EDBT 2026 Demo / reviewers in the wild / expert
Kimmo Halunen
dblp:87/5497
· DBLP profile ↗
18ranked-venue papers
3as first author
9since 2021 · last 2024
0000-0003-1169-5920ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 17 · 2 first-author · 9 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | NEWSROOM: Towards Automating Cyber Situational Awareness Processes and Tools for Cyber DefenceabstractCyber Situational Awareness (CSA) is an important element in both cyber security and cyber defence to inform processes and activities on strategic, tactical, and operational level. Furthermore, CSA enables informed decision making. The ongoing digitization and interconnection of previously unconnected components and sectors equally affects the civilian and military sector. In defence, this means that the cyber domain is both a separate military domain as well as a cross-domain and connecting element for the other military domains comprising land, air, sea, and space. Therefore, CSA must support perception, comprehension, and projection of events in the cyber space for persons with different roles and expertise. This paper introduces NEWSROOM, a research initiative to improve technologies, methods, and processes specifically related to CSA in cyber defence. For this purpose, NEWSROOM aims to improve methods for attacker behavior classification, cyber threat intelligence (CTI) collection and interaction, secure information access and sharing, as well as human computer interfaces (HCI) and visualizations to provide persons with different roles and expertise with accurate and easy to comprehend mission- and situation-specific CSA. Eventually, NEWSROOM’s core objective is to enable informed and fast decision-making in stressful situations of military operations. The paper outlines the concept of NEWSROOM and explains how its components can be applied in relevant application scenarios. Markus Wurzenberger, Stephan Krenn, Max Landauer, Florian Skopik, Cora Lisa Perner, Jarno Lötjönen, Jani Päijänen, Georgios Gardikis, Nikos Alabasis, Liisa Sakerman, Kristiina Omri, Juha Röning, Kimmo Halunen, Vincent Thouvenot, Martin Weise, Andreas Rauber, Vasileios Gkioulos, Sokratis K. Katsikas, Luigi Sabetta, Jacopo Bonato, Rocío Ortíz, Daniel Navarro, Nikolaos Stamatelatos, Ioannis Avdoulas, Rudolf Mayer, Andreas Ekelhart, Ioannis Giannoulakis, Emmanouil Kafetzakis, Antonello Corsi, Ulrike Lechner, Corinna Schmitt |
ARES | 13 |
| 2024 | Automating IoT Security Standard Testing by Common Security Tools
Rauli Kaksonen, Kimmo Halunen, Marko Laakso, Juha Röning |
ICISSP | 2 |
| 2024 | Security Analysis for BB84 Key DistillationabstractKey distillation, also referred to as classical post-processing, plays a pivotal role in Quantum Key Distribution (QKD) protocols. Key distillation encompasses numerous subroutines, making the analysis of its overall security implications potentially challenging for those outside the research community. In this paper, we elucidate the role of the key distillation phase in QKD from a security standpoint. We begin by analyzing the different components of the key distillation phase individually, followed by an examination of the process as a whole. We then calculate the bit strength of the produced key, assuming that an attacker is executing an intercept and resend attack. For our analysis, we employ a practical key distillation implementation linked to a decoy state BB84 protocol as a case study. Our findings suggest that the security of the final key, post the key distillation phase, hinges on several factors. These include the theoretical security of the implemented subroutines, the total information leakage throughout the process, and the choices of subroutine parameters. Given these assumptions, we can distill 287 secure bits for every 1000 bits that undergo the key distillation procedure. Sara Nikula, Anssi Lintulampi, Kimmo Halunen |
SECRYPT | 3 |
| 2023 | Vulnerabilities in IoT Devices, Backends, Applications, and Components
Rauli Kaksonen, Kimmo Halunen, Juha Röning |
ICISSP | 2 |
| 2023 | Transparent Security Method for Automating IoT Security Assessments
Rauli Kaksonen, Kimmo Halunen, Marko Laakso, Juha Röning |
ISPEC | 2 |
| 2022 | Applying a cryptographic metric to post-quantum lattice-based signature algorithmsabstractMeasuring the security of cryptographic systems is not a simple task. Nevertheless, there is an increasing need for a cryptographic metric which could assist in decision making when choosing between various candidates. The National Institute of Standards and Technology (NIST) has launched a process to standardize quantum-resistance public key encryption, key encapsulation and digital signature algorithms. This is NIST’s response to the threat posed by quantum computers against classical public key cryptography. In this paper, we apply a metric taxonomy, produced by earlier studies, to two NIST third round finalist digital signature algorithms Dilithium and Falcon in order to asses the effectiveness and extensiveness of the metric. Although, our results show that clear differences can be found with used metrics, we propose some improvements to them to allow more comprehensive analysis. Markus Rautell, Outi-Marja Latvala, Visa Antero Vallivaara, Kimmo Halunen |
ARES | 4 |
| 2022 | Implementing Post-quantum Cryptography for Developers
Julius Hekkala, Kimmo Halunen, Visa Antero Vallivaara |
ICISSP | 2 |
| 2022 | Common Cybersecurity Requirements in IoT Standards, Best Practices, and Guidelines
Rauli Kaksonen, Kimmo Halunen, Juha Röning |
IoTBDS | 2 |
