The Experts below are selected from a list of 594 Experts worldwide ranked by ideXlab platform

Panos Papadimitratos - One of the best experts on this subject based on the ideXlab platform.

  • scalable resilient vehicle centric certificate revocation list distribution in vehicular communication systems
    arXiv: Cryptography and Security, 2020
    Co-Authors: Mohammad Khodaei, Panos Papadimitratos
    Abstract:

    In spite of progress in securing Vehicular Communication (VC) systems, there is no consensus on how to distribute certificate revocation lists (CRLs). The main challenges lie exactly in (i) crafting an efficient and timely distribution of CRLs for numerous anonymous credentials, pseudonyms, (ii) maintaining strong privacy for vehicles prior to revocation events, even with honest-but-curious system entities, (iii) and catering to computation and communication constraints of on-board units with intermittent connectivity to the infrastructure. Relying on peers to distribute the CRLs is a double-edged sword: abusive peers could "pollute" the process, thus degrading the timely CRLs distribution. In this paper, we propose a vehicle-centric solution that addresses all these challenges and thus closes a gap in the literature. Our scheme radically reduces CRL distribution overhead: each vehicle receives CRLs corresponding only to its region of operation and its actual trip duration. Moreover, a "fingerprint" of CRL 'pieces' is attached to a subset of (verifiable) pseudonyms for fast CRL 'piece' validation (while mitigating resource depletion attacks abusing the CRL distribution). Our experimental evaluation shows that our scheme is efficient, scalable, dependable, and practical: with no more than 25 KB/s of traffic load, the latest CRL can be delivered to 95% of the vehicles in a region (15 x 15 KM) within 15s, i.e., more than 40 times faster than the state-of-the-art. Overall, our scheme is a comprehensive solution that complements standards and can catalyze the deployment of secure and privacy-protecting VC systems.

  • Scalable & Resilient Vehicle-Centric certificate revocation list Distribution in Vehicular Communication Systems
    IEEE Transactions on Mobile Computing, 2020
    Co-Authors: Mohammad Khodaei, Panos Papadimitratos
    Abstract:

    In spite of progress in securing Vehicular Communication (VC) systems, there is no consensus on how to distribute certificate revocation lists (CRLs). The main challenges lie exactly in (i) crafting an efficient and timely distribution of CRLs for numerous anonymous credentials, pseudonyms, (ii) maintaining strong privacy for vehicles prior to revocation events, even with honest-but-curious system entities, (iii) and catering to computation and communication constraints of on-board units with intermittent connectivity to the infrastructure. Relying on peers to distribute the CRLs is a double-edged sword: abusive peers could "pollute" the process, thus degrading the timely CRLs distribution. In this paper, we propose a vehicle-centric solution that addresses all these challenges and thus closes a gap in the literature. Our scheme radically reduces CRL distribution overhead: each vehicle receives CRLs corresponding only to its region of operation and its actual trip duration. Moreover, a "fingerprint" of CRL 'pieces' is attached to a subset of (verifiable) pseudonyms for fast CRL 'piece' validation (while mitigating resource depletion attacks abusing the CRL distribution). Our experimental evaluation shows that our scheme is efficient, scalable, dependable, and practical: with no more than 25 KB/s of traffic load, the latest CRL can be delivered to 95% of the vehicles in a region (15 x 15 KM) within 15s, i.e., more than 40 times faster than the state-of-the-art. Overall, our scheme is a comprehensive solution that complements standards and can catalyze the deployment of secure and privacy-protecting VC systems.

  • efficient scalable and resilient vehicle centric certificate revocation list distribution in vanets
    Wireless Network Security, 2018
    Co-Authors: Mohammad Khodaei, Panos Papadimitratos
    Abstract:

