The Experts below are selected from a list of 19989 Experts worldwide ranked by ideXlab platform

Frank Piessens - One of the best experts on this subject based on the ideXlab platform.

  • Open access to the Proceedings of the 22nd USENIX Security Symposium is sponsored by USENIX Sancus: Low-cost Trustworthy Extensible Networked Devices with a Zero-Software Trusted Computing Base Sancus: Low-cost trustworthy extensible networked devices wit
    2020
    Co-Authors: Job Noorman, Pieter Agten, Wilfried Daniels, Raoul Strackx, Christophe Huygens, Frank Piessens, Bart Preneel, Ingrid Verbauwhede, Anthony Van Herrewege, K U Leuven
    Abstract:

    Abstract In this paper we propose Sancus, a security architecture for networked embedded devices. Sancus supports extensibility in the form of remote (even third-Party) Software installation on devices while maintaining strong security guarantees. More specifically, Sancus can remotely attest to a Software provider that a specific Software module is running uncompromised, and can authenticate messages from Software modules to Software providers. Software modules can securely maintain local state, and can securely interact with other Software modules that they choose to trust. The most distinguishing feature of Sancus is that it achieves these security guarantees without trusting any infrastructural Software on the device. The Trusted Computing Base (TCB) on the device is only the hardware. Moreover, the hardware cost of Sancus is low. We describe the design of Sancus, and develop and evaluate a prototype FPGA implementation of a Sancusenabled device. The prototype extends an MSP430 processor with hardware support for the memory access control and cryptographic functionality required to run Sancus. We also develop a C compiler that targets our device and that can compile standard C modules to Sancus protected Software modules

  • sancus 2 0 a low cost security architecture for iot devices
    ACM Transactions on Privacy and Security (TOPS), 2017
    Co-Authors: Job Noorman, Frank Piessens, Bart Preneel, Ingrid Verbauwhede, Jo Van Bulck, Jan Tobias Muhlberg, Pieter Maene, Johannes Gotzfried, Tilo Muller, Felix C Freiling
    Abstract:

    The Sancus security architecture for networked embedded devices was proposed in 2013 at the USENIX Security conference. It supports remote (even third-Party) Software installation on devices while maintaining strong security guarantees. More specifically, Sancus can remotely attest to a Software provider that a specific Software module is running uncompromised and can provide a secure communication channel between Software modules and Software providers. Software modules can securely maintain local state and can securely interact with other Software modules that they choose to trust. Over the past three years, significant experience has been gained with applications of Sancus, and several extensions of the architecture have been investigated—both by the original designers as well as by independent researchers. Informed by these additional research results, this journal version of the Sancus paper describes an improved design and implementation, supporting additional security guarantees (such as confidential deployment) and a more efficient cryptographic core. We describe the design of Sancus 2.0 (without relying on any prior knowledge of Sancus) and develop and evaluate a prototype FPGA implementation. The prototype extends an MSP430 processor with hardware support for the memory access control and cryptographic functionality required to run Sancus. We report on our experience using Sancus in a variety of application scenarios and discuss some important avenues of ongoing and future work.

  • sancus low cost trustworthy extensible networked devices with a zero Software trusted computing base
    USENIX Security Symposium, 2013
    Co-Authors: Job Noorman, Pieter Agten, Wilfried Daniels, Raoul Strackx, Christophe Huygens, Anthony Van Herrewege, Bart Preneel, Ingrid Verbauwhede, Frank Piessens
    Abstract:

    In this paper we propose Sancus, a security architecture for networked embedded devices. Sancus supports extensibility in the form of remote (even third-Party) Software installation on devices while maintaining strong security guarantees. More specifically, Sancus can remotely attest to a Software provider that a specific Software module is running uncompromised, and can authenticate messages from Software modules to Software providers. Software modules can securely maintain local state, and can securely interact with other Software modules that they choose to trust. The most distinguishing feature of Sancus is that it achieves these security guarantees without trusting any infrastructural Software on the device. The Trusted Computing Base (TCB) on the device is only the hardware. Moreover, the hardware cost of Sancus is low. We describe the design of Sancus, and develop and evaluate a prototype FPGA implementation of a Sancus-enabled device. The prototype extends an MSP430 processor with hardware support for the memory access control and cryptographic functionality required to run Sancus. We also develop a C compiler that targets our device and that can compile standard C modules to Sancus protected Software modules.

