Bart Preneel

dblp:p/BartPreneel · DBLP profile ↗
← Back
283ranked-venue papers
27as first author
42since 2021 · last 2026
0000-0003-2005-9651ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 214 · 23 first-author · 33 since 2021Systems, architecture and hardware · 21 · 1 since 2021Computer networks · 12 · 1 first-author · 1 since 2021Theory of computation · 9 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 8Applied, interdisciplinary, general and emerging computing · 6 · 2 first-author · 1 since 2021Software engineering, systems software and programming languages · 5Databases, data management, data science and information retrieval · 3Human-computer interaction and ubiquitous computing · 2
YearPublicationVenuePosition
2026 Permutation-Based Hash from Non-Idealized Assumptions: Adding Feed-Forward to Sponge
Chun Guo 0002, Kai Hu 0001, Shuntian Jiang, Yanhong Fan 0001, Bart Preneel
CRYPTO (6)6
2026 CARPOOL: Secure And Reliable Proof of Location
abstract
Multiple authentication solutions are widely deployed, such as OTP/TOTP/HOTP codes, hardware tokens, PINs, or biometrics. However, in practice, one sometimes needs to authenticate not only the user but also their location. The current state-of-the-art secure localisation schemes are either unreliable or insecure, or require additional hardware to reliably prove the user's location. This paper proposes CARPOOL, a novel, secure, and reliable approach to affirm the location of the user by solely relying on location-bounded interactions with commercial off-the-shelf devices. Our solution does not require any additional hardware, leverages devices already present in a given environment, and can be integrated effortlessly with existing security components, such as identity and access control systems. To demonstrate the feasibility of our work and to show that it can be deployed in a realistic closed environment setting, we implemented a proof of concept realisation of CARPOOL on an Android phone and multiple Raspberry Pi boards and integrated CARPOOL with Amazon Web Services (AWS) Cognito.
Sayon Duttagupta, Dave Singelée, Xavier Carpent, Takahito Yoshizawa, Seyed Farhad Aghili, Aysajan Abidin, Bart Preneel
SACMAT7
2026 One Tap to Hijack Them All: A Security Analysis of the Google Fast Pair Protocol
abstract
Google's Fast Pair Service (GFPS) extends Bluetooth pairing with one-tap setup and account synchronisation. This paper presents the first comprehensive security analysis of GFPS. By examining 25 commercial accessories from 16 vendors across 17 unique Bluetooth chipsets, we uncover systemic enforcement failures of the specification's core security requirements. Moreover, we show that the security failures we have identified in the pairing protocol can be further cascaded, amplifying their impact across the device ecosystem. Although GFPS and Google's Find Hub network are often treated as distinct services within the broader Google ecosystem, we show that failures in one can produce severe consequences in the other. We demonstrate WhisperPair, a family of practical attacks that enables unauthorised pairing, silent hijacking of audio devices, and covert account binding that registers a victim's accessory to an attacker's account, thereby enabling persistent location tracking and stalking via Google Find Hub. These vulnerabilities are not isolated incidents but symptoms of systemic, ecosystem-wide gaps in implementation, validation, and certification. Our analysis exposes that the source of these flaws lies in GFPS's reliance on fallible, application-layer state checks rather than on cryptographic enforcement, allowing them to propagate across vendors to the end users. To address the root cause, we propose IntentPair, a lightweight protocol modification that cryptographically binds the user's pairing intent into the key schedule, eliminating the vulnerability by design. Our findings show how a small usability “add-on” can introduce large-scale security and privacy risks for hundreds of millions of users.
Sayon Duttagupta, Seppe Wyns, Nikola Antonijevic, Dave Singelée, Bart Preneel
SP5
2026 Certificate revocation - search for a way forward
abstract
Revocation of digital certificates represents a series of improvements by IETF in order to standardize a complete and effective solution. This applies to the context of Internet web sites in which web servers and browsers use digital certificates to establish Transport Layer Security (TLS). Despite IETF’s effort over the years to establish a reliable revocation mechanism, including Certificate Revocation List (CRL), Online Certificate Status Protocol (OCSP) and its variants, various technical issues hinder complete resolution of the revocation problem. At the same time, all major browser vendors implement their own proprietary solutions to address the revocation problem. As a result, revocation solutions are fragmented, incomplete, and ineffective, and the level of real-world acceptance of standardized solutions is limited. To address this situation, in 2020, IETF has introduced short-term certificate concept to avoid revocation altogether. It is called Support for Short-Term, Automatically Renewed (STAR) which recommends a validity period of 4 days. To measure the level of adoption of this new approach in the Internet, we collected and analyzed web server certificates from 1 million websites; the result of our extensive analysis indicates that this scheme has not gained traction in reality. In fact, we found no implementation of a 4-day validity period out of more than 1.5 million server certificates that we collected. This situation indicates that the latest IETF effort to promote short-term certificates has not materialized, with no clear alternative solution in sight to resolve the revocation issue. We present our insights into the reasons for this absence of traction in reality and present our view of a possible way forward.
Takahito Yoshizawa, Himanshu Agarwal, Dave Singelée, Bart Preneel
Comput. Secur.4
2025 CarDS - Controller Area Network and Automotive Ethernet Realistic Data Set
abstract
Intrusion Detection Systems (IDSs) serve as a crucial defense mechanism against cyberattacks targeting the In-Vehicle Network (IVN) of modern, interconnected vehicles. To develop and test new IDS approaches, researchers require realistic IVN data featuring real attacks on moving vehicles. To this end, this paper presents Controller Area Network and Automotive Ethernet Realistic Data Set (CarDS), a novel dataset targeting both the Controller Area Network (CAN) and Automotive Ethernet (AE) traffic of a modern, multi-domain and multi-protocol IVN. Existing datasets are often simulated or limited to basic IVN architectures consisting of only a single CAN bus. Additionally, there are no realistic datasets for AE, despite its growing importance in high-speed in-vehicle communication. CarDS addresses these limitations by providing a labeled, time-synchronized dataset of CAN and AE traces that includes both comprehensive benign profiles and sophisticated attacks. Our traces are captured from an electric vehicle from 2020 featuring a domain-oriented architecture comprising 10 internal CAN buses and 6 AE buses. Specifically, our dataset covers 9h 07m 09s of real IVN data and features 397,383,125 CAN and 180,604,377 AE messages distributed over different scenarios in 258 traces.
Wouter Hellemans, Jannis Hamborg, Timm Lauser, Md Masoom Rabbani, Bart Preneel, Christoph Krauß, Nele Mentens
ACSAC5
2025 Bitcoin Under Volatile Block Rewards: How Mempool Statistics Can Influence Bitcoin Mining
abstract
The security of Bitcoin protocols is deeply dependent on the incentives provided to miners, which come from a combination of block rewards and transaction fees. As Bitcoin experiences more halving events, the protocol reward converges to zero, making transaction fees the primary source of miner rewards. This shift in Bitcoin's incentivization mechanism, which introduces volatility into block rewards, leads to the emergence of new security threats or intensifies existing ones. Previous security analyses of Bitcoin have either considered a fixed block reward model or a highly simplified volatile model, overlooking the complexities of Bitcoin's mempool behavior.
Roozbeh Sarenche, Alireza Aghabagherloo, Svetla Nikova, Bart Preneel
CCS4
2025 SPARK: Secure Privacy-Preserving Anonymous Swarm Attestation for In-Vehicle Networks
abstract
In recent years, vehicles have evolved into cyberphysical autonomous systems that rely on sensor data from various sources within the vehicle. With the emergence of Vehicle-to-Everything (V2X) technology, the scope of the collaborative functionality in vehicles is now expanding to the inter-vehicular level. To support these modern capabilities, the complexity of the Electronic Control Units (ECUs) and the In-Vehicle Network (IVN) architecture is rapidly increasing. As a result, IVNs are now swarms of devices that communicate safety-critical data. Unfortunately, current vehicular networks lack security, opening the path to numerous cyberattacks. A typical solution for verifying the integrity of multiple devices is swarm attestation. However, in a typical IVN setting, only the Original Equipment Manufacturer (OEM) has access to the legitimate configuration of the ECUs and does not want to disclose this information due to intellectual property and security concerns. Therefore, state- of-the-art swarm attestation schemes, which do not provide privacy guarantees, are unsuitable for IVNs.This paper proposes Secure Privacy Preserving Anonymous Swarm Attestation for In-Vehicle Networks (SPARK), which builds upon a novel group signature scheme to enable privacy-preserving, anonymous, and traceable swarm attestation of IVNs. We validate SPARK through a proof-of-concept implementation using a standardized hardware Trusted Platform Module (TPM 2.0) and representative hardware platforms. The results demonstrate the real-world applicability of SPARK.
Wouter Hellemans, Nada El Kassem, Md Masoom Rabbani, Edlira Dushku, Liqun Chen 0002, An Braeken, Bart Preneel, Nele Mentens
EuroS&P7
2025 Commitment Attacks on Ethereum's Reward Mechanism
abstract
Validators in permissionless, large-scale blockchains, such as Ethereum, are typically payoff-maximizing, rational actors. Ethereum relies on in-protocol incentives, like rewards for correct and timely votes, to induce honest behavior and secure the blockchain. However, external incentives, such as the block proposer’s opportunity to capture maximal extractable value (MEV), may tempt validators to deviate from honest protocol participation.We show a series of commitment attacks on LMD GHOST, a core part of Ethereum’s consensus mechanism. We demonstrate how a single adversarial block proposer can orchestrate long-range chain reorganizations by manipulating Ethereum’s reward system for timely votes. These attacks disrupt the intended balance of power between proposers and voters: by leveraging credible threats, the adversarial proposer can coerce voters from previous slots into supporting blocks that conflict with the honest chain, enabling a chain reorganization.In response, we introduce a novel reward mechanism that restores the voters’ role as a check against proposer power. Our proposed mitigation is fairer and more decentralized – not only in the context of these attacks – but also practical for implementation in Ethereum.
Roozbeh Sarenche, Ertem Nusret Tas, Barnabé Monnot, Caspar Schwarz-Schilling, Bart Preneel
EuroS&P5
2025 CovFUZZ: Coverage-based fuzzer for 4G&5G protocols
abstract
4G and 5G represent the current cellular communication standards utilized daily by billions of users for various applications. Consequently, ensuring the security of 4G and 5G network implementations is critically important. This paper introduces an automated fuzzing framework designed to test the security of 4G and 5G Attach procedure implementations. Our framework provides a comprehensive solution for uplink and downlink fuzzing in 4G, as well as downlink fuzzing in 5G, while supporting fuzzing on all layers except the physical layer. To guide the fuzzing process, we introduce a novel algorithm that assigns probabilities to packet fields and adjusts these probabilities based on coverage information from the device-under-test (DUT). For cases where coverage information from the DUT is unavailable, we propose a novel methodology to estimate it. When evaluating our framework, we first run the random fuzzing experiments, where the mutation probabilities are fixed throughout the fuzzing, and give an insight into how those probabilities should be chosen to optimize the Random fuzzer to achieve the best coverage. Next, we evaluate the efficiency of the proposed coverage-based algorithms by fuzzing open-source 4G stack (srsRAN) instances and show that the fuzzer guided by our algorithm outperforms the optimized Random fuzzer in terms of DUT’s code coverage. In addition, we run fuzzing tests on 13 commercial off-the-shelf (COTS) devices. In total, we discovered vulnerabilities in 10 COTS devices and all of the srsRAN 4G instances.
Ilja Siros, Dave Singelée, Bart Preneel
EuroS&P3
2025 Mining Power Destruction Attacks in the Presence of Petty-Compliant Mining Pools
Roozbeh Sarenche, Svetla Nikova, Bart Preneel
FC (2)3
2025 Exploring Adversarial Attacks on the MaSTer Truncation Protocol
abstract
At CANS 2024, Zbudila et al. presented MaSTer, a maliciously secure multi-party computation protocol for truncation.It allows adversaries to manipulate outputs with a bounded additive error while avoiding detection with a certain probability.In this work, we analyse the broader implications of adversarial exploitation in probabilistic truncation protocols, specifically in relation to MaSTer.We propose three attack strategies aimed at inducing misclassification in deep neural network (DNN) inference.Our empirical evaluation across multiple datasets demonstrates that while adversarial influence remains negligible under realistic constraints, certain configurations and network architectures exhibit increased vulnerability.By improving the understanding of the risks associated with probabilistic truncation protocols in privacy-preserving machine learning, our work demonstrates that the MaSTer protocol is robust in realistic settings.
Martin Zbudila, Aysajan Abidin, Bart Preneel
IH&MMSec3
2025 PathSafe: Secure Path Verification in Software-Defined Networks
abstract
Network topology verification in Software-Defined Networks (SDN) poses a significant challenge, as vulnerabilities can allow attackers to deceive the controller and manipulate the data plane into incorrect topologies, thereby endangering the entire network's security. Current solutions fail to guarantee both security and efficiency in the verification process, often resulting in damaging user traffic. With the aim of solving joint objectives, in this paper, we introduce PathSafe, a novel tool constructed on top of the existing controller frameworks designed for secure path verification in SDN environments. It enables the verification of all available paths between two points in the network and ensures a secure process. Our approach requires a data plane component for real-time packet monitoring at line speed and a control plane verification step. Our research demonstrates that PathSafe effectively mitigates security risks in compromised switches and host scenarios. Alongside a theoretical exploration of this challenge, we present a proof of concept implemented in P4, a common language for programmable data planes. Results obtained in Mininet underscore the practical applicability of PathSafe that, compared to alternatives, reduces overhead in the verification process while maintaining a limited execution time.
Doriana Monaco, Nikola Antonijevic, Sayon Duttagupta, Dave Singelée, Alessio Sacco, Eduard Marin, Bart Preneel
NOMS7
2025 ZeroTouch: Reinforcing RSS for Secure Geofencing
abstract
Geofencing, the virtual demarcation of physical spaces, is widely used for managing the localisation of Internet of Things (IoT) devices. However, traditional localisation techniques face security challenges indoors due to signal interference and susceptibility to spoofing, often requiring extensive calibration or extra hardware, limiting scalability. In this work, we propose ZeroTouch, a machine learning-based system that leverages Received Signal Strength (RSS) measurements from multiple receivers to improve the security of geofencing without introducing additional deployment overhead. While RSS-based localisation is known to have inherent security limitations, we show that by aggregating RSS readings from multiple anchor points and detecting anomalies using an autoencoder model, ZeroTouch provides a practical and automated mechanism for verifying whether a device is inside or outside a defined boundary. Rather than serving as a standalone security mechanism, ZeroTouch enhances existing authentication frameworks by adding an additional zero-touch security layer that operates passively in the background. ZeroTouch eliminates manual calibration, removes the human-in-the-loop element, and simplifies deployment. We evaluate our solution in a realistic simulated environment and demonstrate that it achieves high accuracy in distinguishing between in-room and out-of-room devices, even in strong adversarial settings.