    In spite of progress in securing Vehicular Communication (VC) systems, there is no consensus on how to distribute certificate revocation lists (CRLs). The main challenges lie exactly in (i) crafting an efficient and timely distribution of CRLs for numerous anonymous credentials, pseudonyms, (ii) maintaining strong privacy for vehicles prior to revocation events, even with honest-but-curious system entities, (iii) and catering to computation and communication constraints of on-board units with intermittent connectivity to the infrastructure. Relying on peers to distribute the CRLs is a double-edged sword: abusive peers could "pollute" the process, thus degrading the timely CRLs distribution. In this paper, we propose a vehicle-centric solution that addresses all these challenges and thus closes a gap in the literature. Our scheme radically reduces CRL distribution overhead: each vehicle receives CRLs corresponding only to its region of operation and its actual trip duration. Moreover, a "fingerprint" of CRL 'pieces' is attached to a subset of (verifiable) pseudonyms for fast CRL 'piece' validation (while mitigating resource depletion attacks abusing the CRL distribution). Our experimental evaluation shows that our scheme is efficient, scalable, dependable, and practical: with no more than 25 KB/s of traffic load, the latest CRL can be delivered to 95% of the vehicles in a region (50x50 KM) within 15s, i.e., more than 40 times faster than the state-of-the-art. Overall, our scheme is a comprehensive solution that complements standards and can catalyze the deployment of secure and privacy-protecting VC systems.

  • WISEC - Efficient, Scalable, and Resilient Vehicle-Centric certificate revocation list Distribution in VANETs
    Proceedings of the 11th ACM Conference on Security & Privacy in Wireless and Mobile Networks, 2018
    Co-Authors: Mohammad Khodaei, Panos Papadimitratos
    Abstract:

    In spite of progress in securing Vehicular Communication (VC) systems, there is no consensus on how to distribute certificate revocation lists (CRLs). The main challenges lie exactly in (i) crafting an efficient and timely distribution of CRLs for numerous anonymous credentials, pseudonyms, (ii) maintaining strong privacy for vehicles prior to revocation events, even with honest-but-curious system entities, (iii) and catering to computation and communication constraints of on-board units with intermittent connectivity to the infrastructure. Relying on peers to distribute the CRLs is a double-edged sword: abusive peers could "pollute" the process, thus degrading the timely CRLs distribution. In this paper, we propose a vehicle-centric solution that addresses all these challenges and thus closes a gap in the literature. Our scheme radically reduces CRL distribution overhead: each vehicle receives CRLs corresponding only to its region of operation and its actual trip duration. Moreover, a "fingerprint" of CRL 'pieces' is attached to a subset of (verifiable) pseudonyms for fast CRL 'piece' validation (while mitigating resource depletion attacks abusing the CRL distribution). Our experimental evaluation shows that our scheme is efficient, scalable, dependable, and practical: with no more than 25 KB/s of traffic load, the latest CRL can be delivered to 95% of the vehicles in a region (50x50 KM) within 15s, i.e., more than 40 times faster than the state-of-the-art. Overall, our scheme is a comprehensive solution that complements standards and can catalyze the deployment of secure and privacy-protecting VC systems.

Mohammad Khodaei - One of the best experts on this subject based on the ideXlab platform.

  • scalable resilient vehicle centric certificate revocation list distribution in vehicular communication systems
    arXiv: Cryptography and Security, 2020
    Co-Authors: Mohammad Khodaei, Panos Papadimitratos
    Abstract:

    In spite of progress in securing Vehicular Communication (VC) systems, there is no consensus on how to distribute certificate revocation lists (CRLs). The main challenges lie exactly in (i) crafting an efficient and timely distribution of CRLs for numerous anonymous credentials, pseudonyms, (ii) maintaining strong privacy for vehicles prior to revocation events, even with honest-but-curious system entities, (iii) and catering to computation and communication constraints of on-board units with intermittent connectivity to the infrastructure. Relying on peers to distribute the CRLs is a double-edged sword: abusive peers could "pollute" the process, thus degrading the timely CRLs distribution. In this paper, we propose a vehicle-centric solution that addresses all these challenges and thus closes a gap in the literature. Our scheme radically reduces CRL distribution overhead: each vehicle receives CRLs corresponding only to its region of operation and its actual trip duration. Moreover, a "fingerprint" of CRL 'pieces' is attached to a subset of (verifiable) pseudonyms for fast CRL 'piece' validation (while mitigating resource depletion attacks abusing the CRL distribution). Our experimental evaluation shows that our scheme is efficient, scalable, dependable, and practical: with no more than 25 KB/s of traffic load, the latest CRL can be delivered to 95% of the vehicles in a region (15 x 15 KM) within 15s, i.e., more than 40 times faster than the state-of-the-art. Overall, our scheme is a comprehensive solution that complements standards and can catalyze the deployment of secure and privacy-protecting VC systems.