| 2021 | Involving Humans in the Cryptographic Loop: Introduction and Threat Analysis of EEVEHACabstractOur digital lives rely on modern cryptography that is based on complicated mathematics average human users cannot follow. Previous attempts at adding the human user into the cryptographic loop include things like Human Authenticated Key Exchange and visualizable cryptography. This paper presents our proof-of-concept implementation of these ideas as a system called EEVEHAC. It utilizes human capabilities to achieve an end-to-end encrypted channel between a user and a server that is authenticated with human senses and can be used through untrusted environments. The security of this complete system is analyzed. We find that the combination of the two different systems into EEVEHAC on a theoretical level retains the security of the individual systems. We also identify the weaknesses of this implementation and discuss options for overcoming them. Julius Hekkala, Sara Nikula, Outi-Marja Latvala, Kimmo Halunen |
SECRYPT | 4 |
| 2017 | n-Auth: Mobile Authentication Done RightabstractWeak security, excessive personal data collection for user profiling, and a poor user experience are just a few of the many problems that mobile authentication solutions suffer from. Despite being an interesting platform, mobile devices are still not being used to their full potential for authentication. n-Auth is a firm step in unlocking the full potential of mobile devices in authentication, by improving both security and usability whilst respecting the privacy of the user. Our focus is on the combined usage of several strong cryptographic techniques with secure HCI design principles to achieve a better user experience. We specified and built n-Auth, for which robust Android and iOS apps are openly available through the official stores. Roel Peeters, Jens Hermans, Pieter Maene, Katri Grenman, Kimmo Halunen, Juha Häikiö |
ACSAC | 5 |
| 2017 | Evaluating the Efficiency of Blockchains in IoT with Simulations
Jari Kreku, Visa Antero Vallivaara, Kimmo Halunen, Jani Suomalainen |
IoTBDS | 3 |
| 2017 | Evaluation of user authentication methods in the gadget-free world
Kimmo Halunen, Juha Häikiö, Visa Antero Vallivaara |
Pervasive Mob. Comput. | 1 |
| 2016 | Improving the Sphinx Mix Network
Filipe Beato, Kimmo Halunen, Bart Mennink |
CANS | 2 |
| 2014 | Detecting man-in-the-middle attacks on non-mobile systemsabstractIn this paper we propose a method for detecting man-in-the-middle attacks using the timestamps of TCP packet headers. From these timestamps, the delays can be calculated and by comparing the mean of the delays in the current connection to data gathered from previous sessions it is possible to detect if the packets have unusually long delays. We show that in our small case study we can find and set a threshold parameter that accurately detects man-in-the-middle attacks with a low probability of false positives. Thus, it may be used as a simple precautionary measure against malicious attacks. The method in its current form is limited to non-mobile systems, where the variations in the delay are fairly low and uniform. Visa Antero Vallivaara, Mirko Sailio, Kimmo Halunen |
CODASPY | 3 |
| 2011 | Risk Assessment in Critical Infrastructure Security Modelling Based on Dependency Analysis - (Short Paper)
Thomas Schaberreiter, Kati Kittilä, Kimmo Halunen, Juha Röning, Djamel Khadraoui |
CRITIS | 3 |
| 2010 | Variants of Multicollision Attacks on Iterated Hash Functions
Tuomas Kortelainen, Juha Kortelainen, Kimmo Halunen |
Inscrypt | 3 |
| 2009 | Finding Preimages of Multiple Passwords Secured with VSHabstractIn this paper we present an improvement to the preimage attacks on Very Smooth Hash (VSH) function. VSH was proposed as a collision resistant hash function by Contini et al., but it has been found lacking in preimage resistance by Saarinen. With our method, we show how to find preimages of multiple passwords secured by VSH. We also demonstrate that our method is faster in finding preimages of multiple passwords than the methods proposed earlier. We tested the methods with five, ten and fifty randomised alphanumeric passwords. The results show that our method is many times faster than the original method of Saarinen and almost three times faster than the improved method proposed by Halunen et al. Furthermore, we argue that the methods presented previously and our method are essentially the only significantly different methods derivable from Saarinen's work. Kimmo Halunen, Pauli Rikula, Juha Röning |
ARES | 1 |
| 2008 | On the Security of VSH in Password SchemesabstractIn this paper we improve Saarinen's method for finding preimages of Very Smooth Hash (VSH) hash values and generalise it to some of the variants of VSH proposed by Contini et al. VSH is a new hash function that has been proved to be collision resistant under similar assumptions on the factoring of large integers as the RSA cipher. Saarinen has developed a method for finding preimages of VSH hash values and in his paper he gave an example of its application to 169-bit VSH and 4-character passwords consisting of lowercase alphabets. Because there were no results on the practical effectiveness of this approach with cryptographically significant security parameters, we give some results on the time and memory required to find the preimages of 8-character alphanumeric passwords secured by 1024-bit and 2048-bit VSH on quite modest hardware. In our study we implemented both the original VSH and the cubing variant of VSH. Our results show that both Saarinen's method and our method can find preimages of password hash values very quickly and that our method is faster in many cases. Our method also uses reusable tables that can be used to find the preimages of subsequent hash values faster than with the original method. Kimmo Halunen, Pauli Rikula, Juha Röning |
ARES | 1 |