemo Voigt, Klaus Wehrle |
SECON | 3 |
| 2014 | Secure communication for the Internet of Things - a comparison of link-layer security and IPsec for 6LoWPANabstractABSTRACT The future Internet is an IPv6 network interconnecting traditional computers and a large number of smart objects. This Internet of Things (IoT) will be the foundation of many services and our daily life will depend on its availability and reliable operation. Therefore, among many other issues, the challenge of implementing secure communication in the IoT must be addressed. In the traditional Internet, IPsec is the established and tested way of securing networks. It is therefore reasonable to explore the option of using IPsec as a security mechanism for the IoT. Smart objects are generally added to the Internet using IPv6 over Low‐power Wireless Personal Area Networks (6LoWPAN), which defines IP communication for resource‐constrained networks. Thus, to provide security for the IoT based on the trusted and tested IPsec mechanism, it is necessary to define an IPsec extension of 6LoWPAN. In this paper, we present such a 6LoWPAN/IPsec extension and show the viability of this approach. We describe our 6LoWPAN/IPsec implementation, which we evaluate and compare with our implementation of IEEE 802.15.4 link‐layer security. We also show that it is possible to reuse crypto hardware within existing IEEE 802.15.4 transceivers for 6LoWPAN/IPsec. The evaluation results show that IPsec is a feasible option for securing the IoT in terms of packet size, energy consumption, memory usage, and processing time. Furthermore, we demonstrate that in contrast to common belief, IPsec scales better than link‐layer security as the data size and the number of hops grow, resulting in time and energy savings. Copyright © 2012 John Wiley & Sons, Ltd. Shahid Raza, Simon Duquennoy, Joel Höglund, Utz Roedig, Thiemo Voigt |
Secur. Commun. Networks | 1 |
| 2013 | Combined secure storage and communication for the Internet of ThingsabstractThe future Internet of Things (IoT) may be based on the existing and established Internet Protocol (IP). Many IoT application scenarios will handle sensitive data. However, as security requirements for storage and communication are addressed separately, work such as key management or cryp-tographic processing is duplicated. In this paper we present a framework that allows us to combine secure storage and secure communication in the IP-based IoT. We show how data can be stored securely such that it can be delivered securely upon request without further cryptographic processing. Our prototype implementation shows that combined secure storage and communication can reduce the security-related processing on nodes by up to 71% and energy consumption by up to 32.1%. Ibrahim Ethem Bagci, Shahid Raza, T. tony Chung, Utz Roedig, Thiemo Voigt |
SECON | 2 |
| 2013 | SVELTE: Real-time intrusion detection in the Internet of Things
Shahid Raza, Linus Wallgren, Thiemo Voigt |
Ad Hoc Networks | 1 |
| 2012 | 6LoWPAN Compressed DTLS for CoAPabstractReal deployments of the IoT require security. CoAP is being standardized as an application layer protocol for the Internet of Things (IoT). CoAP proposes to use DTLS to provide end-to-end security to protect the IoT. DTLS is a heavyweight protocol and its headers are too long to fit in a single IEEE802.15.4 MTU. 6LoWPAN provides header compression mechanisms to reduce the size of upper layer headers. 6LoWPAN header compression mechanisms can be used to compress the security headers as well. In this paper we propose 6LoWPAN header compression for DTLS. We link our compressed DTLS with the 6LoWPAN standard using standardized mechanisms. We show that our proposed DTLS compression significantly reduces the number of additional security bits. For example, only for the DTLS Record header that is added in every DTLS packet, the number of additional security bits can be reduced by 62%. Our compressed-DTLS is the first lightweight 6LoWPAN extension for DTLS. Shahid Raza, Daniele Trabalza, Thiemo Voigt |
DCOSS | 1 |
| 2009 | Security Considerations for the WirelessHART ProtocolabstractWirelessHART is a secure and reliable communication standard for industrial process automation. The WirelessHART specifications are well organized in all aspects except security: there are no separate specifications of security requirements or features. Rather, security mechanisms are described throughout the documentation. This hinders implementation of the standard and development of applications since it requires profound knowledge of all the core specifications on the part of the developer. In this paper we provide a comprehensive overview of WirelessHART security: we analyze the provided security mechanisms against well known threats in the wireless medium, and propose recommendations to mitigate shortcomings. Furthermore, we elucidate the specifications of the security manager, its placement in the network, and interaction with the network manager. Shahid Raza, Adriaan Slabbert, Thiemo Voigt, Krister Landernäs |
ETFA | 1 |
| 2009 | Accurate Power Profiling of Sensornets with the COOJA/MSPSim SimulatorabstractPower consumption is of utmost concern in sensor networks. Researchers have several ways of measuring the power consumption of a complete sensor network, but they are typically either impractical or inaccurate. To meet the need for practical and scalable measurement of power consumption of sensor networks, we have developed a cycle-accurate simulator, called COOJA/MSPsim, that enables live power estimation of systems running on MSP430 processors. This demonstration shows the ease of use and the power measurement accuracy of COOJA/MSPsim. The demo setup consists of a small sensor network and a laptop. Beside gathering software-based power measurements from the motes, the laptop runs COOJA/MSPsim to simulate the same network.We visualize the power consumption of both the simulated and the real sensor network, and show that the simulator produces matching results. Joakim Eriksson, Fredrik Österlind, Thiemo Voigt, Niclas Finne, Shahid Raza, Nicolas Tsiftes, Adam Dunkels |
MASS | 5 |
| 2009 | Design and Implementation of a Security Manager for WirelessHART NetworksabstractWirelessHART is the first open standard for wireless sensor networks designed specifically for industrial process automation and control systems. WirelessHART is a secure protocol; however, it relies on a Security Manager for the management of the security keys and the authentication of new devices. The WirelessHART standard does not provide the specification and design of the Security Manager. Also, the security specifications in the standard are not well organized and are dispersed throughout the standard which makes an implementation of the standard more difficult. In this paper we provide the detailed specification and design as well as an implementation of the Security Manager for the WirelessHART standard. We evaluate our security manager against different cryptographic algorithms and measure the latency between the Network Manager and the Security Manager. Our evaluation shows that the proposed security manager meets the WirelessHART requirements. Our analysis shows that the provided Security Manager is capable of securing both the wireless and wired part of the WirelessHART network. Shahid Raza, Thiemo Voigt, Adriaan Slabbert, Krister Landernäs |
MASS | 1 |