Nikola Antonijevic, Sayon Duttagupta, Dave Singelée, Enrique Argones-Rúa, Bart Preneel
SACMAT5
2025 Selfish Mining Time-Averaged Analysis in Bitcoin: Is Orphan Reporting an Effective Countermeasure?
abstract
A Bitcoin miner who owns a sufficient amount of mining power can perform selfish mining to increase its relative revenue. Studies have demonstrated that the time-averaged profit of a selfish miner starts to rise once the mining difficulty level gets adjusted in favor of the attacker. Selfish mining profitability lies in the fact that orphan blocks are not incorporated into the current version of Bitcoin’s difficulty adjustment mechanism (DAM). Therefore, it is believed that considering the count of orphan blocks in the DAM can result in complete unprofitability for selfish mining. In this paper, we disprove this belief by providing a formal analysis of the selfish mining time-averaged profit. We present a precise definition of the orphan blocks that can be incorporated into calculating the next epoch’s target and then introduce two modified versions of DAM in which both main-chain blocks and orphan blocks are incorporated. We propose two versions of smart intermittent selfish mining, where the first one dominates the normal intermittent selfish mining, and the second one results in selfish mining profitability under the modified DAMs. Moreover, we present the orphan exclusion attack with the help of which the attacker can stop honest miners from reporting the orphan blocks. Using combinatorial tools, we analyze the profitability of selfish mining accompanied by the orphan exclusion attack under the modified DAMs. Our results show that even when considering orphan blocks in the DAM, selfish mining can still be profitable. However, the level of profitability under the modified DAMs is significantly lower than that observed under the current version of Bitcoin DAM, suggesting that orphan reporting can be an effective countermeasure against a payoff-maximizing selfish miner.
Roozbeh Sarenche, Ren Zhang 0003, Svetla Nikova, Bart Preneel
IEEE Trans. Inf. Forensics Secur.4
2025 Toward a Real-Time Intrusion Detection System for Modern In-Vehicle Networks
abstract
Over the past decade, it has been demonstrated that the In-Vehicle Network (IVN) of a modern Intelligent Transportation System (ITS) is vulnerable to several cyberattacks. Given the collaborative nature of these systems, detecting (remote) cyberattacks is of utmost importance in ensuring trusted interactions. One key technique that has been explored to detect adversarial presence in IVNs are Intrusion Detection Systems (IDSs). However, many existing solutions focus on legacy architectures or are not practically feasible due to their hardware requirements or inability to operate in real-time. To this end, we propose Modular Reduced Temporal Convolutional Network (MR-TCN), an efficient IDS architecture that can effectively be accelerated on hardware to enable real-time intrusion detection in low-cost embedded platforms. Additionally, we evaluate variants of MR-TCN on a Field-Programmable Gate Array (FPGA) platform across a diverse range of IVN traffic (i.e., CAN CC, CAN FD, and Automotive Ethernet), demonstrating its suitability in real-world applications.
Wouter Hellemans, Laurens Le Jeune, Md Masoom Rabbani, Bart Preneel, Nele Mentens
IEEE Trans. Intell. Transp. Syst.4
2024 Skye: An Expanding PRF based Fast KDF and its Applications
abstract
A Key Derivation Function (KDF) generates a uniform and highly random key-stream from weakly random key material. KDFs are broadly used in various security protocols such as digital signatures and key exchange protocols. HKDF, the most deployed KDF in practice, is based on the extract-then-expand paradigm. It is presently used, among others, in the Signal Protocol for end-to-end encrypted messaging.
Amit Singh Bhati, Antonin Dufka, Elena Andreeva 0001, Arnab Roy 0005, Bart Preneel
AsiaCCS5
2024 MaSTer: Maliciously Secure Truncation for Replicated Secret Sharing Without Pre-processing
Martin Zbudila, Erik Pohle, Aysajan Abidin, Bart Preneel
CANS (1)4
2024 Revisiting Truncated Differential Attack from the Perspective of Equivalent Propagation Equations - Improved Attacks on TWINE and LBlock
Shiqi Hou, Muzhou Li, Kai Hu 0001, Shichang Wang, Bart Preneel
Inscrypt (2)5
2024 The Encryption Debate: An Enduring Struggle
abstract
The ongoing conflict between governments seeking lawful access to encrypted information in the pursuit of national security and crime prevention and the protection of individual privacy has fueled a series of recurring "Crypto Wars." This brief article examines these conflicts, highlighting how the focus of the debate has shifted over the last decades.
Bart Preneel
CODASPY1
2024 Deep Selfish Proposing in Longest-Chain Proof-of-Stake Protocols
Roozbeh Sarenche, Svetla Nikova, Bart Preneel
FC (1)3
2024 Intersections are Not Good for Your Privacy
abstract
Cooperative Awareness Messages (CAM) defined by ETSI Intelligent Transport Systems (ITS) can compromise privacy as a result of its transmission criteria. Because these transmission criteria reflect vehicle's movement, the resulting transmission patterns serve as metadata of vehicles. Passive observations of these patterns can help correlate with a specific vehicle on the road. Furthermore, in some cases, this correlation and identification of a vehicle is independent of the number of vehicles present in the vicinity. Observations from our simulation indicate that the mandatory use and occasional change of pseudonyms is a false premise as they do not protect privacy. In fact, the use of pseudonyms has no bearing with this context. Consequently, the existing CAM transmission criteria pose a tradeoff question between cooperative awareness (and ultimately road safety) and privacy. We propose that ETSI ITS standard to consider our findings and re-evaluate the CAM transmission criteria in Vehicule-to-Everything (V2X) communication.
Takahito Yoshizawa, Bart Preneel
WiMob2
2024 Fast Evaluation of S-Boxes With Garbled Circuits
abstract
Garbling schemes are vital primitives for privacy-preserving protocols and secure two-party computation. This paper presents a projective garbling scheme that assigns$2^{n}$values to wires in a circuit comprising XOR and unary projection gates. A generalization of FreeXOR allows the XOR of wires with$2^{n}$values to be very efficient. We then analyze the performance of our scheme by evaluating substitution-permutation ciphers. Using our proposal, we measure high-speed evaluation of the ciphers with a moderately increased cost in garbling and bandwidth. Theoretical analysis suggests that for evaluating the nine examined ciphers, one can expect a 4- to 70-fold improvement in evaluation performance with, at most, a 4-fold increase in garbling cost and, at most, an 8-fold increase in communication cost compared to the Half-Gates (Zahur, Rosulek and Evans; Eurocrypt’15) and ThreeHalves (Rosulek and Roy; Crypto’21) garbling schemes. In an offline/online setting, such as secure function evaluation as a service, the circuit garbling and communication to the evaluator can proceed in the offline phase. Thus, our scheme offers a fast online phase. Furthermore, we present efficient Boolean circuits for the S-boxes of TWINE and Midori64 ciphers. To our knowledge, our formulas give the smallest number of AND gates for the S-boxes of these two ciphers.
Erik Pohle, Aysajan Abidin, Bart Preneel
IEEE Trans. Inf. Forensics Secur.3
2023 Reusable, Instant and Private Payment Guarantees for Cryptocurrencies
Akash Madhusudan, Mahdi Sedaghat, Samarth Tiwari, Kelong Cong, Bart Preneel
ACISP5
2023 Cryptanalysis of SPEEDY
Qun Liu 0006, Muzhou Li, Bart Preneel
ACISP5
2023 Threshold Structure-Preserving Signatures
Elizabeth C. Crites, Markulf Kohlweiss, Bart Preneel, Mahdi Sedaghat, Daniel Slamanig
ASIACRYPT (2)3
2023 Improved Quantum Circuits for AES: Reducing the Depth and the Number of Qubits
Qun Liu 0006, Bart Preneel
ASIACRYPT (3)2
2023 Let's Go Eevee! A Friendly and Suitable Family of AEAD Modes for IoT-to-Cloud Secure Computation
abstract
IoT devices collect privacy-sensitive data, e.g., in smart grids or in medical devices, and send this data to cloud servers for further processing. In order to ensure confidentiality as well as authenticity of the sensor data in the untrusted cloud environment, we consider a transciphering scenario between embedded IoT devices and multiple cloud servers that perform secure multi-party computation (MPC). Concretely, the IoT devices encrypt their data with a lightweight symmetric cipher and send the ciphertext to the cloud servers. To obtain the secret shares of the cleartext message for further processing, the cloud servers engage in an MPC protocol to decrypt the ciphertext in a distributed manner. This way, the plaintext is never exposed to the individual servers.
Amit Singh Bhati, Erik Pohle, Aysajan Abidin, Elena Andreeva 0001, Bart Preneel
CCS5
2023 Yes we CAN!: Towards bringing security to legacy-restricted Controller Area Networks. A review
abstract
With the demand for advanced functionality such as autonomous driving, the complexity and connectivity of modern vehicles have faced an overwhelming expansion in recent years. Although the numerous interfaces pave the way for a better user experience, recent research has demonstrated that they can also serve as an attack surface for cybercriminals. Therefore, researchers have been challenged to develop a wide variety of security solutions aiming to solve specific issues.
Wouter Hellemans, Md Masoom Rabbani, Bart Preneel, Nele Mentens
CF3
2023 HAT: Secure and Practical Key Establishment for Implantable Medical Devices
abstract
During the last few years, Implantable Medical Devices (IMDs) have evolved considerably. IMD manufacturers are now starting to rely on standard wireless technologies for connectivity. Moreover, there is an evolution towards open systems where the IMD can be remotely monitored or reconfigured through personal commercial-off-the-shelf devices such as smartphones or tablets. Nevertheless, a major problem that still remains unsolved today is the secure establishment of cryptographic keys between the IMD and such personal devices. Researchers have already proposed various solutions, most notably by relying on an additional external device. Unfortunately, these proposed approaches are either insecure, difficult to realise in practice, or are unsuitable for the latest generation of IMDs. Motivated by this, we present HAT, a secure and practical solution to provide fine-grained and dynamic access control for the next generation of IMDs, while offering full control and transparency to the patient. The main idea behind HAT is to shift the access control responsibilities from the IMD to an external device under the user's control, such as a smartphone, acting as the IMD's Key Distribution Center. We show that HAT only introduces minimal energy and memory overhead and formally prove its security using Verifpal.
Sayon Duttagupta, Eduard Marin, Dave Singelée, Bart Preneel
CODASPY4
2023 Arithmetic Circuit Implementations of S-boxes for SKINNY and PHOTON in MPC
Aysajan Abidin, Erik Pohle, Bart Preneel
ESORICS (1)3
2023 Post-Quantum Impacts on V2X Certificates - Already at The End of The Road
abstract
The current certificate definition for vehicle-to-everything (V2X) communication does not support forward compatibility as it does not take migration toward Post Quantum Cryptography (PQC) into account. As a result, introducing PQC-compatible certificates in V2X can result in similar to Distributed Denial-of-Service (DDoS) attack to both legacy and PQC-ready vehicles. This situation will make the deployment of PQC certificates a stalemate situation. In addition, due to the larger public key and signature sizes in PQC algorithms, V2X message size will significantly increase, causing the channel capacity and effective transmission range to decrease. This situation will negatively impact the operation of V2X communication. In this sense, any unnecessary channel usages need to be avoided. We propose to revise the certificate definitions in IEEE 1609 and ETSI Intelligent Transport System (ITS) standards to address and mitigate these issues and pave the way for the migration toward PQC algorithm.
Takahito Yoshizawa, Bart Preneel
VTC2023-Spring2
2022 A White-Box Speck Implementation Using Self-equivalence Encodings
Joachim Vandersmissen, Adrián Ranea, Bart Preneel
ACNS3
2022 Stretching Cube Attacks: Improved Methods to Recover Massive Superpolies
Jiahui He 0002, Kai Hu 0001, Bart Preneel, Meiqin Wang 0001
ASIACRYPT (4)3
2022 T-HIBE: A Novel Key Establishment Solution for Decentralized, Multi-Tenant IoT Systems
abstract
The Internet of Things (IoT) devices has evolved considerably in the past few years and is expected to grow exponentially in the next decade. This exponential growth makes key management in an IoT ecosystem very challenging. Traditional IoT systems are often centralized and grouped into an ecosystem. However, this type of centralized architecture is not always compatible with practical IoT deployments. This paper proposes T-HIBE, a secure key establishment and agreement solution for a decentralized multi-tenant IoT system with multiple security domains. T-HIBE relies on principles of identity-based cryptography for key transport between intra and inter-domain devices while avoiding the inherent key-escrow problem. Furthermore, we have demonstrated our proposed architecture on an ARM Cortex-M4 microcontroller and evaluated the performance to show that T-HIBE does not have a significant energy and performance cost.
Sayon Duttagupta, Dave Singelée, Bart Preneel
CCNC3
2022 Implicit White-Box Implementations: White-Boxing ARX Ciphers
Adrián Ranea, Joachim Vandersmissen, Bart Preneel
CRYPTO (1)3
2022 A Greater GIFT: Strengthening GIFT Against Statistical Cryptanalysis
Ling Sun 0001, Bart Preneel, Wei Wang 0035, Meiqin Wang 0001
EUROCRYPT (3)2
2022 NC-Max: Breaking the Security-Performance Tradeoff in Nakamoto Consensus
Ren Zhang 0003, Dingwei Zhang, Quake Wang, Shichen Wu, Jan Xie, Bart Preneel
NDSS6
2022 On Handling of Certificate Digest in V2X Communication
abstract
We propose a change in the IEEE 1609.2 and ETSI ITS standards that define a certificate distribution mechanism, called inline peer-to-peer certificate distribution (P2PCD). Messages exchanged in V2X messages are secured with digital signatures and digital certificates for the corresponding public keys. This P2PCD mechanism is used in Basic Safety Message (BSM) for the US and Cooperative Awareness Message (CAM) for Europe, and allows vehicles to proactively resolve unknown certificates. The unknown certificate situation occurs as not all messages contain the certificate in order to reduce overhead in these messages. This mechanism appears to be beneficial to minimize delay in verifying the authenticity and integrity of received messages. We evaluated its usefulness by conducting a simulation to recreate real-world highway traffic flow. The result indicates that, for high-way traffic, the benefit of this mechanism is negligble. At the same time, it increases unnecessary processing burden in vehicles. Based on our observation, we propose to update the IEEE 1609.2 and ETSI ITS standards in such a way that this mechanism should be restricted to traffic environments where it brings benefits.
Takahito Yoshizawa, Bart Preneel
WiMob2
2022 HERMES: Scalable, Secure, and Privacy-Enhancing Vehicular Sharing-Access System
abstract
We propose HERMES, a scalable, secure, and privacy-enhancing system for users to share and access vehicles. HERMES securely outsources operations of vehicle access token (AT) generation to a set of untrusted servers. It builds on an earlier proposal, namely, SePCAR, and extends the system design for improved efficiency and scalability. To cater to system and user needs for secure and private computations, HERMES utilizes and combines several cryptographic primitives with secure multiparty computation (MPC) efficiently. It conceals secret keys of vehicles and transaction details from the servers, including vehicle booking details, AT information, and user and vehicle identities. It also provides user accountability in case of disputes. Besides, we provide semantic security analysis and prove that HERMES meets its security and privacy requirements. Last but not least, we demonstrate that HERMES is efficient and, in contrast to SePCAR, scales to a large number of users and vehicles, making it practical for real-world deployments. We build our evaluations with two different MPC protocols: 1) HtMAC-MiMC and 2) CBC-MAC-AES. Our results demonstrate that HERMES is in the range of milliseconds for generating an AT, whether it operates for a single-vehicle owner or a large rental-company branch with over 1000 vehicles; handling 546 and 84 AT generations per second, respectively. As a result, HERMES is an order of magnitude faster compared to SePCAR. Specifically, it delivers 696 (with HtMAC-MiMC) and 42 (with CBC-MAC-AES) more ATs compared to in SePCAR for a single-vehicle owner AT generation. Furthermore, we show that HERMES is practical on the vehicle side, too, as AT operations performed on a prototype vehicle on-board unit take only$\approx 62 $ms.
