EDBT 2026 Demo / reviewers in the wild / expert
Andreas Fuchs 0002
dblp:94/285-2
· DBLP profile ↗
18ranked-venue papers
5as first author
6since 2021 · last 2024
0000-0002-0105-003XORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 17 · 5 first-author · 6 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Acceleration of DICE Key Generation using Key CachingabstractDICE is a Trusted Computing standard intended to secure resource-constrained off-the-shelf hardware. It implements a Root of Trust that can be used to construct a Chain of Trust boot system, with symmetric keys representing firmware integrity and device identity. Based on this, asymmetric keys can be generated, but this slows down the boot process significantly as the keys need to be generated on every boot. Asymmetric keys provide multiple advantages when compared to symmetric ones, especially for updateable systems. This prevents the adoption of DICE in fields with strict boot time requirements, for example in the automotive context. Dominik Lorych, Lukas Jäger, Andreas Fuchs 0002 |
ARES | 3 |
| 2023 | Secure and Lightweight Over-the-Air Software Update Distribution for Connected VehiclesabstractConnected vehicles are increasingly threatened by cyberattacks during their long lifecycle. Therefore, timely Over-the-Air (OTA) update processes are becoming a mandatory mitigation mechanism and their security a critical task. In this paper, we present a novel secure OTA update distribution mechanism for connected vehicles that addresses threats and requirements of recent automotive security regulations and standards. We tailor our security concept to the capabilities of a Trusted Platform Module 2.0 (TPM) that we deploy as hardware trust anchor at the vehicle telematics unit and show its benefits and uniqueness regarding security guarantees and functionality in comparison to related work. In our concept, the TPM acts as trusted update distribution point that securely translates the asymmetric backend cryptography to the symmetric in-vehicle cryptography and as update authorization point that coordinates the update installation, e.g., regarding the vehicle state. These concepts are completely enforced inside the shielded location of the TPM, which then represents our minimal hardened trusted computing base on the telematics unit. The solution does not rely on boot time integrity mechanisms and thus even mitigates against advanced runtime and physical hardware cyberattacks. We evaluate our solution using a prototypical implementation within an automotive evaluation platform. Christian Plappert, Andreas Fuchs 0002 |
ACSAC | 2 |
| 2023 | Secure and Lightweight ECU Attestations for Resilient Over-the-Air Updates in Connected VehiclesabstractRecent automotive standards and regulations define requirements for over-the-air (OTA) software updates as a mandatory mitigation mechanism to secure the increasingly connected vehicles against future cyberthreats in a timely manner. Targeting these requirements, we design, implement, and evaluate a novel security concept targeted at securing the in-vehicle processes participating in the OTA update process. It is designed as complementary security measure to further harden already in-place secure update distribution mechanisms and is compliant to recent automotive standards and regulations. Its security is bootstrapped from the secure interlocking of two trusted computing technologies: The Trusted Platform Module 2.0 (TPM 2.0) as overall hardware trust anchor within the vehicle and the Device Identifier Composition Engine (DICE) for securely bootstrapping the resource constrained controllers. Our concept allows the controllers to report their currently running software version to the TPM 2.0 in a secure and lightweight way. Depending on the controllers’ software state, the TPM 2.0 may authorize to transition the vehicle from an update-ready state back to the fully functional drive mode, e.g., after an OTA software update was successfully installed. Christian Plappert, Andreas Fuchs 0002 |
ACSAC | 2 |
| 2023 | Evaluating the applicability of hardware trust anchors for automotive applicationsabstractThe automotive trend towards autonomous driving and advanced connected services increases both complexity of the vehicle internal network and the connections to its environment. This introduced complexity further broadens the vehicle cyberattack surface. As mitigation strategy, state-of-the-art security mechanisms utilize so-called hardware trust anchors (HTAs) to protect security-sensitive data and processes in shielded locations that are isolated utilizing hardware security mechanisms. However, there is a variety of different HTAs with different functionality and security guarantees and there is currently no work done that compares and evaluates them against current and emerging automotive requirements. In this work, we evaluate the applicability of various HTAs to secure modern as well as upcoming future automotive applications. For this, we analyze and evaluate HTAs that are already established in the automotive field as well as promising HTAs from other domains. We extend our preliminary work [1] by increasing the range of the analyzed HTAs with solutions that are feasible for the most resource constrained automotive controllers and technologies that become feasible to be utilized by the introduction of high-performance controllers in future automotive architectures. We assess the different HTAs based on the evaluation criteria and in accordance to automotive requirements. Christian Plappert, Dominik Lorych, Michael Eckel, Lukas Jäger, Andreas Fuchs 0002, Ronald Heddergott |
Comput. Secur. | 5 |