  • Scalable & Resilient Vehicle-Centric certificate revocation list Distribution in Vehicular Communication Systems
    IEEE Transactions on Mobile Computing, 2020
    Co-Authors: Mohammad Khodaei, Panos Papadimitratos
    Abstract:

    In spite of progress in securing Vehicular Communication (VC) systems, there is no consensus on how to distribute certificate revocation lists (CRLs). The main challenges lie exactly in (i) crafting an efficient and timely distribution of CRLs for numerous anonymous credentials, pseudonyms, (ii) maintaining strong privacy for vehicles prior to revocation events, even with honest-but-curious system entities, (iii) and catering to computation and communication constraints of on-board units with intermittent connectivity to the infrastructure. Relying on peers to distribute the CRLs is a double-edged sword: abusive peers could "pollute" the process, thus degrading the timely CRLs distribution. In this paper, we propose a vehicle-centric solution that addresses all these challenges and thus closes a gap in the literature. Our scheme radically reduces CRL distribution overhead: each vehicle receives CRLs corresponding only to its region of operation and its actual trip duration. Moreover, a "fingerprint" of CRL 'pieces' is attached to a subset of (verifiable) pseudonyms for fast CRL 'piece' validation (while mitigating resource depletion attacks abusing the CRL distribution). Our experimental evaluation shows that our scheme is efficient, scalable, dependable, and practical: with no more than 25 KB/s of traffic load, the latest CRL can be delivered to 95% of the vehicles in a region (15 x 15 KM) within 15s, i.e., more than 40 times faster than the state-of-the-art. Overall, our scheme is a comprehensive solution that complements standards and can catalyze the deployment of secure and privacy-protecting VC systems.

  • scalable a resilient vehicle centric certificate revocation list distribution in vehicular communication systems
    IEEE Transactions on Mobile Computing, 2020
    Co-Authors: Mohammad Khodaei, Panos Papadimitratos
    Abstract:

    In spite of progress in securing Vehicular Communication (VC) systems, there is no consensus on how to distribute certificate revocation lists (CRLs). The main challenges lie exactly in (i) craftin ...

  • efficient scalable and resilient vehicle centric certificate revocation list distribution in vanets
    Wireless Network Security, 2018
    Co-Authors: Mohammad Khodaei, Panos Papadimitratos
    Abstract:

    In spite of progress in securing Vehicular Communication (VC) systems, there is no consensus on how to distribute certificate revocation lists (CRLs). The main challenges lie exactly in (i) crafting an efficient and timely distribution of CRLs for numerous anonymous credentials, pseudonyms, (ii) maintaining strong privacy for vehicles prior to revocation events, even with honest-but-curious system entities, (iii) and catering to computation and communication constraints of on-board units with intermittent connectivity to the infrastructure. Relying on peers to distribute the CRLs is a double-edged sword: abusive peers could "pollute" the process, thus degrading the timely CRLs distribution. In this paper, we propose a vehicle-centric solution that addresses all these challenges and thus closes a gap in the literature. Our scheme radically reduces CRL distribution overhead: each vehicle receives CRLs corresponding only to its region of operation and its actual trip duration. Moreover, a "fingerprint" of CRL 'pieces' is attached to a subset of (verifiable) pseudonyms for fast CRL 'piece' validation (while mitigating resource depletion attacks abusing the CRL distribution). Our experimental evaluation shows that our scheme is efficient, scalable, dependable, and practical: with no more than 25 KB/s of traffic load, the latest CRL can be delivered to 95% of the vehicles in a region (50x50 KM) within 15s, i.e., more than 40 times faster than the state-of-the-art. Overall, our scheme is a comprehensive solution that complements standards and can catalyze the deployment of secure and privacy-protecting VC systems.