Iraklis Symeonidis, Dragos Rotaru, Mustafa A. Mustafa, Bart Mennink, Bart Preneel, Panagiotis Papadimitratos
IEEE Internet Things J.5
2021 Categorization of Faulty Nonce Misuse Resistant Message Authentication
Yu Long Chen, Bart Mennink, Bart Preneel
ASIACRYPT (3)3
2021 Cross-Domain Attribute-Based Access Control Encryption
Mahdi Sedaghat, Bart Preneel
CANS2
2021 Systematic Security Analysis of Stream Encryption With Key Erasure
abstract
We consider a generalized construction of stream ciphers with forward security. The design framework is modular: it is built from a so-called layer function that updates the key and (optionally) the nonce and generates a new pseudorandom output stream. We analyze the generalized construction for four different instantiations: two possible layer functions that are in turn instantiated with either a block cipher or a pseudorandom function. We prove that each of these instantiations gives a stream cipher that is pseudorandom and forward secure in the multi-user setting with a very tight bound. A comprehensive analysis shows that the two block cipher based instantiations achieve very similar bounds. For the pseudorandom function based instantiations there is no clear winner: either layer can be beneficial over the other one, depending on the choice of parameters. By instantiating the pseudorandom function with a generic construction such as the sum of permutations, we obtain a highly efficient and competitive stream cipher based on an n-bit block cipher that is secure beyond the$2^{\text {n}/2}$birthday bound.
Yu Long Chen, Atul Luykx, Bart Mennink, Bart Preneel
IEEE Trans. Inf. Theory4
2020 Big Data against Corona: Mass Surveillance or Privacy by Design? Keynote
abstract
Summary form only given, as follows. The complete presentation was not made available for publication as part of the conference proceedings. The corona pandemic is the first major pandemic in times of big data, AI and smart devices. Some nations have demonstrated that these technologies can be deployed successfully at a large scale to support a trace/quarantine/test/isolate strategy in order to contain a pandemic. However, serious concerns have been raised on the privacy implications of some solutions, which makes them incompatible with privacy and human rights that are protected by EU law. This talk surveys these attempts and the related privacy concerns. It will also present the contact tracing solution developed by the DP-3T (Distributed Privacy-Preserving Proximity Tracing) consortium that has been rolled out in more than 20 countries and states, with support of Google and Apple. The talk will discuss the lessons learned from this large-scale deployment in which the principles of privacy-by-design and data minimization have played a central role.
Bart Preneel
AICCSA1
2020 On Self-equivalence Encodings in White-Box Implementations
Adrián Ranea, Bart Preneel
SAC2
2019 SC2Share: Smart Contract for Secure Car Sharing
abstract
This paper presents an efficient solution for the booking and payments functionality of a car sharing system that allows individuals to share their personal, underused cars in a completely decentralized manner, annulling the need of an intermediary. Our solution, named SC2Share, leverages smart contracts and uses them to carry out secure and private car booking and payments. Our experiments on SC2Share on the Ethereum testnet guarantee high security and privacy to its users and confirm that our system is cost-efficient and ready for practical use.
Akash Madhusudan, Iraklis Symeonidis, Mustafa A. Mustafa, Ren Zhang 0003, Bart Preneel
ICISSP5
2019 On the Difficulty of Using Patient's Physiological Signals in Cryptographic Protocols
abstract
With the increasing capabilities of wearable sensors and implantable medical devices, new opportunities arise to diagnose, control and treat several chronic conditions. Unfortunately, these advancements also open new attack vectors, making security an essential requirement for the further adoption of these devices. Researchers have already developed security solutions tailored to their unique requirements and constraints. However, a fundamental yet unsolved problem is how to securely and efficiently establish and manage cryptographic keys. One of the most promising approaches is the use of patient's physiological signals for key establishment.
Eduard Marin, Enrique Argones-Rúa, Dave Singelée, Bart Preneel
SACMAT4
2019 Improved Interpolation Attacks on Cryptographic Primitives of Low Algebraic Degree
Chaoyun Li, Bart Preneel
SAC2
2019 Block-Anti-Circulant Unbalanced Oil and Vinegar
Alan Szepieniec, Bart Preneel
SAC2
2019 Lay Down the Common Metrics: Evaluating Proof-of-Work Consensus Protocols' Security
abstract
Following Bitcoin's Nakamoto Consensus protocol (NC), hundreds of cryptocurrencies utilize proofs of work (PoW) to maintain their ledgers. However, research shows that NC fails to achieve perfect chain quality, allowing malicious miners to alter the public ledger in order to launch several attacks, i.e., selfish mining, double-spending and feather-forking. Some later designs, represented by Ethereum, Bitcoin-NG, DECOR+, Byzcoin and Publish or Perish, aim to solve the problem by raising the chain quality; other designs, represented by Fruitchains, DECOR+ and Subchains, claim to successfully defend against the attacks in the absence of perfect chain quality. As their effectiveness remains self-claimed, the community is divided on whether a secure PoW protocol is possible. In order to resolve this ambiguity and to lay down the foundation of a common body of knowledge, this paper introduces a multi-metric evaluation framework to quantitatively analyze PoW protocols' chain quality and attack resistance. Subsequently we use this framework to evaluate the security of these improved designs through Markov decision processes. We conclude that to date, no PoW protocol achieves ideal chain quality or is resistant against all three attacks. We attribute existing PoW protocols' imperfect chain quality to their unrealistic security assumptions, and their unsatisfactory attack resistance to a dilemma between "rewarding the bad" and "punishing the good". Moreover, our analysis reveals various new protocol-specific attack strategies. Based on our analysis, we propose future directions toward more secure PoW protocols and indicate several common pitfalls in PoW security analyses.
Ren Zhang 0003, Bart Preneel
IEEE Symposium on Security and Privacy2
2018 Securing Wireless Neurostimulators
abstract
Implantable medical devices (IMDs) typically rely on proprietary protocols to wirelessly communicate with external device programmers. In this paper, we fully reverse engineer the proprietary protocol between a device programmer and a widely used commercial neurostimulator from one of the leading IMD manufacturers. For the reverse engineering, we follow a black-box approach and use inexpensive hardware equipment. We document the message format and the protocol state-machine, and show that the transmissions sent over the air are neither encrypted nor authenticated. Furthermore, we conduct several software radio-based attacks that could compromise the safety and privacy of patients, and investigate the feasibility of performing these attacks in real scenarios.
Eduard Marin, Dave Singelée, Bohan Yang 0001, Vladimir Volskiy, Guy A. E. Vandenbosch, Bart Nuttin, Bart Preneel
CODASPY7
2018 Optimal Forgeries Against Polynomial-Based MACs and GCM
Atul Luykx, Bart Preneel
EUROCRYPT (1)2
2018 Privacy-preserving Biometric Authentication Model for e-Finance Applications
abstract
Widespread use of biometric architectures implies the need to secure highly sensitive data to respect the privacy rights of the users. In this paper, we discuss the following question: To what extent can biometric designs be characterized as Privacy Enhancing Technologies? The terms of privacy and security for biometric schemes are defined, while current regulations for the protection of biometric information are presented. Additionally, we analyze and compare cryptographic techniques for secure biometric designs. Finally, we introduce a privacy-preserving approach for biometric authentication in mobile electronic financial applications. Our model utilizes the mechanism of pseudonymous biometric identities for secure user registration and authentication. We discuss how the privacy requirements for the processing of biometric data can be met in our scenario. This work attempts to contribute to the development of privacy-by-design biometric technologies.
Christina-Angeliki Toli, Bart Preneel
ICISSP2
2018 Public Key Compression for Constrained Linear Signature Schemes
Ward Beullens, Bart Preneel, Alan Szepieniec
SAC2
2018 Collateral damage of Facebook third-party applications: a comprehensive study
Iraklis Symeonidis, Gergely Biczók, Fatemeh Shirazi, Cristina Pérez-Solà, Jessica Schroers, Bart Preneel
Comput. Secur.6
2018 Private Mobile Pay-TV From Priced Oblivious Transfer
abstract
In pay-TV, a service provider offers TV programs and channels to users. To ensure that only authorized users gain access, conditional access systems (CAS) have been proposed. In existing CAS, users disclose to the service provider the TV programs and channels they purchase. We propose a pay-per-view and a pay-per-channel CAS that protect users' privacy. Our pay-per-view CAS employs priced oblivious transfer (POT) to allow a user to purchase TV programs without disclosing which programs were bought to the service provider. In our pay-per-channel CAS, POT is employed together with broadcast attribute-based encryption to achieve low storage overhead, collusion resistance, efficient revocation, and broadcast efficiency. We propose a new POT scheme and show its feasibility by implementing and testing our CAS on a representative mobile platform.
Wouter Biesmans, Josep Balasch, Alfredo Rial, Bart Preneel, Ingrid Verbauwhede
IEEE Trans. Inf. Forensics Secur.4
2017 A Privacy-Preserving Device Tracking System Using a Low-Power Wide-Area Network
Tomer Ashur, Jeroen Delvaux, Sanghan Lee, Pieter Maene, Eduard Marin, Svetla Nikova, Oscar Reparaz, Vladimir Rozic, Dave Singelée, Bohan Yang 0001, Bart Preneel
CANS11
2017 SCM: Secure Code Memory Architecture
abstract
An increasing number of applications implemented on a SoC (System-on-chip) require security features. This work addresses the issue of protecting the integrity of code and read-only data that is stored in memory. To this end, we propose a new architecture called SCM, which works as a standalone IP core in a SoC. To the best of our knowledge, there exists no architectural elements similar to SCM that offer the same strict security guarantees while, at the same time, not requiring any modifications to other IP cores in its SoC design. In addition, SCM has the flexibility to select the parts of the software to be protected, which eases the integration of our solution with existing software. The evaluation of SCM was done on the Zynq platform which features an ARM processor and an FPGA. The design was evaluated by executing a number of different benchmarks from memory protected by SCM, and we found that it introduces minimal overhead to the system.
Ruan de Clercq, Ronald De Keulenaer, Pieter Maene, Bart Preneel, Bjorn De Sutter, Ingrid Verbauwhede
AsiaCCS4
2017 On the Necessity of a Prescribed Block Validity Consensus: Analyzing Bitcoin Unlimited Mining Protocol
abstract
Bitcoin has not only attracted many users but also been considered as a technical breakthrough by academia. However, the expanding potential of Bitcoin is largely untapped due to its limited throughput. The Bitcoin community is now facing its biggest crisis in history as the community splits on how to increase the throughput. Among various proposals, Bitcoin Unlimited recently became the most popular candidate, as it allows miners to collectively decide the block size limit according to the real network capacity. However, the security of BU is heatedly debated and no consensus has been reached as the issue is discussed in different miner incentive models. In this paper, we systematically evaluate BU's security with three incentive models via testing the two major arguments of BU supporters: the block validity consensus is not necessary for BU's security; such consensus would emerge in BU out of economic incentives. Our results invalidate both arguments and therefore disprove BU's security claims. Our paper further contributes to the field by addressing the necessity of a prescribed block validity consensus for cryptocurrencies.
Ren Zhang 0003, Bart Preneel
CoNEXT2
2017 Publish or Perish: A Backward-Compatible Defense Against Selfish Mining in Bitcoin
Ren Zhang 0003, Bart Preneel
CT-RSA2
2017 SePCAR: A Secure and Privacy-Enhancing Protocol for Car Access Provision
Iraklis Symeonidis, Abdelrahaman Aly, Mustafa A. Mustafa, Bart Mennink, Siemen Dhooghe, Bart Preneel
ESORICS (2)6
2017 The Future of Information Security
Bart Preneel
ICISSP1
2017 MQ Signatures for PKI
Alan Szepieniec, Ward Beullens, Bart Preneel
PQCrypto3
2017 Physical-layer fingerprinting of LoRa devices using supervised and zero-shot learning
abstract
Physical-layer fingerprinting investigates how features extracted from radio signals can be used to uniquely identify devices. This paper proposes and analyses a novel methodology to fingerprint LoRa devices, which is inspired by recent advances in supervised machine learning and zero-shot image classification. Contrary to previous works, our methodology does not rely on localized and low-dimensional features, such as those extracted from the signal transient or preamble, but uses the entire signal. We have performed our experiments using 22 LoRa devices with 3 different chipsets. Our results show that identical chipsets can be distinguished with 59% to 99% accuracy per symbol, whereas chipsets from different vendors can be fingerprinted with 99% to 100% accuracy per symbol. The fingerprinting can be performed using only inexpensive commercial off-the-shelf software defined radios, and a low sample rate of 1 Msps. Finally, we release all datasets and code pertaining to these experiments to the public domain.
Pieter Robyns, Eduard Marin, Wim Lamotte, Peter Quax, Dave Singelée, Bart Preneel
WISEC6
2017 Sancus 2.0: A Low-Cost Security Architecture for IoT Devices
abstract
The Sancus security architecture for networked embedded devices was proposed in 2013 at the USENIX Security conference. It supports remote (even third-party) software installation on devices while maintaining strong security guarantees. More specifically, Sancus can remotely attest to a software provider that a specific software module is running uncompromised and can provide a secure communication channel between software modules and software providers. Software modules can securely maintain local state and can securely interact with other software modules that they choose to trust. Over the past three years, significant experience has been gained with applications of Sancus, and several extensions of the architecture have been investigated—both by the original designers as well as by independent researchers. Informed by these additional research results, this journal version of the Sancus paper describes an improved design and implementation, supporting additional security guarantees (such as confidential deployment) and a more efficient cryptographic core. We describe the design of Sancus 2.0 (without relying on any prior knowledge of Sancus) and develop and evaluate a prototype FPGA implementation. The prototype extends an MSP430 processor with hardware support for the memory access control and cryptographic functionality required to run Sancus. We report on our experience using Sancus in a variety of application scenarios and discuss some important avenues of ongoing and future work.
Job Noorman, Jo Van Bulck, Jan Tobias Mühlberg, Frank Piessens, Pieter Maene, Bart Preneel, Ingrid Verbauwhede, Johannes Götzfried, Tilo Müller, Felix C. Freiling
ACM Trans. Priv. Secur.6
2016 On the (in)security of the latest generation implantable cardiac defibrillators and how to secure them
Eduard Marin, Dave Singelée, Flavio D. Garcia, Tom Chothia, Rik Willems, Bart Preneel
ACSAC6
2016 An Efficient Entity Authentication Protocol with Enhanced Security and Privacy Properties
Aysajan Abidin, Enrique Argones-Rúa, Bart Preneel
CANS3
2016 A Privacy-Preserving Model for Biometric Fusion
Christina-Angeliki Toli, Abdelrahaman Aly, Bart Preneel
CANS3
2016 On the Feasibility of Cryptography for a Wireless Insulin Pump System
abstract
This paper analyses the security and privacy properties of a widely used insulin pump and its peripherals. We eavesdrop the wireless channel using Commercial Off-The-Shelf (COTS) software-based radios to intercept the messages sent between these devices; fully reverse-engineer the wireless communication protocol using a black-box approach; and document the message format and the protocol state-machine in use. The upshot is that no standard cryptographic mechanisms are applied and hence the system is shown to be completely vulnerable to replay and message injection attacks. Furthermore, sensitive patient health-related information is sent unencrypted over the wireless channel.