| 2022 | Analysis and Evaluation of Hardware Trust Anchors in the Automotive DomainabstractAutomotive architectures get increasingly more complex both regarding internal as well as external connections to offer new services like autonomous driving. This development further broadens the cyberattack surface of modern vehicles. As mitigation mechanism, hardware trust anchors (HTAs) are increasingly integrated into the electronic control units (ECUs) of modern vehicles to shield security-sensitive data like cryptographic keys against a variety of cyberattacks. However, the provided security capabilities differ among the HTAs. There is currently no evaluation of the HTAs that also addresses current and emerging future requirements of the automotive domain. Thus, in this work, we will analyze and evaluate typical automotive HTAs regarding their feasibility to be used in modern and upcoming vehicle architectures. For this we derive comprehensive evaluation criteria from both related work as well as the automotive domain analysis and make an extensive assessment of the HTA properties in accordance to requirements of the automotive domain. Christian Plappert, Andreas Fuchs 0002, Ronald Heddergott |
ARES | 2 |
| 2021 | Secure Role and Rights Management for Automotive Access and Feature ActivationabstractThe trend towards fully autonomous vehicles changes the concept of car ownership drastically. Purchasing a personal car becomes obsolete. Thus, business models related to feature activation are gaining even higher importance for car manufacturers in order to retain their customers. Various recent security incidents demonstrated however that vehicles are a valuable attack goal ranging from illegal access to car features to the theft of the whole vehicles. Christian Plappert, Lukas Jäger, Andreas Fuchs 0002 |
AsiaCCS | 3 |
| 2020 | HIP: HSM-based identities for plug-and-chargeabstractPlug-and-Charge (PnC) standards such as ISO 15118 enable Electric Vehicle (EV) authentication against Charge Points (CPs) without driver intervention. Credentials are stored in the vehicle itself making methods using RFID cards obsolete. However, credentials are generated in service provider backend systems and provisioned via the Internet and not in a secure Hardware Security Module (HSM) within the vehicle. In this paper, we propose HIP, a backwards compatible protocol extension for ISO 15118 where keys are generated and stored in a Trusted Platform Module (TPM) within the vehicle. Our implementation and evaluation show that our solution is feasible and is a viable option for future editions of ISO 15118. Andreas Fuchs 0002, Dustin Kern, Christoph Krauß, Maria Zhdanova |
ARES | 1 |
| 2020 | Securing Electric Vehicle Charging Systems Through Component Binding
Andreas Fuchs 0002, Dustin Kern, Christoph Krauß, Maria Zhdanova |
SAFECOMP | 1 |
| 2020 | Secure Attestation of Virtualized Environments
Michael Eckel, Andreas Fuchs 0002, Jürgen Repp, Markus Springer |
SEC | 2 |
| 2019 | Security Requirements Engineering in Safety-Critical Railway Signalling NetworksabstractSecuring a safety-critical system is a challenging task, because safety requirements have to be considered alongside security controls. We report on our experience to develop a security architecture for railway signalling systems starting from the bare safety-critical system that requires protection. We use a threat-based approach to determine security risk acceptance criteria and derive security requirements. We discuss the executed process and make suggestions for improvements. Based on the security requirements, we develop a security architecture. The architecture is based on a hardware platform that provides the resources required for safety as well as security applications and is able to run these applications of mixed-criticality (safety-critical applications and other applications run on the same device). To achieve this, we apply the MILS approach, a separation-based high-assurance security architecture to simplify the safety case and security case of our approach. We describe the assurance requirements of the separation kernel subcomponent, which represents the key component of the MILS architecture. We further discuss the security measures of our architecture that are included to protect the safety-critical application from cyberattacks. Markus Heinrich, Tsvetoslava Vateva-Gurova, Tolga Arul, Stefan Katzenbeisser 0001, Neeraj Suri, Henk Birkholz, Andreas Fuchs 0002, Christoph Krauß, Maria Zhdanova, Don Kuzhiyelil, Sergey Tverdyshev, Christian Schlehuber |
Secur. Commun. Networks | 7 |
| 2017 | Rolling DICE: Lightweight Remote Attestation for COTS IoT HardwareabstractThe specification Device Identity Composition Engine (DICE) provides a novel basis for remote attestations specifically suitable in the IoT context. Its purpose is to provide means for remote attestations to devices that are too size-, cost-, energy- or otherwise constrained to have Trusted Platform Module attached. Lukas Jäger, Richard Petri 0001, Andreas Fuchs 0002 |
ARES | 3 |
| 2017 | Runtime Firmware Product Lines Using TPM2.0
Andreas Fuchs 0002, Christoph Krauß, Jürgen Repp |
SEC | 1 |
| 2016 | Advanced Remote Firmware Upgrades Using TPM 2.0
Andreas Fuchs 0002, Christoph Krauß, Jürgen Repp |
SEC | 1 |
| 2015 | On the Secure Distribution of Vendor-Specific Keys in Deployment Scenarios
Nicolai Kuntze, Andreas Fuchs 0002, Carsten Rudolph |
SEC | 2 |
| 2014 | Discovering Secure Service CompositionsabstractS.242-253 Luca Pino, George Spanoudakis, Andreas Fuchs 0002, Sigrid Gürgens |
CLOSER | 3 |
| 2010 | Authentic Refinement of Semantically Enhanced Policies in Pervasive Systems
Julian Schütte, Nicolai Kuntze, Andreas Fuchs 0002, Atta Badii |
SEC | 3 |
| 2010 | Trust in Peer-to-Peer Content Distribution Protocols
Nicolai Kuntze, Carsten Rudolph, Andreas Fuchs 0002 |
WISTP | 3 |
| 2009 | On the Security Validation of Integrated Security Solutions
Andreas Fuchs 0002, Sigrid Gürgens, Carsten Rudolph |
SEC | 1 |