  • WISEC - Efficient, Scalable, and Resilient Vehicle-Centric certificate revocation list Distribution in VANETs
    Proceedings of the 11th ACM Conference on Security & Privacy in Wireless and Mobile Networks, 2018
    Co-Authors: Mohammad Khodaei, Panos Papadimitratos
    Abstract:

    In spite of progress in securing Vehicular Communication (VC) systems, there is no consensus on how to distribute certificate revocation lists (CRLs). The main challenges lie exactly in (i) crafting an efficient and timely distribution of CRLs for numerous anonymous credentials, pseudonyms, (ii) maintaining strong privacy for vehicles prior to revocation events, even with honest-but-curious system entities, (iii) and catering to computation and communication constraints of on-board units with intermittent connectivity to the infrastructure. Relying on peers to distribute the CRLs is a double-edged sword: abusive peers could "pollute" the process, thus degrading the timely CRLs distribution. In this paper, we propose a vehicle-centric solution that addresses all these challenges and thus closes a gap in the literature. Our scheme radically reduces CRL distribution overhead: each vehicle receives CRLs corresponding only to its region of operation and its actual trip duration. Moreover, a "fingerprint" of CRL 'pieces' is attached to a subset of (verifiable) pseudonyms for fast CRL 'piece' validation (while mitigating resource depletion attacks abusing the CRL distribution). Our experimental evaluation shows that our scheme is efficient, scalable, dependable, and practical: with no more than 25 KB/s of traffic load, the latest CRL can be delivered to 95% of the vehicles in a region (50x50 KM) within 15s, i.e., more than 40 times faster than the state-of-the-art. Overall, our scheme is a comprehensive solution that complements standards and can catalyze the deployment of secure and privacy-protecting VC systems.

Henry L. Owen - One of the best experts on this subject based on the ideXlab platform.

  • certificate revocation list distribution in vanets using most pieces broadcast
    SoutheastCon, 2010
    Co-Authors: Michael Nowatkowski, Henry L. Owen
    Abstract:

    This paper describes a novel idea for distributing certificate revocation lists (CRLs) in a vehicular ad hoc network (VANET) scenario. The idea, Most Pieces Broadcast (MPB), takes advantage of the two distinct channel types in VANETs while reducing contention for the wireless medium. Broadcast methods that reduce wireless medium contention in VANETs are highly desirable to assist in keeping the medium available for transmission of time-critical safety messages. MPB scales remarkably well using raptor coding to generate redundant file pieces.

  • The effects of limited lifetime pseudonyms on certificate revocation list size in VANETS
    Proceedings of the IEEE SoutheastCon 2010 (SoutheastCon), 2010
    Co-Authors: Michael Nowatkowski, Chris Mcmanus, Jennie E. Wolfgang, Henry L. Owen
    Abstract:

    Concerns for VANET participants will be the reliability and trustworthiness of received messages and the privacy in the use of the VANET to prevent vehicle tracking. To address these concerns, public key certificates have been standardized for VANETS; however, with the use of public key certificates comes additional concerns, especially how to ensure that received certificates are valid. To achieve this aim, timely distribution of certificate revocation lists (CRLs) to VANET participants will be essential. Depending on the policies for the number of pseudonyms carried by vehicles and the triggers for revoking certificates, the size of the CRL may grow very quickly. This paper investigates the parameters that determine the sizes of CRLs in an attempt to quantify the scope of CRL distribution challenges. We also propose adding a "valid after" field to the WAVE certificate in the IEEE Trial-Use Standard 1609.2 to reduce some of the large CRL sizes we discovered.

  • Scalable certificate revocation list distribution in vehicular ad hoc networks
    2010 IEEE Globecom Workshops GC'10, 2010
    Co-Authors: Michael E. Nowatkowski, Henry L. Owen
    Abstract:

    In this paper, the primary objective is to discuss the details of scalable methods for distributing certificate revocation lists and other large files using vehicle-to-vehicle and vehicle-to-infrastructure communications while taking advantage of the multi-channel operations in IEEE 1609.4. We also discuss the results from a simulation study using the ns-3 network simulator to closely replicate the WAVE environment discussed in the IEEE 802.11p and 1609 draft standards. Realistic vehicle traces were used in the simulation study. The results show that the methods developed in this research scale very well for increasing vehicle densities.