Eduard Marin, Dave Singelée, Bohan Yang 0001, Ingrid Verbauwhede, Bart Preneel
CODASPY5
2016 SOFIA: Software and control flow integrity architecture
Ruan de Clercq, Ronald De Keulenaer, Bart Coppens 0001, Bohan Yang 0001, Pieter Maene, Koen De Bosschere, Bart Preneel, Bjorn De Sutter, Ingrid Verbauwhede
DATE7
2016 On the Influence of Message Length in PMAC's Security Bounds
Atul Luykx, Bart Preneel, Alan Szepieniec, Kan Yasuda
EUROCRYPT (1)2
2016 A MAC Mode for Lightweight Block Ciphers
Atul Luykx, Bart Preneel, Elmar Tischhauser, Kan Yasuda
FSE2
2016 Collateral Damage of Online Social Network Applications
abstract
peer reviewed
Iraklis Symeonidis, Pagona Tsormpatzoudi, Bart Preneel
ICISSP3
2016 Binary decision diagram to design balanced secure logic styles
abstract
Embedded implementations of cryptographic algorithms require countermeasures against side-channel attacks (SCAs), that exploit physical variables measured during the computation. These countermeasures increase cost, power consumption and latency of the device. One class of countermeasures, hiding, consists of a balanced circuit style, including balancing of the capacitances and delays; it requires full connection to avoid memory effect that is an effect caused by repeatedly recharged energy after being only partially discharged at the internal parasitic capacitance. This paper proposes binary decision diagrams (BDDs) to derive complex pull-down networks that fulfill all these requirements while being compact at the same time; it uses sense amplifier-based logic (SABL) to obtain well-balanced pre-charge circuits. An attack based on mutual information analysis (MIA) is applied to the AES S-boxes implemented in our novel secure logic style. After the evaluation at pre-layout SPICE level, the balanced circuit with BDD leaks less information than comparable logic styles, even though the implementation area is reduced by 40.6%, the power consumption up to 46.1% and the delay by 35.2% compared to the classic SABL approach.
Seokhie Hong, Bart Preneel, Ingrid Verbauwhede
IOLTS3
2016 Extension Field Cancellation: A New Central Trapdoor for Multivariate Quadratic Systems
Alan Szepieniec, Jintai Ding, Bart Preneel
PQCrypto3
2016 Collateral Damage of Facebook Apps: Friends, Providers, and Privacy Interdependence
Iraklis Symeonidis, Fatemeh Shirazi, Gergely Biczók, Cristina Pérez-Solà, Bart Preneel
SEC5
2016 Flip Feng Shui: Hammering a Needle in the Software Stack
Kaveh Razavi, Ben Gras, Erik Bosman, Bart Preneel, Cristiano Giuffrida, Herbert Bos
USENIX Security Symposium4
2016 An Implementation of a High Assurance Smart Meter Using Protected Module Architectures
Jan Tobias Mühlberg, Sara Cleemput, Mustafa A. Mustafa, Jo Van Bulck, Bart Preneel, Frank Piessens
WISTP5
2016 Practical identity-based private sharing for online social networks
Filipe Beato, Stijn Meul, Bart Preneel
Comput. Commun.3
2016 On the choice of the appropriate AES data encryption method for ZigBee nodes
abstract
Abstract This paper describes the experiments that have been conducted to determine the optimal implementation method for AES (Advanced Encryption Standard) data encryption in a ZigBee network in terms of energy consumption. Four possible scenarios have been considered. The first one is a freely available AES‐cryptographic algorithm on the processor which controls the ZigBee nodes. The second also involves the processor but is based on a proprietary, highly optimized algorithm. The other methods are based on hardware implementations. Whereas the third option is based on a cryptographic block, embedded in the ZigBee node controller, the last solution utilizes an AES128‐CBC‐MAC hardware co‐processor embedded on a Spartan 3A FPGA. The ZigBee modules in the network contain an 8‐bit microcontroller which takes care of the ZigBee protocol stack—and the encryption calculations in all but the last case. All approaches are examined and compared. We show that the usage of a microcontroller with an on‐board AES processor is the optimal design choice for a new hardware platform. An optimized software library gives the best results when extending an existing platform. This paper gives developers an idea of the amount of energy they can gain/lose by choosing one of the four solutions. Copyright © 2010 John Wiley & Sons, Ltd.
Geoffrey Ottoy, Tom Hamelinckx, Bart Preneel, Lieven De Strycker, Jean-Pierre Goemaere
Secur. Commun. Networks3
2015 On the XOR of Multiple Random Permutations
Bart Mennink, Bart Preneel
ACNS2
2015 On the Impact of Known-Key Attacks on Hash Functions
Bart Mennink, Bart Preneel
ASIACRYPT (2)2
2015 Post-Snowden Threat Models
abstract
In June 2013 Edward Snowden leaked a large collection of documents that describe the capabilities and technologies of the NSA and its allies. Even to security experts the scale, nature and impact of some of the techniques revealed was surprising. A major consequence is the increased awareness of the public at large of the existence of highly intrusive mass surveillance techniques. There has also been some impact in the business world, including a growing interest in companies that (claim to) develop end-to-end secure solutions. There is no doubt that large nation states and organized crime have carefully studied the techniques and are exploring which ones they can use for their own benefit. But after two years, there is little progress in legal or governance measures to address some of the excesses by increasing accountability. Moreover, the security research community seems to have been slow to respond to the new threat landscape. In this lecture we analyze these threats and speculate how they could be countered.
Bart Preneel
SACMAT1
2015 Forgery and Subkey Recovery on CAESAR Candidate iFeed
Willem Schroé, Bart Mennink, Elena Andreeva 0001, Bart Preneel
SAC4
2015 Open problems in hash function security
Elena Andreeva 0001, Bart Mennink, Bart Preneel
Des. Codes Cryptogr.3
2015 Anonymous Split E-Cash - Toward Mobile Anonymous Payments
abstract
Anonymous E-Cash was first introduced in 1982 as a digital, privacy-preserving alternative to physical cash. A lot of research has since then been devoted to extend and improve its properties, leading to the appearance of multiple schemes. Despite this progress, the practical feasibility of E-Cash systems is still today an open question. Payment tokens are typically portable hardware devices in smart card form, resource constrained due to their size, and therefore not suited to support largely complex protocols such as E-Cash. Migrating to more powerful mobile platforms, for instance, smartphones, seems a natural alternative. However, this implies moving computations from trusted and dedicated execution environments to generic multiapplication platforms, which may result in security vulnerabilities. In this work, we propose a new anonymous E-Cash system to overcome this limitation. Motivated by existing payment schemes based on MTM (Mobile Trusted Module) architectures, we consider at design time a model in which user payment tokens are composed of two modules: an untrusted but powerful execution platform (e.g., smartphone) and a trusted but constrained platform (e.g., secure element). We show how the protocol’s computational complexity can be relaxed by a secure split of computations: nonsensitive operations are delegated to the powerful platform, while sensitive computations are kept in a secure environment. We provide a full construction of our proposed Anonymous Split E-Cash scheme and show that it fully complies with the main properties of an ideal E-Cash system. Finally, we test its performance by implementing it on an Android smartphone equipped with a Java-Card-compatible secure element.
Marijn Scheir, Josep Balasch, Alfredo Rial, Bart Preneel, Ingrid Verbauwhede
ACM Trans. Embed. Comput. Syst.4
2014 Breaking and Fixing Cryptophia's Short Combiner
Bart Mennink, Bart Preneel
CANS2
2014 Censorship-resistant and privacy-preserving distributed web search
abstract
The vast majority of Internet users are relying on centralized search engine providers to conduct their web searches. However, search results can be censored and search queries can be recorded by these providers without the user's knowledge. Distributed web search engines based on peer-to-peer networks have been proposed to mitigate these threats. In this paper we analyze the three most popular real-world distributed web search engines: Faroo, Seeks and Yacy, with respect to their censorship resistance and privacy protection. We show that none of them provides an adequate level of protection against an adversary with modest resources. Recognizing these flaws, we identify security properties a censorship-resistant and privacy-preserving distributed web search engine should provide. We propose two novel defense mechanisms called node density protocol and webpage verification protocol to achieve censorship resistance and show their effectiveness and feasibility with simulations. Finally, we elaborate on how state-of-the-art defense mechanisms achieve privacy protection in distributed web search engines.
Michael Herrmann 0003, Ren Zhang 0003, Kai-Chun Ning, Claudia Díaz, Bart Preneel
P2P5
2014 Chaskey: An Efficient MAC Algorithm for 32-bit Microcontrollers
Nicky Mouha, Bart Mennink, Anthony Van Herrewege, Dai Watanabe, Bart Preneel, Ingrid Verbauwhede
Selected Areas in Cryptography5
2014 Practical privacy-preserving location-sharing based services with aggregate statistics
abstract
Location-sharing-based services (LSBSs) allow users to share their location with their friends in a sporadic manner. In currently deployed LSBSs users must disclose their location to the service provider in order to share it with their friends. This default disclosure of location data introduces privacy risks. We define the security properties that a privacy-preserving LSBS should fulfill and propose two constructions. First, a construction based on identity based broadcast encryption (IBBE) in which the service provider does not learn the user's location, but learns which other users are allowed to receive a location update. Second, a construction based on anonymous IBBE in which the service provider does not learn the latter either. As advantages with respect to previous work, in our schemes the LSBS provider does not need to perform any operations to compute the reply to a location data request, but only needs to forward IBBE ciphertexts to the receivers. We implement both constructions and present a performance analysis that shows their practicality. Furthermore, we extend our schemes such that the service provider, performing some verification work, is able to collect privacy-preserving aggregate statistics on the locations users share with each other.
Michael Herrmann 0003, Alfredo Rial, Claudia Díaz, Bart Preneel
WISEC4
2014 Internal differential collision attacks on the reduced-round Grøstl-0 hash function
Kota Ideguchi, Elmar Tischhauser, Bart Preneel
Des. Codes Cryptogr.3
2014 Proper RFID Privacy: Model and Protocols
abstract
We approach RFID privacy both from modelling and protocol point of view. Our privacy model avoids the drawbacks of several proposed RFID privacy models that either suffer from insufficient generality or put forward unrealistic assumptions regarding the adversary's ability to corrupt tags. Furthermore, our model can handle multiple readers and introduces two new privacy notions to capture the recently discovered insider attackers. We analyse multiple existing RFID protocols, demonstrating the easy applicability of our model, and propose a new wide-forward-insider private RFID authentication protocol. This protocol provides sufficient privacy guarantees for most practical applications and is the most efficient of its kind, it only requires two scalar-EC point multiplications.
Jens Hermans, Roel Peeters, Bart Preneel
IEEE Trans. Mob. Comput.3
2013 FPDetective: dusting the web for fingerprinters
abstract
In the modern web, the browser has emerged as the vehicle of choice, which users are to trust, customize, and use, to access a wealth of information and online services. However, recent studies show that the browser can also be used to invisibly fingerprint the user: a practice that may have serious privacy and security implications.
Gunes Acar, Marc Juarez, Nick Nikiforakis, Claudia Díaz, Seda Gurses, Frank Piessens, Bart Preneel
CCS7
2013 For some eyes only: protecting online information sharing
abstract
End-users have become accustomed to the ease with which online systems allow them to exchange messages, pictures, and other files with colleagues, friends, and family. This con- venience, however, sometimes comes at the expense of hav- ing their data be viewed by a number of unauthorized par- ties, such as hackers, advertisement companies, other users, or governmental agencies. A number of systems have been proposed to protect data shared online; yet these solutions typically just shift trust to another third party server, are platform specific (e.g., work for Facebook only), or fail to hide that confidential communication is taking place. In this paper, we present a novel system that enables users to exchange data over any web-based sharing platform, while both keeping the communicated data confidential and hiding from a casual observer that an exchange of confidential data is taking place. We provide a proof-of-concept implementa- tion of our system in the form of a publicly available Fire- fox plugin, and demonstrate the viability of our approach through a performance evaluation.
Filipe Beato, Iulia Ion, Srdjan Capkun, Bart Preneel, Marc Langheinrich
CODASPY4
2013 Format-compliant encryption techniques for high efficiency video coding
abstract
When middlebox devices should be able to adapt an encrypted video stream in the network without having the decryption key, format-compliant partial encryption schemes should be applied. In this paper, we propose such encryption schemes for the recently standardized High Efficiency Video Coding (HEVC) standard. By encrypting specific syntax elements like the sign of the residual information, the sign of the motion vector (MV) difference, the MV prediction index, and the MV reference index, format compliance and the possibility for adaptation are offered. Scrambling performance gradually increases when shifting from encrypting the motion information to encrypting the residual sign and finally to the combination thereof. Applying all these techniques has a negligible impact on the compression efficiency.
Glenn Van Wallendael, Jan De Cock, Sebastiaan Van Leuven, Andras Boho, Peter Lambert, Bart Preneel, Rik Van de Walle
ICIP6
2013 Two Attacks on a White-Box AES Implementation
Tancrède Lepoint, Matthieu Rivain, Yoni De Mulder, Peter Roelse, Bart Preneel
Selected Areas in Cryptography5
2013 AEGIS: A Fast Authenticated Encryption Algorithm
Hongjun Wu 0001, Bart Preneel
Selected Areas in Cryptography2
2013 The SHA-3 competition: lessons learned
abstract
Cryptographic hash functions play a central role in cryptography: they map arbitrarily large input strings to fixed length output strings. The main applications are to create a short unique identifier to a string, to transform a string with a one-way mapping, and to commit to a string or to confirm its knowledge without revealing it. Additional applications are the mapping of group or field elements to strings, key derivation and the extraction of entropy. The main security requirements are preimage and second preimage resistance, collision resistance and indifferentiability from a random oracle. During the last three decades, more than 200 hash functions designs have been published; many of those have been cryptanalyzed, including widely used schemes such as MD5 and SHA-1. Moreover, there was a lack of theoretical understanding of their constructions; as a consequence, structural flaws were identified in widely used designs. These concerns also undermined to some extent the confidence in the SHA-2 hash functions, that have been designed for long term security. As a consequence, the US National Institute for Standards and Technology has organized an open competition. The competition started in November 2007; after five years of intense design, analysis and debate the Keccak function was announced as the winner in October 2012. The new FIPS standard is expected to be published in 2014. This extended abstract will identify some lessons learned during this competition.
Bart Preneel
SIN1
2013 Sancus: Low-cost Trustworthy Extensible Networked Devices with a Zero-software Trusted Computing Base
Job Noorman, Pieter Agten, Wilfried Daniels, Raoul Strackx, Anthony Van Herrewege, Christophe Huygens, Bart Preneel, Ingrid Verbauwhede, Frank Piessens
USENIX Security Symposium7
2012 Interface Design for Mapping a Variety of RSA Exponentiation Algorithms on a HW/SW Co-design Platform
abstract
When mapping public-key algorithms, such as RSA, onto constrained devices, both efficiency and flexibility are a challenge. Because word lengths are large, minimum 1024 bits, typically a dedicated co-processor is used. On the other hand, flexibility is required, because designers want to support a variety of RSA exponentiation algorithms. Typically the solution is then a hardware/software (HW/SW) co-design platform. In this paper we have chosen this approach: we use an 8051 micro-controller for flexibility and a Montgomery multiplier for efficiency. However, the importance of the interface between HW and SW is often neglected. The main focus of this paper is therefore to propose an interface that supports maximally the flexibility and the efficiency. We use this interface to compare six different exponentiation variants of RSA with and without side-channel attack countermeasures.
Leif Uhsadel, Markus Ullrich, Ingrid Verbauwhede, Bart Preneel
ASAP4
2012 Security implications in Kerberos by the introduction of smart cards
abstract
Public key Kerberos (PKINIT) is a standardized authentication and key establishment protocol which is used by the Windows active directory subsystem. In this paper we show that card-based public key Kerberos is flawed. In particular, access to a user's card enables an adversary to impersonate that user even after the adversary's access to the card is revoked. The attack neither exploits physical properties of the card, nor extracts any of its secrets.
Nikos Mavrogiannopoulos, Andreas Pashalidis, Bart Preneel
AsiaCCS3
2012 A cross-protocol attack on the TLS protocol
abstract
This paper describes a cross-protocol attack on all versions of TLS; it can be seen as an extension of the Wagner and Schneier attack on SSL 3.0. The attack presents valid explicit elliptic curve Diffie-Hellman parameters signed by a server to a client that incorrectly interprets these parameters as valid plain Diffie-Hellman parameters. Our attack enables an adversary to successfully impersonate a server to a random client after obtaining 240 signed elliptic curve keys from the original server. While attacking a specific client is improbable due to the high number of signed keys required during the lifetime of one TLS handshake, it is not completely unrealistic for a setting where the server has high computational power and the attacker contents itself with recovering one out of many session keys. We remark that popular open-source server implementations are not susceptible to this attack, since they typically do not support the explicit curve option. Finally we propose a fix that renders the protocol immune to this family of cross-protocol attacks.
Nikos Mavrogiannopoulos, Frederik Vercauteren, Vesselin Velichkov, Bart Preneel
CCS4
2012 Soft Decision Error Correction for Compact Memory-Based PUFs Using a Single Enrollment
Vincent van der Leest, Bart Preneel, Erik van der Sluis
CHES2
2012 Hash Functions Based on Three Permutations: A Generic Security Analysis
Bart Mennink, Bart Preneel
CRYPTO2
2012 It's Not My Fault - On Fault Attacks on Symmetric Cryptography
abstract
Symmetric cryptographic algorithms include stream ciphers, block ciphers, MAC algorithms, and hash functions. This paper discusses the generations of these algorithms and how these generations are affected by fault attacks. It also offers a perspective on approaches that could offer increased resistance against fault attacks and other implementation attacks.
Bart Preneel
FDTC1
2012 UNAF: A Special Set of Additive Differences with Application to the Differential Analysis of ARX
Vesselin Velichkov, Nicky Mouha, Christophe De Cannière, Bart Preneel
FSE4
2012 A Model for Structure Attacks, with Applications to PRESENT and Serpent
Elmar Tischhauser, Bart Preneel
FSE4
2012 Robust Image Content Authentication with Tamper Location
abstract
We propose a novel image authentication system by combining perceptual hashing and robust watermarking. An image is divided into blocks. Each block is represented by a compact hash value. The hash value is embedded in the block. The authenticity of the image can be verified by re-computing hash values and comparing them with the ones extracted from the image. The system can tolerate a wide range of incidental distortion, and locate tampered areas as small as 1/64 of an image. In order to have minimal interference, we design both the hash and the watermark algorithms in the wavelet domain. The hash is formed by the sign bits of wavelet coefficients. The lattice-based QIM watermarking algorithm ensures a high payload while maintaining the image quality. Extensive experiments confirm the good performance of the proposal, and show that our proposal significantly outperforms a state-of-the-art algorithm.
Li Weng, Geert Braeckman, Ann Dooms, Bart Preneel, Peter Schelkens
ICME4
2012 Cryptanalysis of the Xiao - Lai White-Box AES Implementation
Yoni De Mulder, Peter Roelse, Bart Preneel
Selected Areas in Cryptography3
2012 A Practical Attack on KeeLoq
Wim Aerts, Eli Biham, Dieter De Moitie, Elke De Mulder, Orr Dunkelman, Sebastiaan Indesteege, Nathan Keller, Bart Preneel, Guy A. E. Vandenbosch, Ingrid Verbauwhede
J. Cryptol.8
2012 Related-Key Boomerang and Rectangle Attacks: Theory and Experimental Analysis
abstract
In 2004, we introduced the related-key boomerang/ rectangle attacks, which allow us to enjoy the benefits of the boomerang attack and the related-key technique, simultaneously. The new attacks were used since then to attack numerous block ciphers. While the claimed applications are significant, most of them have a major drawback. Their validity cannot be verified experimentally due to their high complexity. Together with the lack of rigorous justification of the probabilistic assumptions underlying the technique, this lead Murphy to claim that attacks using the related-key boomerang/rectangle technique are not legitimate. This paper contains two contributions. The first is a rigorous analysis of the related-key boomerang/rectangle attacks, including devising provably optimal distinguishers and computing their success rate, and discussing the underlying independence assumptions. The second contribution is an extensive experimental verification of the related-key boomerang attack against the GSM block cipher, KASUMI. Our experiments reveal that the success probability of the distinguisher, when averaged over different choices of the keys, is close to the theoretical prediction. However, the exact probability depends on the key, such that for some por- tion of the keys, the distinguisher holds with a higher probability than expected, while for the rest of the keys, the distinguisher fails completely.
Jongsung Kim, Seokhie Hong, Bart Preneel, Eli Biham, Orr Dunkelman, Nathan Keller
IEEE Trans. Inf. Theory3
2012 Evaluating Tag-Based Preference Obfuscation Systems
abstract
While personalization is key to increase the usability of online services, disclosing one's preferences is undesirable from a privacy perspective, because it enables profiling through the linkage of what may otherwise be unlinkable service invocations. This paper considers an easily implementable class of obfuscation strategies as a means to mitigate these risks, and examines its privacy/utility tradeoff. Our results are based on simulations that take place within a modular evaluation framework that can seamlessly accommodate real-world data. We conducted experiments with different simulated behaviors and using two preference populations, namely a population of maximally diverse preferences and one consisting of the movie preferences of some Netflix users. We measure utility in a way that is specific to the application of preference obfuscation. Privacy is measured in terms of unlinkability, with respect to two different adversaries. Our results show that reasonable privacy/utility tradeoffs require the disclosure of only small amounts of preference information.
Andreas Pashalidis, Bart Preneel
IEEE Trans. Knowl. Data Eng.2
2011 Finding Collisions for Reduced Luffa-256 v2 (Poster)
Bart Preneel, Hirotaka Yoshida, Dai Watanabe
ACISP1
2011 Algebraic Techniques in Differential Cryptanalysis Revisited
Nicky Mouha, Bart Preneel
ACISP4
2011 Differential and Linear Cryptanalysis Using Mixed-Integer Linear Programming
Nicky Mouha, Qingju Wang 0001, Dawu Gu, Bart Preneel
Inscrypt4
2011 Meet-in-the-Middle Attacks on Reduced-Round XTEA
Gautham Sekar, Nicky Mouha, Vesselin Velichkov, Bart Preneel
CT-RSA4
2011 A New RFID Privacy Model
Jens Hermans, Andreas Pashalidis, Frederik Vercauteren, Bart Preneel
ESORICS4
2011 The Additive Differential Probability of ARX
Vesselin Velichkov, Nicky Mouha, Christophe De Cannière, Bart Preneel
FSE4
2011 Image Distortion Estimation by Hash Comparison
Li Weng, Bart Preneel
MMM (1)2
2011 A Privacy-Preserving ID-Based Group Key Agreement Scheme Applied in VPAN
Yoni De Mulder, Karel Wouters, Bart Preneel
SOFSEM3
2011 A taxonomy of self-modifying code for obfuscation
Nikos Mavrogiannopoulos, Nessim Kisserli, Bart Preneel
Comput. Secur.3
2011 Tripartite modular multiplication
Kazuo Sakiyama, Miroslav Knezevic, Junfeng Fan, Bart Preneel, Ingrid Verbauwhede
Integr.4
2011 Practical Collisions for EnRUPT
Sebastiaan Indesteege, Bart Preneel
J. Cryptol.2
2011 A privacy threat analysis framework: supporting the elicitation and fulfillment of privacy requirements
Mina Deng, Kim Wuyts, Riccardo Scandariato, Bart Preneel, Wouter Joosen
Requir. Eng.4
2011 PriPAYD: Privacy-Friendly Pay-As-You-Drive Insurance
abstract
Pay-As-You-Drive insurance schemes are establishing themselves as the future of car insurance. However, their current implementations, in which fine-grained location data are sent to insurers, entail a serious privacy risk. We present PriPAYD, a system where the premium calculations are performed locally in the vehicle, and only aggregated data are sent to the insurance company, without leaking location information. Our design is based on well-understood security techniques that ensure its correct functioning. We discuss the viability of PriPAYD in terms of cost, security, and ease of certification. We demonstrate that PriPAYD is possible through a proof-of-concept implementation that shows how privacy can be obtained at a very reasonable extra cost.
Carmela Troncoso, George Danezis, Eleni Kosta, Josep Balasch, Bart Preneel
IEEE Trans. Dependable Secur. Comput.5
2011 A Privacy-Preserving Buyer-Seller Watermarking Protocol Based on Priced Oblivious Transfer
abstract
Buyer-seller watermarking protocols allow copyright protection of digital goods. To protect privacy, some of those protocols provide buyers with anonymity. However, anonymous e-commerce protocols pose several disadvantages, like hindering customer management or requiring anonymous payment mechanisms. Additionally, no existing buyer-seller watermarking protocol provides fair exchange. We propose a novel approach for the design of privacy-preserving buyer-seller watermarking protocols. In our approach, the seller authenticates buyers but does not learn which items are purchased. Since buyers are not anonymous, customer management is eased and currently deployed methods of payment can be utilized. We define an ideal functionality for privacy-preserving copyright protection protocols. To realize our functionality, a protocol must ensure that buyers pay the right price without disclosing the purchased item, and that sellers are able to identify buyers that released pirated copies. We construct a protocol based on priced oblivious transfer and on existing techniques for asymmetric watermark embedding. Furthermore, we implement and evaluate the efficiency of our protocol, and we explain how to extend it in order to achieve optimistic fair exchange.
Alfredo Rial, Josep Balasch, Bart Preneel
IEEE Trans. Inf. Forensics Secur.3
2010 Revisiting Higher-Order DPA Attacks:
Benedikt Gierlichs, Lejla Batina, Bart Preneel, Ingrid Verbauwhede
CT-RSA3
2010 Speed Records for NTRU
Jens Hermans, Frederik Vercauteren, Bart Preneel
CT-RSA3
2010 The First 30 Years of Cryptographic Hash Functions and the NIST SHA-3 Competition
Bart Preneel
CT-RSA1
2010 An embedded platform for privacy-friendly road charging applications
abstract
Systems based on satellite localization are enabling new scenarios for road charging schemes by offering the possibility to charge drivers as a function of their road usage. An in-vehicle installation of a black box with the capabilities of a Location Based Service terminal suffices to deploy such a scheme. In the most straightforward architecture a back-end server collects vehicle's location data in order to extract the correct fees. However, with industry, governments and users being more and more aware of privacy issues the deployment of such system seems to be contradictory. Our contribution is the demonstration of a practical and functional road charging system based on PriPAYD [1]. Our black box is built guaranteeing most of the processing of location data in real-time, thus minimizing overheads required to ensure security and privacy. The performance of our software-based prototype is tested and proves that the deployment of a privacy-friendly solution can be achieved within a minimum cost increment compared to existing road charging schemes.
Josep Balasch, Ingrid Verbauwhede, Bart Preneel
DATE3
2010 A general model for hiding control flow
abstract
This paper proposes a general model for hiding control flow graph flattening in C programs. We explain what control flow graph flattening is and illustrate why it is successful as protection against static control flow analysis. Furthermore, we propose a scheme, complementary to control flow graph flattening, which does not leak any control flow graph information statically. Instead of relying on ad hoc security by using variable aliasing and global pointers to complicate data flow analysis of the switch variable, we try to base our security claims more on information theory, data flow, and cryptography. Our formal model is structured and extendable. Moreover, it can specify which minimum of information to hide from the program (e.g. a secret value or function) such that no control flow information is leaked. To express the robustness of our scheme we present some attacks and their feasibility. Finally, we sketch a few scenarios in which our solution could be deployed.
Jan Cappaert, Bart Preneel
Digital Rights Management Workshop2
2010 Cryptographic Hash Functions: Theory and Practice
Bart Preneel
ICICS1
2010 Security Reductions of the Second Round SHA-3 Candidates
Elena Andreeva 0001, Bart Mennink, Bart Preneel
ISC3
2010 Improved Collision Attacks on the Reduced-Round Grøstl Hash Function
Kota Ideguchi, Elmar Tischhauser, Bart Preneel
ISC3
2010 A novel video hash algorithm
abstract
Perceptual hashing is an emerging solution for identification and authentication of multimedia content. In this work, a video hash algorithm is proposed. This algorithm computes a 180-bit hash value for videos of arbitrary lengths. The hash value can resist common signal processing and slight geometric distortion. The basic mechanism of the algorithm is to compute and accumulate frame hash values. A frame hash algorithm is designed by combining semi-global and local features. Semi-global features are extracted by computing several statistics from image blocks. Local features are extracted by computing a compact edge density map around stable feature points. The good performance of the new algorithm has been demonstrated by experiments.
Li Weng, Bart Preneel
ACM Multimedia2
2010 From Image Hashing to Video Hashing
Li Weng, Bart Preneel
MMM2
2010 Increased Resilience in Threshold Cryptography: Sharing a Secret with Devices That Cannot Store Shares
Koen Simoens, Roel Peeters, Bart Preneel
Pairing3
2010 Efficient Isolation of Trusted Subsystems in Embedded Systems
Raoul Strackx, Frank Piessens, Bart Preneel
SecureComm3
2010 PrETP: Privacy-Preserving Electronic Toll Pricing
Josep Balasch, Alfredo Rial, Carmela Troncoso, Bart Preneel, Ingrid Verbauwhede, Christophe Geuens
USENIX Security Symposium4
2010 Galois geometries and applications
Jan De Beule, Yves Edel, Emilia Käsper, Andreas Klein 0001, Svetla Nikova, Bart Preneel, Jeroen Schillewaert, Leo Storme
Des. Codes Cryptogr.6
2010 Algebraic cryptanalysis of a small-scale version of stream cipher Lex
abstract
In this study, the authors analyse with respect to algebraic attacks a small-scale version of the stream cipher Lex. They base it on a small-scale version of the block cipher advanced encryption standard (AES) with 16-bit state and 16-bit key. They represent the small-scale Lex and its key schedule in two alternative ways: as a system of cubic boolean equations and as a system of quadratic boolean equations. The authors use Gröbner bases to solve the two systems for different number of rounds and sizes of the leak. They obtain the best results for the quadratic representation of the cipher. For this case they are able to recover the secret key in time less than 2 min by solving a system of 374 quadratic boolean equations in 208 unknowns resulting from 5 rounds of the cipher.