  • certificate revocation list distribution in vehicular ad hoc networks
    2010
    Co-Authors: Henry L. Owen, Michael Nowatkowski
    Abstract:

    The objective of this research is to investigate improved methods for distributing certificate revocation lists (CRLs) in vehicular ad hoc networks (VANETs). VANETs are a subset of mobile ad hoc networks composed of network-equipped vehicles and infrastructure points, which will allow vehicles to communicate with other vehicles and with roadside infrastructure points. While sharing some of the same limitations of mobile ad hoc networks, such as lack of infrastructure and limited communications range, VANETs have several dissimilarities that make them a much different research area. The main differences include the size of the network, the speed of the vehicles, and the network security concerns. Confidentiality, authenticity, integrity, and availability are some of the standard goals of network security. While confidentiality and authenticity at times seem in opposition to each other, VANET researchers have developed many methods for enhancing confidentiality while at the same time providing authenticity. The method agreed upon for confidentiality and authenticity by most researchers and the IEEE 1609 working group is a public key infrastructure (PKI) system. An important part of any PKI system is the revocation of certificates. The revocation process, as well as the distribution of revocation information, is an open research problem for VANETs. This research develops new methods of CRL distribution and compares them to existing methods proposed by other researchers. The new methods show improved performance in various vehicle traffic densities.

  • ADHOCNETS - Cooperative certificate revocation list distribution methods in VANETs
    Ad Hoc Networks, 2010
    Co-Authors: Michael Nowatkowski, Chris Mcmanus, Jennie E. Wolfgang, Henry L. Owen
    Abstract:

    This paper discusses two new methods for distributing certificate revocation lists (CRL) in a vehicular ad hoc network environment using cooperative methods. The main purpose for using cooperative methods is to attempt to reduce the number of collisions in the dedicated short range communication (DSRC) broadcast environment. The reduced number of collisions will increase the effective throughput of the medium. The first method uses a polling scheme to determine which nodes possess the most number of CRL file pieces. The second method takes advantage of the multiple service channels available in DSRC. Both methods use a form of coding that reduces the impact of the piece problem. Both methods are compared to the Code Torrent method of file distribution.

Panos Papadimitratos - One of the best experts on this subject based on the ideXlab platform.

Jj Jason J. Haas - One of the best experts on this subject based on the ideXlab platform.

  • Efficient certificate revocation list organization and distribution
    IEEE Journal on Selected Areas in Communications, 2011
    Co-Authors: Jj Jason J. Haas, Yih-chun Hu, Kenneth P. Laberteaux
    Abstract:

    In this paper, we propose a lightweight mechanism for revoking security certificates that is appropriate for the limited bandwidth and hardware cost constraints of a VANET. A certificate Authority (CA) issues certificates to trusted nodes, i.e., vehicles. If the CA looses trust in a vehicle (e.g., due to evidence of malfunction or malicious behavior), the CA must promptly revoke the certificates of the distrusted vehicle. To distribute revocation information quickly even during incremental deployment, we propose that CAs use certificate revocation lists (CRLs). The CRL should be composed in a secure manner, and it should be exchanged in a way such that the CRL is both quickly and widely distributed. We previously proposed a mechanism for the quick distribution of CRL updates that also covers a wide area by using vehicle-to-vehicle (V2V) communication . In this paper, we additionally investigate the performance of V2V communication in partial deployment scenarios, that is, where only a certain percentage of vehicles are equipped with VANET radios. We provide simulation results that show our V2V exchange mechanism is quicker than distributing CRLs or CRL updates through road-side units (RSUs) alone. However, this revocation process, which involves both the CA and vehicles, must conform to the aforementioned bandwidth and hardware restrictions. In this paper, we present mechanisms that achieve the goals of reduced CRL size, a computationally efficient mechanism for determining if a certificate is on the CRL, and a lightweight mechanism for exchanging CRL updates. Additionally, we expand on our previous work to provide privacy to revoked vehicles prior to their revocation.

  • Vehicular Ad Hoc Networks - Security certificate revocation list distribution for vanet
    Proceedings of the fifth ACM international workshop on VehiculAr Inter-NETworking - VANET '08, 2008
    Co-Authors: Kenneth P. Laberteaux, Jj Jason J. Haas
    Abstract:

    In a VANET, a certificate authority issues keys and certificates to vehicles. Each vehicle distributes these certificates to other VANET participants and subsequently signs messages against these certificates. If the certificate authority needs to revoke a certificate (e.g. due to a breach of trust), it universally distributes a certificate revocation list. We propose a method for car-to-car epidemic distribution of certificate revocation lists which is quick and efficient. Large-scale simulations based on realistic mobility traces show that this epidemic model significantly outperforms methods that only employ road side unit distribution points.