Vesselin Velichkov, Vincent Rijmen, Bart Preneel
IET Inf. Secur.3
2010 A Provably Secure Anonymous Buyer-Seller Watermarking Protocol
abstract
Buyer-seller watermarking (BSW) protocols allow copyright protection of digital content. The protocol is anonymous when the identity of buyers is not revealed if they do not release pirated copies. Existing BSW protocols are not provided with a formal analysis of their security properties. We employ the ideal-world/real-world paradigm to propose a formal security definition for copyright protection protocols, and we analyze an anonymous BSW protocol and prove that it fulfills our definition. Additionally, we implement the protocol and measure its efficiency.
Alfredo Rial, Mina Deng, Tiziano Bianchi, Alessandro Piva, Bart Preneel
IEEE Trans. Inf. Forensics Secur.5
2009 Anonymous user communication for privacy protection in wireless metropolitan mesh networks
abstract
As a combination of ad hoc networks and wireless local area network (WLAN), the wireless mesh network (WMN) provides a low-cost convenient solution to the last-mile network-connectivity problem. As such, existing route protocols designed to provide security and privacy protection for ad hoc networks are no longer applicable in WMNs. On the other hand, little research has focused on privacy-preserving routing for WMNs. In this paper, we propose two solutions for security and privacy protection in WMNs. The first scheme relies on group signatures, together with user credentials, to deliver security and privacy protection. By enforcing access control using user credentials, the user's identity has to be disclosed to mesh routers. To avoid this, our second scheme employs pairwise secrets between any two users to achieve stronger privacy protection. In the second scheme, the user is kept anonymous to mesh routers. Finally, we analyze these two schemes in terms of security, privacy, and performance.
Zhiguo Wan, Kui Ren 0001, Bo Zhu 0001, Bart Preneel, Ming Gu 0001
AsiaCCS4
2009 Cryptanalysis of the ESSENCE Family of Hash Functions
Nicky Mouha, Gautham Sekar, Jean-Philippe Aumasson, Thomas Peyrin, Søren S. Thomsen, Meltem Sönmez Turan, Bart Preneel
Inscrypt7
2009 Case Study : A class E power amplifier for ISO-14443A
abstract
This paper reports on the design and implementation of a class E push-pull amplifier in order to increase the reading range of an ISO-14443A RFID system. With the aid of classical design formulas and some alterations due to parasitic and intrinsic capacitances, a working implementation was made that can provide the loop with an amplified modulated current wave.
Elke De Mulder, Wim Aerts, Bart Preneel, Ingrid Verbauwhede, Guy A. E. Vandenbosch
DDECS3
2009 Practical Collisions for EnRUPT
Sebastiaan Indesteege, Bart Preneel
FSE2
2009 Shape-based features for image hashing
abstract
Perceptual hashing is a solution for identification and authentication of multimedia content. The key of this technique is the extraction of proper features. In this paper, two features are proposed for natural image hashing. They are based on the description of shapes, in terms of contours and regions. The contour-based feature is formed by edge detection. The region-based feature is formed by the angular radial transform. Simulation results show that they have good robustness and discriminability. Compared to some other features, better ROC performance is achieved.
Li Weng, Bart Preneel
ICME2
2009 A New Approach to chi2 Cryptanalysis of Block Ciphers
Jorge Nakahara Jr., Gautham Sekar, Daniel Santana de Freitas, Chang Chiann, Ramon Hugo de Souza, Bart Preneel
ISC6
2009 Towards Security Notions for White-Box Cryptography
Amitabh Saxena, Brecht Wyseur, Bart Preneel
ISC3
2009 Universally Composable Adaptive Priced Oblivious Transfer
Alfredo Rial, Markulf Kohlweiss, Bart Preneel
Pairing3
2009 Threshold things that think: usable authorization for resharing
abstract
No abstract available.
Roel Peeters, Markulf Kohlweiss, Bart Preneel, Nicky Sulmon
SOUPS3
2009 Privacy Weaknesses in Biometric Sketches
abstract
The increasing use of biometrics has given rise to new privacy concerns. Biometric encryption systems have been proposed in order to alleviate such concerns: rather than comparing the biometric data directly, a key is derived from these data and subsequently knowledge of this key is proved. One specific application of biometric encryption is the use of biometric sketches: in this case biometric template data are protected with biometric encryption. We address the question whether one can undermine a user's privacy given access to biometrically encrypted documents, and more in particular, we examine if an attacker can determine whether two documents were encrypted using the same biometric. This is a particular concern for biometric sketches that are deployed in multiple locations: in one scenario the same biometric sketch is deployed everywhere; in a second scenario the same biometric data is protected with two different biometric sketches. We present attacks on template protection schemes that can be described as fuzzy sketches based on error-correcting codes. We demonstrate how to link and reverse protected templates produced by code-offset and bit-permutation sketches.
Koen Simoens, Pim Tuyls, Bart Preneel
SP3
2009 Delegation and digital mandates: Legal requirements and security objectives
Brendan Van Alsenoy, Danny De Cock, Koen Simoens, Jos Dumortier, Bart Preneel
Comput. Law Secur. Rev.5
2009 n PAKE+: A Tree-Based Group Password-Authenticated Key Exchange Protocol Using Different Passwords
Zhiguo Wan, Robert H. Deng, Feng Bao 0001, Bart Preneel, Ming Gu 0001
J. Comput. Sci. Technol.4
2009 Guest editorial: special issue on electronic voting
abstract
The 13 papers in this special issue focus on electronic voting.
Ronald L. Rivest, David Chaum, Bart Preneel, Aviel D. Rubin, Donald G. Saari, Poorvi L. Vora
IEEE Trans. Inf. Forensics Secur.3
2008 Secure and Privacy-Friendly Logging for eGovernment Services
abstract
In this paper we present a scheme for building a logging- trail for processes related to eGovernment services. A citizen can reconstruct the trail of such a process and verify its status if he is the subject of that process. Reconstruction is based on hand-overs, special types of log events, that link data stored by multiple logging servers, which are not necessarily trusted. Our scheme is privacy-friendly in the sense that only the authorised subject, i.e. the citizen, can link the different log entries related to one specific process. The scheme is also auditable; it allows logging servers to show that they behave according to a certain policy.
Karel Wouters, Koen Simoens, Danny Lathouwers, Bart Preneel
ARES4
2008 Mutual Information Analysis
Benedikt Gierlichs, Lejla Batina, Pim Tuyls, Bart Preneel
CHES4
2008 The State of Hash Functions and the NIST SHA-3 Competition
Bart Preneel
Inscrypt1
2008 Key-Recovery Attacks on Universal Hash Function Based MAC Algorithms
Helena Handschuh, Bart Preneel
CRYPTO2
2008 A Framework for the Analysis of Mix-Based Steganographic File Systems
Claudia Díaz, Carmela Troncoso, Bart Preneel
ESORICS3
2008 Reliable Key Establishment Scheme Exploiting Unidirectional Links in Wireless Sensor Networks
abstract
Wireless sensor networks are designed for outdoor environment surveillance and require benign coverage, steady working status and long lifetime, moreover, they require efficient security services for rigorous applications. Most security schemes are designed to work efficiently only when bidirectional links exist. So do most key establishment protocols for WSNs. Traditional key establishment schemes delete all the unidirectional links from the network. Hence, the sensors covered only by unidirectional links are excluded from the collaborating network, even if they are stable and energetic. These schemes shorten the lifetime and decrease the connectivity of the whole network. To improve the network connectivity and increase the number of available sensors in the network, a security mechanism is proposed for wireless sensor networks exploiting unidirectional links. By searching local connection components in a small area, this mechanism helps negotiate shared secrets among nodes that may covered by unidirectional links. It obtains identity authentication and perfect resilience against node compromise.The simulation reveals that, our scheme can greatly increase the proportion of available sensor nodes and network connectivity, which will efficiently prolong the network lifetime.
Yuanyuan Zhang 0002, Dawu Gu, Bart Preneel
EUC (1)3
2008 A Practical Attack on KeeLoq
Sebastiaan Indesteege, Nathan Keller, Orr Dunkelman, Eli Biham, Bart Preneel
EUROCRYPT5
2008 On Secure and Anonymous Buyer-Seller Watermarking Protocol
abstract
Buyer-seller watermarking protocols incorporate digital watermarking with cryptography, in order to protect digital copyrights and privacy rights for the seller and the buyer before, during, and after purchase activities in e-commerce. In this paper, we analyze the security of some previously proposed protocols, and propose a secure and anonymous buyer-seller watermarking protocol. In contrast to early work, our improvement on the protocol's security properties ensures that the design requirements are fulfilled. The proposed protocol is able to simultaneously solve the piracy tracing problem, the customer's rights problem, the unbinding problem, the anonymity problem, the conspiracy problem, and the dispute problem. In the proposed protocol, a buyer can purchase digital contents anonymously but his anonymity can be revoked as soon as he is adjudicated to be guilty by a legal institute, such as civil court.
Mina Deng, Bart Preneel
ICIW2
2008 Towards Tamper Resistant Code Encryption: Practice and Experience
Jan Cappaert, Bart Preneel, Bertrand Anckaert, Matias Madou, Koen De Bosschere
ISPEC2
2008 Collisions for RC4-Hash
Sebastiaan Indesteege, Bart Preneel
ISC2
2008 Perfect Matching Disclosure Attacks
Carmela Troncoso, Benedikt Gierlichs, Bart Preneel, Ingrid Verbauwhede
Privacy Enhancing Technologies3
2008 Cryptographic Algorithms - Successes, Failures and Challenges
Bart Preneel
SECRYPT1
2008 Anonymous ID-Based Group Key Agreement for Wireless Networks
abstract
Popularity of group-oriented applications motivates research on security and privacy protection for group communications. A number of group key agreement protocols exploiting ID-based cryptosystem have been proposed for this objective. Though bearing beneficial features like reduced management cost, private key delegation from ID-based cryptosystem, they have not taken into account privacy issues during group communication. In wireless networks, the privacy problem becomes more crucial and urgent for mobile users due to the open nature of radio media. In this paper, we proposed an anonymous ID- based group key agreement protocol for wireless networks. Based on ID-based cryptosystem, our protocol not only benefits from the desirable features of ID-based cryptosystem, but also provides privacy protection for mobile users. More important, in the proposed protocol, the computation cost for each group member is largely reduced to meet the computation capability restriction of mobile devices.
Zhiguo Wan, Kui Ren 0001, Wenjing Lou, Bart Preneel
WCNC4
2008 A secure privacy-preserving roaming protocol based on hierarchical identity-based encryption for mobile networks
abstract
Roaming services in wireless networks provide people with preferable flexibility and convenience. However, such ad-vantages should be offered with both security and privacy in mind. With consideration on privacy protection during roaming in wireless networks, we proposed a hierarchical ID-based roaming protocol in this paper. In our scheme, we use a 2-layer hierarchical ID-based cryptosystem in which a trusted party acts as the root authority, each domain server acts as the second-layer authority, and the roaming user is the end user. With the hierarchical ID-based cryptosystem, we can avoid involvement with home network, and keep the roaming the user’s identity private. Furthermore, not only the root authority is relieved from management of a large amount of private/public key pairs, but the domain servers are free to generate key pairs for their registered users. At the same time, we use hash chains together with ID-based signatures to achieve non-repudiation for service payment. Categories and Subject Descriptors
Zhiguo Wan, Kui Ren 0001, Bart Preneel
WISEC3
2008 Insights on identity documents based on the Belgian case study
Danny De Cock, Koen Simoens, Bart Preneel
Inf. Secur. Tech. Rep.3
2008 Remote attestation on legacy operating systems with trusted platform modules
Dries Schellekens, Brecht Wyseur, Bart Preneel
Sci. Comput. Program.3
2007 Seven-Property-Preserving Iterated Hashing: ROX
Elena Andreeva 0001, Gregory Neven, Bart Preneel, Thomas Shrimpton
ASIACRYPT3
2007 MAME: A Compression Function with Reduced Hardware Requirements
Hirotaka Yoshida, Dai Watanabe, Katsuyuki Okeya, Jun Kitahara, Hongjun Wu 0001, Özgül Küçük, Bart Preneel
CHES7
2007 Cryptanalysis of Reduced Variants of the FORK-256 Hash Function
Florian Mendel, Joseph Lano, Bart Preneel
CT-RSA3
2007 Differential Cryptanalysis of the Stream Ciphers Py, Py6 and Pypy
Hongjun Wu 0001, Bart Preneel
EUROCRYPT2
2007 Related-Key Rectangle Attacks on Reduced AES-192 and AES-256
Jongsung Kim, Seokhie Hong, Bart Preneel
FSE3
2007 Differential-Linear Attacks Against the Stream Cipher Phelix
Hongjun Wu 0001, Bart Preneel
FSE2
2007 Efficient pipelining for modular multiplication architectures in prime fields
abstract
This paper presents a pipelined architecture of a modular Montgomery multiplier, which is suitable to be used in public key coprocessors. Starting from a baseline implementation of the Montgomery algorithm, a more compact pipelined version is derived. The design makes use of 16-bit integer multiplication blocks that are available on recently manufactured FPGAs. The critical path is optimized by omitting the exact computation of intermediate results in the Montgomery algorithm using a 6-2 carry-save notation. This results in a high-speed architecture,which outperforms previously designed Montgomery multipliers. Because a very popular application of Montgomery multiplication is public key cryptography, we compare our implementation to the state-of-the-art in Montgomery multipliers on the basis of performance results for 1024-bit RSA.
Nele Mentens, Kazuo Sakiyama, Bart Preneel, Ingrid Verbauwhede
ACM Great Lakes Symposium on VLSI3
2007 Side-channel resistant system-level design flow for public-key cryptography
abstract
In this paper, we propose a new design methodology to assess the risk for side-channel attacks, more specifically timing analysis and simple power analysis, at an early design stage. This method is illustrated with the design of an elliptic curve cryptographic processor. It also allows to evaluate the quality of countermeasures against these attacks by evaluating hamming distances for eachsignal and each register in a partial functional domain (e.g. datapath or controller). Thus a first order side-channel-resistant design can be obtained with system-level design in which the simulation can run faster than conventional HDL simulations.
Kazuo Sakiyama, Elke De Mulder, Bart Preneel, Ingrid Verbauwhede
ACM Great Lakes Symposium on VLSI3
2007 n PAKE + : A Hierarchical Group Password-Authenticated Key Exchange Protocol Using Different Passwords
Zhiguo Wan, Robert H. Deng, Feng Bao 0001, Bart Preneel
ICICS4
2007 Attacking Some Perceptual Image Hash Algorithms
abstract
Perceptual hashing is an emerging solution for multimedia content authentication. Due to their robustness, such techniques might not work well when malicious attack is perceptually insignificant. We designed an experiment and verified that some state-of-the-art image hash algorithms could not distinguish small malicious distortion and some authentic distortion. We proposed an enhancement framework as a remedy. It suggests extracting information from the content and combining it with the secret key to generate the perceptual hash, so that perceptually insignificant information can be protected.
Li Weng, Bart Preneel
ICME2
2007 Public-Key Cryptography on the Top of a Needle
abstract
This work describes the smallest known hardware implementation for Elliptic/Hyperelliptic Curve Cryptography (ECC/HECC). We propose two solutions for Public-key Cryptography (PKC), which are based on arithmetic on elliptic/hyperelliptic curves. One solution relies on ECC over binary fields 𝔽2𝓃where 𝓃 is a composite number of the form2𝑝(𝑝is a prime) and another on HECC on curves of genus 2 over 𝔽2𝑝. This implies the same arithmetic unit for both cases which supports arithmetic in a field 𝔽2𝑝. Our best solution that still results in a feasible performance features less than 5 kgates with an average power consumption smaller than 10μW.
Lejla Batina, Nele Mentens, Kazuo Sakiyama, Bart Preneel, Ingrid Verbauwhede
ISCAS4
2007 Efficient Negative Databases from Cryptographic Hash Functions
George Danezis, Claudia Díaz, Sebastian Faust, Emilia Käsper, Carmela Troncoso, Bart Preneel
ISC6
2007 New Weaknesses in the Keystream Generation Algorithms of the Stream Ciphers TPy and Py
Gautham Sekar, Souradyuti Paul, Bart Preneel
ISC3
2007 Key Establishment Using Secure Distance Bounding Protocols
abstract
Key establishment is one of the major challenges in wireless personal area networks, as traditional security mechanisms often do not cope with the dynamic characteristics of wireless ad-hoc networks. In this paper, we present an efficient key establishment protocol, based on the basic Diffie-Hellman protocol. It enables mutual device authentication through presence and establishes a session key between personal mobile devices which do not yet share any authenticated cryptographic material. Distance bounding protocols, which have been introduced by Brands and Chaum at Eurocrypt'93 to preclude distance fraud and mafia fraud attacks, are employed to determine an upper- bound on the distance to another entity. Our solution only requires limited user-interaction: the user of a mobile device is expected to perform a visual verification within a small physical space.
Dave Singelée, Bart Preneel
MobiQuitous2
2007 Efficient Oblivious Augmented Maps: Location-Based Services with a Payment Broker
Markulf Kohlweiss, Sebastian Faust, Lothar Fritsch, Bartek Gedrojc, Bart Preneel
Privacy Enhancing Technologies5
2007 A survey of recent developments in cryptographic algorithms for smart cards
Bart Preneel
Comput. Networks1
2007 High-performance Public-key Cryptoprocessor for Wireless Mobile Applications
Kazuo Sakiyama, Lejla Batina, Bart Preneel, Ingrid Verbauwhede
Mob. Networks Appl.3
2007 Multicore Curve-Based Cryptoprocessor with Reconfigurable Modular Arithmetic Logic Units over GF(2n)
abstract
This paper presents a reconfigurable curve-based cryptoprocessor that accelerates scalar multiplication of Elliptic Curve Cryptography (ECC) and HyperElliptic Curve Cryptography (HECC) of genus 2 over GF(2n). By allocating a copies of processing cores that embed reconfigurable Modular Arithmetic Logic Units (MALUs) over GF(2n), the scalar multiplication of ECC/HECC can be accelerated by exploiting Instruction-Level Parallelism (ILP). The supported field size can be arbitrary up to a(n + 1) - 1. The superscaling feature is facilitated by defining a single instruction that can be used for all field operations and point/divisor operations. In addition, the cryptoprocessor is fully programmable and it can handle various curve parameters and arbitrary irreducible polynomials. The cost, performance, and security trade-offs are thoroughly discussed for different hardware configurations and software programs. The synthesis results with a 0.13-mum CMOS technology show that the proposed reconfigurable cryptoprocessor runs at 292 MHz, whereas the field sizes can be supported up to 587 bits. The compact and fastest configuration of our design is also synthesized with a fixed field size and irreducible polynomial. The results show that the scalar multiplication of ECC over GF(2163) and HECC over GF(283) can be performed in 29 and 63 mus, respectively.
Kazuo Sakiyama, Lejla Batina, Bart Preneel, Ingrid Verbauwhede
IEEE Trans. Computers3
2006 Evaluating the Resistance of Stream Ciphers with Linear Feedback Against Fast Algebraic Attacks
An Braeken, Joseph Lano, Bart Preneel
ACISP3
2006 ARM: Anonymous Routing Protocol for Mobile Ad hoc Networks
abstract
Due to the nature of radio transmissions, communications in wireless networks are easy to capture and analyze. Next to this, privacy enhancing techniques (PETs) proposed for wired networks such as the Internet often cannot be applied to mobile ad hoc networks (MANETs). In this paper we present a novel anonymous on demand routing scheme for MANETs. We identify a number of problems of previously proposed works and propose an efficient solution that provides anonymity in a stronger adversary model
Stefaan Seys, Bart Preneel
AINA (2)2
2006 A Weakness in Some Oblivious Transfer and Zero-Knowledge Protocols
Ventzislav Nikov, Svetla Nikova, Bart Preneel
ASIACRYPT3
2006 On the (In)security of Stream Ciphers Based on Arrays and Modular Addition
Souradyuti Paul, Bart Preneel
ASIACRYPT2
2006 Superscalar Coprocessor for High-Speed Curve-Based Cryptography
Kazuo Sakiyama, Lejla Batina, Bart Preneel, Ingrid Verbauwhede
CHES3
2006 Fpga-Oriented Secure Data Path Design: Implementation of a Public Key Coprocessor
abstract
This paper introduces a secure FPGA implementation of a coprocessor for public key cryptography. It supports Elliptic Curve Cryptography (ECC) as well as the older RSA standard. When choosing adequate key lengths, RSA and ECC are assumed to be secure from an algorithmic point of view. On the other hand, an implementation of these algorithms should also guarantee side-channel security. This feature does not only cause an inevitable performance degradation, but also an area increase. We overcome these drawbacks by fitting the public key architecture and algorithms into a coprocessor that optimally exploites the dedicated features on a Spartan XC3S4000. Although this is a very low-cost FPGA, the performance results of our implementation meet the requirements of a broad range of high-end applications.
Nele Mentens, Kazuo Sakiyama, Lejla Batina, Ingrid Verbauwhede, Bart Preneel
FPL5
2006 FPGA Vendor Agnostic True Random Number Generator
abstract
This paper describes a solution for the generation of true random numbers in a purely digital fashion; making it suitable for any FPGA type, because no FPGA vendor specific features (e.g., like phase-locked loop) or external analog components are required. Our solution is based on a framework for a provable secure true random number generator recently proposed by Sunar, Martin and Stinson. It uses a large amount of ring oscillators with identical ring lengths as a fast noise source - but with some deterministic bits - and eliminates the non-random samples by appropriate post-processing based on resilient functions. This results in a slower bit stream with high entropy. Our FPGA implementation achieves a random bit throughput of more than 2 Mbps, remains fairly compact (needing minimally 110 ring oscillators of 3 inverters) and is highly portable
Dries Schellekens, Bart Preneel, Ingrid Verbauwhede
FPL2
2006 Distinguishing Attacks on the Stream Cipher Py
Souradyuti Paul, Bart Preneel, Gautham Sekar
FSE2
2006 Cryptanalysis of the Stream Cipher DECIM
Hongjun Wu 0001, Bart Preneel
FSE2
2006 Resynchronization Attacks on WG and LEX
Hongjun Wu 0001, Bart Preneel
FSE2
2006 A Parallel Processing Hardware Architecture for Elliptic Curve Cryptosystems
abstract
We propose a parallel processing crypto-processor for elliptic curve cryptography (ECC) to speed up EC point multiplication. The processor consists of a controller that dynamically checks instruction-level parallelism (ILP) and multiple sets of modular arithmetic logic units accelerating modular operations. A case study of HW design with the proposed architecture shows that EC point multiplication over GF(p) and GF(2m) can be improved by a factor of 1.6 compared to the case of using single processing element
Kazuo Sakiyama, Elke De Mulder, Bart Preneel, Ingrid Verbauwhede
ICASSP (3)3
2006 Flexible hardware architectures for curve-based cryptography
abstract
This paper compares implementations of elliptic and hyperelliptic curve cryptography (ECC and HECC) on an FPGA platform. We use the same low-level blocks to implement the basic operations and we choose the bit-lengths so that both systems have equal security levels. The results are in favor of HECC. Our HECC implementation is slightly larger than ECC, but at the same time around 35% faster
Lejla Batina, Nele Mentens, Bart Preneel, Ingrid Verbauwhede
ISCAS3
2006 A fast dual-field modular arithmetic logic unit and its hardware implementation
abstract
We propose a fast modular arithmetic logic unit (MALU) that is scalable in the digit size (d) and the field size (k). The datapath of MALU has chains of carry save adders (CSAs) to speed up the large integer arithmetic operations over GF(p) and GF(2m). It is well suited and very efficient for the modular multiplication and addition/subtraction which are the computational kernels of elliptic curve and hyperelliptic curve cryptography (H/ECC). While maintaining the scalability and multi-function, we obtain a throughput of 205 Mbps and 388 Mbps with a clock rate of 110 MHz for 256-bit GF(p) and GF(2239) respectively on FPGA prototyping
Kazuo Sakiyama, Bart Preneel, Ingrid Verbauwhede
ISCAS2
2006 On the security of stepwise triangular systems
Christopher Wolf, An Braeken, Bart Preneel
Des. Codes Cryptogr.3
2006 An introduction to Block Cipher Cryptanalysis
abstract
Since the introduction of the Data Encryption Standard (DES) in the mid-1970s, block ciphers have played an ever-increasing role in cryptology. Because of the growing number of practical applications relying on their security,block ciphers have received, and are still receiving, a substantial amount of attention from academic cryptanalysts. This has led, over the last decades,to the development of several general techniques to analyze the security of block ciphers. This paper reviews the fundamental principles behind today's state of the art in block cipher cryptanalysis.
Christophe De Cannière, Alex Biryukov, Bart Preneel
Proc. IEEE3
2006 Classification of cubic (n-4)-resilient Boolean functions
abstract
Carlet and Charpin classified the set of cubic (n-4)-resilient Boolean functions into four different types with respect to the Walsh spectrum and the dimension of the linear space. Based on the classification of RM(3,6)/RM(1,6), we have completed this classification of cubic (n-4)-resilient Boolean functions by deriving the corresponding algebraic normal form (ANF) and autocorrelation spectrum for each of the four types. At the same time, we have solved an open problem by proving that all plateaued cubic (n-4)-resilient Boolean functions have dimension of the linear space equal either to n-5 or n-6.
An Braeken, Yuri L. Borissov, Svetla Nikova, Bart Preneel
IEEE Trans. Inf. Theory4
2005 Solving Systems of Differential Equations of Addition
Souradyuti Paul, Bart Preneel
ACISP2
2005 Side-channel aware design: Algorithms and Architectures for Elliptic Curve Cryptography over GF(2n)
abstract
This paper proposes efficient algorithms for Elliptic Curve Cryptography (ECC). As an example a compact and efficient FPGA architecture for ECC over finite fields of even characteristic is presented. The implementation is balanced in order to increase the security w.r.t. simple side-channel attacks. Multiplication in GF(2 n ), Hardware implementation, Systolic array architecture, Elliptic Curve Cryptography (ECC), Montgomery method for point multiplication © 2005 IEEE.
Lejla Batina, Nele Mentens, Bart Preneel, Ingrid Verbauwhede
ASAP3
2005 Hardware/Software Co-design for Hyperelliptic Curve Cryptography (HECC) on the 8051µP
Lejla Batina, David Hwang 0001, Alireza Hodjat, Bart Preneel, Ingrid Verbauwhede
CHES4
2005 A Study of the Security of Unbalanced Oil and Vinegar Signature Schemes
An Braeken, Christopher Wolf, Bart Preneel
CT-RSA3
2005 A Systematic Evaluation of Compact Hardware Implementations for the Rijndael S-Box
Nele Mentens, Lejla Batina, Bart Preneel, Ingrid Verbauwhede
CT-RSA3
2005 Related-Key Rectangle Attacks on Reduced Versions of SHACAL-1 and AES-192
Seokhie Hong, Jongsung Kim, Sangjin Lee 0002, Bart Preneel
FSE4
2005 Classification of Boolean Functions of 6 Variables or Less with Respect to Some Cryptographic Properties
An Braeken, Yuri L. Borissov, Svetla Nikova, Bart Preneel
ICALP4
2005 On the Security of Encryption Modes of MD4, MD5 and HAVAL
Jongsung Kim, Alex Biryukov, Bart Preneel, Sangjin Lee 0002
ICICS3
2005 Probabilistic Algebraic Attacks
An Braeken, Bart Preneel
IMACC2
2005 Normality of Vectorial Functions
An Braeken, Christopher Wolf, Bart Preneel
IMACC3
2005 Location verification using secure distance bounding protocols
abstract
Authentication in conventional networks (like the Internet) is usually based upon something you know (e.g., a password), something you have (e.g., a smartcard) or something you are (biometrics). In mobile ad-hoc networks, location information can also be used to authenticate devices and users. We focus on how a provers can securely show that (s)he is within a certain distance to a verifier. Brands and Chaum proposed the distance bounding protocol as a secure solution for this problem. However, this protocol is vulnerable to a so-called "terrorist fraud attack". In this paper, we explain how to modify the distance bounding protocol to make it resistant to this kind of attacks. Recently, two other secure distance bounding protocols were published. We discuss the properties of these protocols and show how to use it as a building block in a location verification scheme
Dave Singelée, Bart Preneel
MASS2
2005 Power consumption evaluation of efficient digital signature schemes for low power devices
abstract
In this paper we evaluate the power consumption of different digital signature schemes. We compare the cost of the elliptic curve digital signature algorithm with signature schemes solely based on symmetric techniques such as the Diffie-Lamport one-time signature scheme. These evaluations take into account all aspects of using digital signatures in wireless environments: energy consumption of key generation, signing and verification, and the communication cost of sending and receiving the necessary data (including the public keys and the necessary data to authenticate them).
Stefaan Seys, Bart Preneel
WiMob (1)2
2005 Recent attacks on alleged SecurID and their practical implications
Alex Biryukov, Joseph Lano, Bart Preneel
Comput. Secur.3
2005 Spectral characterization of cryptographic Boolean functions satisfying the (extended) propagation criterion of degree l and order k
Michaël Quisquater, Bart Preneel, Joos Vandewalle
Inf. Process. Lett.2
2005 On the covering radii of binary Reed-Muller codes in the set of resilient Boolean functions
abstract
Let R/sub t,n/ be the set of t-resilient Boolean functions in n variables, and let /spl rho//spl circ/(t,r,n) be the maximum distance between t-resilient functions and the rth-order Reed-Muller code RM(r,n). We prove that /spl rho//spl circ/(t,2,6)=16 for t=0,1,2 and /spl rho//spl circ/(3,2,7)=32, from which we derive the lower bound /spl rho//spl circ/(t,2,n) /spl ges/ 2/sup n-2/ with t /spl les/ n-4. Using a result from coding theory on the covering radius of (n-3)th- and (n-4)th-order Reed-Muller codes, we establish exact values of the covering radius of RM(n-3,n) in the set of 1-resilient Boolean functions in n variables, when /spl lfloor/n/2/spl rfloor/=1 mod 2 and lower bounds of RM(n-4,n) in the set of 2-resilient Boolean functions in n variables. This result leads again to different lower bounds for general dimensions n and r=0 or 3 mod 4.
Yuri L. Borissov, An Braeken, Svetla Nikova, Bart Preneel
IEEE Trans. Inf. Theory4
2004 The Biryukov-Demirci Attack on Reduced-Round Versions of IDEA and MESH Ciphers
Jorge Nakahara Jr., Bart Preneel, Joos Vandewalle
ACISP2
2004 Higher Order Universal One-Way Hash Functions
Deukjo Hong, Bart Preneel, Sangjin Lee 0002
ASIACRYPT2
2004 On Feistel Ciphers Using Optimal Diffusion Mappings Across Multiple Rounds
Taizo Shirai, Bart Preneel
ASIACRYPT2
2004 Power Analysis of an FPGA: Implementation of Rijndael: Is Pipelining a DPA Countermeasure?
François-Xavier Standaert, Siddika Berna Örs Yalçin, Bart Preneel
CHES3
2004 Power Analysis Attacks Against FPGA Implementations of the DES
François-Xavier Standaert, Siddika Berna Örs Yalçin, Jean-Jacques Quisquater, Bart Preneel
FPL4
2004 A New Weakness in the RC4 Keystream Generator and an Approach to Improve the Security of the Cipher
Souradyuti Paul, Bart Preneel
FSE2
2004 An FPGA implementation of an elliptic curve processor GF(2m)
abstract
This paper describes a hardware implementation of an arithmetic processor which is efficient for elliptic curve (EC) cryptosystems, which are becoming increasingly popular as an alternative for public key cryptosystems based on factoring. The modular multiplication is implemented using a Montgomery modular multiplication in a systolic array architecture, which has the advantage that the clock frequency becomes independent of the bit length m.
Nele Mentens, Siddika Berna Örs Yalçin, Bart Preneel
ACM Great Lakes Symposium on VLSI3
2004 Robust Metering Schemes for General Access Structures
Ventzislav Nikov, Svetla Nikova, Bart Preneel
ICICS3
2003 Multi-party Computation from Any Linear Secret Sharing Scheme Unconditionally Secure against Adaptive Adversary: The Zero-Error Case
Ventzislav Nikov, Svetla Nikova, Bart Preneel
ACNS3
2003 Hardware Implementation of an Elliptic Curve Processor over GF(p)
abstract
We describe a hardware implementation of an arithmetic processor which is efficient for bit-lengths suitable for both commonly used types of public key cryptography (PKC), i.e., elliptic curve (EC) and RSA cryptosystems. Montgomery modular multiplication in a systolic array architecture is used for modular multiplication. The processor consists of special operational blocks for Montgomery modular multiplication, modular addition/subtraction, EC point doubling/addition, modular multiplicative inversion, EC point multiplier, projective to affine coordinates conversion and Montgomery to normal representation conversion.
Siddika Berna Örs Yalçin, Lejla Batina, Bart Preneel, Joos Vandewalle
ASAP3
2003 Cryptanalysis of 3-Pass HAVAL
Bart Van Rompay, Alex Biryukov, Bart Preneel, Joos Vandewalle
ASIACRYPT3
2003 Power-Analysis Attacks on an FPGA - First Experimental Results
Siddika Berna Örs Yalçin, Elisabeth Oswald, Bart Preneel
CHES3
2003 A Toolbox for Cryptanalysis: Linear and Affine Equivalence Algorithms
Alex Biryukov, Christophe De Cannière, An Braeken, Bart Preneel
EUROCRYPT4
2003 Cryptanalysis of SOBER-t32
Steve Babbage, Christophe De Cannière, Joseph Lano, Bart Preneel, Joos Vandewalle
FSE4
2003 A Concrete Security Analysis for 3GPP-MAC
Dowon Hong, Ju-Sung Kang, Bart Preneel, Heuisu Ryu
FSE3
2003 On the Covering Radius of Second Order Binary Reed-Muller Code in the Set of Resilient Boolean Functions
Yuri L. Borissov, An Braeken, Svetla Nikova, Bart Preneel
IMACC4
2003 A Note on Weak Keys of PES, IDEA, and Some Extended Variants
Jorge Nakahara Jr., Bart Preneel, Joos Vandewalle
ISC2
2003 Towards a framework for evaluating certificate status information mechanisms
John Iliadis, Stefanos Gritzalis, Diomidis Spinellis, Danny De Cock, Bart Preneel, Dimitris Gritzalis
Comput. Commun.5
2003 Hardware architectures for public key cryptography
Lejla Batina, Siddika Berna Örs Yalçin, Bart Preneel, Joos Vandewalle
Integr.3
2003 A new inequality in discrete Fourier theory
abstract
Discrete Fourier theory has been applied successfully in digital communication theory. In this correspondence, we prove a new inequality linking the number of nonzero components of a complex valued function defined on a finite Abelian group to the number of nonzero components of its Fourier transform. We characterize the functions achieving equality. Finally, we compare this inequality applied to Boolean functions to the inequality arising from the minimal distance property of Reed-Muller codes.
Michaël Quisquater, Bart Preneel, Joos Vandewalle
IEEE Trans. Inf. Theory2
2003 (How) can mobile agents do secure electronic transactions on untrusted hosts? A survey of the security issues and the current solutions
abstract
This article investigates if and how mobile agents can execute secure electronic transactions on untrusted hosts. An overview of the security issues of mobile agents is first given. The problem of untrusted (i.e., potentially malicious) hosts is one of these issues, and appears to be the most difficult to solve. The current approaches to counter this problem are evaluated, and their relevance for secure electronic transactions is discussed. In particular, a state-of-the-art survey of mobile agent-based secure electronic transactions is presented.
Joris Claessens, Bart Preneel, Joos Vandewalle
ACM Trans. Internet Techn.2
2002 A New Keystream Generator MUGI
Dai Watanabe, Soichi Furuya, Hirotaka Yoshida, Kazuo Takaragi, Bart Preneel
FSE5
2002 New Weak-Key Classes of IDEA
Alex Biryukov, Jorge Nakahara Jr., Bart Preneel, Joos Vandewalle
ICICS3
2002 On the Security of Today's Online Electronic Banking Systems
Joris Claessens, Valentin Dem, Danny De Cock, Bart Preneel, Joos Vandewalle
Comput. Secur.4
2002 Construction of secure and fast hash functions using nonbinary error-correcting codes
abstract
This paper considers iterated hash functions. It proposes new constructions of fast and secure compression functions with nl-bit outputs for integers n>1 based on error-correcting codes and secure compression functions with l-bit outputs. This leads to simple and practical hash function constructions based on block ciphers such as the Data Encryption Standard (DES), where the key size is slightly smaller than the block size; IDEA, where the key size is twice the block size; Advanced Encryption Standard (AES), with a variable key size; and to MD4-like hash functions. Under reasonable assumptions about the underlying compression function and/or block cipher, it is proved that the new hash functions are collision resistant. More precisely, a lower bound is shown on the number of operations to find a collision as a function of the strength of the underlying compression function. Moreover, some new attacks are presented that essentially match the presented lower bounds. The constructions allow for a large degree of internal parallelism. The limits of this approach are studied in relation to bounds derived in coding theory.
Lars R. Knudsen, Bart Preneel
IEEE Trans. Inf. Theory2
2001 A Memory Efficient Version of Satoh's Algorithm
Frederik Vercauteren, Bart Preneel, Joos Vandewalle
EUROCRYPT2
2001 Improved SQUARE Attacks against Reduced-Round HIEROCRYPT
Paulo S. L. M. Barreto, Vincent Rijmen, Jorge Nakahara Jr., Bart Preneel, Joos Vandewalle, Hae Yong Kim
FSE4
2001 NESSIE: A European Approach to Evaluate Cryptographic Algorithms
abstract
The NESSIE project (New European Schemes for Signature, Integrity and Encryption) intends to put forward a portfolio containing the next generation of cryptographic primitives. These primitives will offer a higher security level than existing primitives, and/or will offer a higher confidence level, built up by an open evaluation process. Moreover, they should be better suited for the constraints of future hardware and software environments. In order to reach this goal, the project has launched an open call in March 2000. In response to this call, 39 primitives have been submitted by September 29, 2000, many of these from major players. Currently, the NESSIE evaluation process is under way; it considers both security and performance aspects. This article presents the status of the NESSIE project after 15 months. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves.
Bart Preneel
FSE1
2001 Producing Collisions for PANAMA
Vincent Rijmen, Bart Van Rompay, Bart Preneel, Joos Vandewalle
FSE3
2001 On Securely Scheduling a Meeting
T. Herlea, Joris Claessens, Bart Preneel, Gregory Neven, Frank Piessens, Bart De Decker
SEC3
2001 Cryptography on smart cards
Johan Borst, Bart Preneel, Vincent Rijmen
Comput. Networks2
2000 Evaluating certificate status information mechanisms
abstract
A wide spectrum of certificate revocation mechanisms is currently in use. A number of them have been proposed by standardisation bodies, while some others have originated from academic or private institutions. What is still missing is a systematic and robust framework for the sound evaluation of these mechanisms. We present a mechanism-neutral framework for the evaluation of mechanisms, which collect, process and distribute certificate status information. A detailed demonstration of its exploitation is also provided. The demonstration is mainly based on the evaluation of Certificate Revocation Lists, as well as of the Online Certificate Status Protocol.
John Iliadis, Diomidis Spinellis, Dimitris Gritzalis, Bart Preneel, Sokratis K. Katsikas
CCS4
2000 Linear Cryptanalysis of Reduced-Round Versions of the SAFER Block Cipher Family
Jorge Nakahara Jr., Bart Preneel, Joos Vandewalle
FSE2
2000 Authentication and Payment in Future Mobile Systems
abstract
This article presents an efficient public-key protocol for mutual authentication and key exchange designed for future mobile communications systems. The paper also demonstrates how a micropayment scheme can be integrated into the authentication proto
Günther Horn, Bart Preneel
J. Comput. Secur.2
1999 Equivalent Keys of HPC
Carl D'Halluin, Gert Bijnens, Bart Preneel, Vincent Rijmen
ASIACRYPT3
1999 Software Performance of Universal Hash Functions
abstract
This paper compares the parameters sizes and software performance of several recent constructions for universal hash functions: bucket hashing, polynomial hashing, Toeplitz hashing, division hashing, evaluation hashing, and MMH hashing. An objective comparison between these widely varying approaches is achieved by defining constructions that offer a comparable security level. It is also demonstrated how the security of these constructions compares favorably to existing MAC algorithms, the security of which is less understood.
Wim Nevelsteen, Bart Preneel
EUROCRYPT2
1999 Linear Cryptanalysis of RC5 and RC6
Johan Borst, Bart Preneel, Joos Vandewalle
FSE2
1999 Attack on Six Rounds of Crypton
Carl D'Halluin, Gert Bijnens, Vincent Rijmen, Bart Preneel
FSE4
1999 On the Security of Double and 2-Key Triple Modes of Operation
Helena Handschuh, Bart Preneel
FSE2
1999 State-of-the-art ciphers for commercial applications
Bart Preneel
Comput. Secur.1
1999 On the Security of Iterated Message Authentication Codes
abstract
The security of iterated message authentication code (MAC) algorithms is considered, and in particular, those constructed from unkeyed hash functions. A new MAC forgery attack applicable to all deterministic iterated MAC algorithms is presented, which requires on the order of 2/sup n/2/ known text-MAC pairs for algorithms with n bits of internal memory, as compared to the best previous general attack which required exhaustive key search. A related key-recovery attack is also given which applies to a large class of MAC algorithms including a strengthened version of CBC-MAC found in ANSI X9.19 and ISO/IEC 9797, and envelope MAC techniques such as "keyed MD5". The security of several related existing MACs based directly on unkeyed hash functions, including the secret prefix and secret suffix methods, is also examined.
Bart Preneel, Paul C. van Oorschot
IEEE Trans. Inf. Theory1
1998 Analysis Methods for (Alleged) RC4
Lars R. Knudsen, Willi Meier, Bart Preneel, Vincent Rijmen, Sven Verdoolaege
ASIACRYPT3
1998 Authentication and Payment in Future Mobile Systems
Günther Horn, Bart Preneel
ESORICS2
1998 An Introduction to Cryptology
Bart Preneel
SOFSEM1
1998 Attacks on Fast Double Block Length Hash Functions
Lars R. Knudsen, Xuejia Lai, Bart Preneel
J. Cryptol.3
1997 Fast and Secure Hashing Based on Codes
Lars R. Knudsen, Bart Preneel
CRYPTO2
1997 A Family of Trapdoor Ciphers
Vincent Rijmen, Bart Preneel
FSE2
1997 Hash Functions and MAC Algorithms Based on Block Ciphers
Bart Preneel
IMACC1
1997 On Weaknesses of Non-surjective Round Functions
Vincent Rijmen, Bart Preneel, Erik De Win
Des. Codes Cryptogr.2
1997 MACs and hash functions: State of the art
Bart Preneel
Inf. Secur. Tech. Rep.1
1996 Hash Functions Based on Block Ciphers and Quaternary Codes
Lars R. Knudsen, Bart Preneel
ASIACRYPT2
1996 On the Security of Two MAC Algorithms
Bart Preneel, Paul C. van Oorschot
EUROCRYPT1
1996 RIPEMD-160: A Strengthened Version of RIPEMD
Hans Dobbertin, Antoon Bosselaers, Bart Preneel
FSE3
1996 The Cipher SHARK
Vincent Rijmen, Joan Daemen, Bart Preneel, Antoon Bosselaers, Erik De Win
FSE3
1995 MDx-MAC and Building Fast MACs from Hash Functions
Bart Preneel, Paul C. van Oorschot
CRYPTO1
1994 FSE'94 - Introduction
Bart Preneel
FSE1
1994 Improved Characteristics for Differential Cryptanalysis of Hash Functions Based on Block Ciphers
Vincent Rijmen, Bart Preneel
FSE2
1994 Cryptanalysis of McGuffin
Vincent Rijmen, Bart Preneel
FSE2
1993 Differential Cryptanalysis of Hash Functions Based on Block Ciphers
abstract
This paper describes a differential attack on several hash functions based on a block cipher. The emphasis will be on the results for cases where DES [8] is the underlying block cipher. It will briefly discuss the case of FEAL-N [19, 21].
Bart Preneel, René Govaerts, Joos Vandewalle
CCS1
1993 Hash Functions Based on Block Ciphers: A Synthetic Approach
Bart Preneel, René Govaerts, Joos Vandewalle
CRYPTO1
1993 Cryptanalysis of the CFB Mode of the DES with a Reduced Number of Rounds
Bart Preneel, Marnix Nuttin, Vincent Rijmen, Johan Buelens
CRYPTO1
1993 Design Principles for Dedicated Hash Functions
Bart Preneel
FSE1
1990 Cryptanalysis of a fast cryptographic checksum algorithm
Bart Preneel, Antoon Bosselaers, René Govaerts, Joos Vandewalle
Comput. Secur.1
1989 A Chosen Text Attack on The Modified Cryptographic Checksum Algorithm of Cohen and Huang
Bart Preneel, Antoon Bosselaers, René Govaerts, Joos Vandewalle
CRYPTO1