Job Noorman - One of the best experts on this subject based on the ideXlab platform.

  • Open access to the Proceedings of the 22nd USENIX Security Symposium is sponsored by USENIX Sancus: Low-cost Trustworthy Extensible Networked Devices with a Zero-Software Trusted Computing Base Sancus: Low-cost trustworthy extensible networked devices wit
    2020
    Co-Authors: Job Noorman, Pieter Agten, Wilfried Daniels, Raoul Strackx, Christophe Huygens, Frank Piessens, Bart Preneel, Ingrid Verbauwhede, Anthony Van Herrewege, K U Leuven
    Abstract:

    Abstract In this paper we propose Sancus, a security architecture for networked embedded devices. Sancus supports extensibility in the form of remote (even third-Party) Software installation on devices while maintaining strong security guarantees. More specifically, Sancus can remotely attest to a Software provider that a specific Software module is running uncompromised, and can authenticate messages from Software modules to Software providers. Software modules can securely maintain local state, and can securely interact with other Software modules that they choose to trust. The most distinguishing feature of Sancus is that it achieves these security guarantees without trusting any infrastructural Software on the device. The Trusted Computing Base (TCB) on the device is only the hardware. Moreover, the hardware cost of Sancus is low. We describe the design of Sancus, and develop and evaluate a prototype FPGA implementation of a Sancusenabled device. The prototype extends an MSP430 processor with hardware support for the memory access control and cryptographic functionality required to run Sancus. We also develop a C compiler that targets our device and that can compile standard C modules to Sancus protected Software modules

  • sancus 2 0 a low cost security architecture for iot devices
    ACM Transactions on Privacy and Security (TOPS), 2017
    Co-Authors: Job Noorman, Frank Piessens, Bart Preneel, Ingrid Verbauwhede, Jo Van Bulck, Jan Tobias Muhlberg, Pieter Maene, Johannes Gotzfried, Tilo Muller, Felix C Freiling
    Abstract:

    The Sancus security architecture for networked embedded devices was proposed in 2013 at the USENIX Security conference. It supports remote (even third-Party) Software installation on devices while maintaining strong security guarantees. More specifically, Sancus can remotely attest to a Software provider that a specific Software module is running uncompromised and can provide a secure communication channel between Software modules and Software providers. Software modules can securely maintain local state and can securely interact with other Software modules that they choose to trust. Over the past three years, significant experience has been gained with applications of Sancus, and several extensions of the architecture have been investigated—both by the original designers as well as by independent researchers. Informed by these additional research results, this journal version of the Sancus paper describes an improved design and implementation, supporting additional security guarantees (such as confidential deployment) and a more efficient cryptographic core. We describe the design of Sancus 2.0 (without relying on any prior knowledge of Sancus) and develop and evaluate a prototype FPGA implementation. The prototype extends an MSP430 processor with hardware support for the memory access control and cryptographic functionality required to run Sancus. We report on our experience using Sancus in a variety of application scenarios and discuss some important avenues of ongoing and future work.

  • sancus low cost trustworthy extensible networked devices with a zero Software trusted computing base
    USENIX Security Symposium, 2013
    Co-Authors: Job Noorman, Pieter Agten, Wilfried Daniels, Raoul Strackx, Christophe Huygens, Anthony Van Herrewege, Bart Preneel, Ingrid Verbauwhede, Frank Piessens
    Abstract:

    In this paper we propose Sancus, a security architecture for networked embedded devices. Sancus supports extensibility in the form of remote (even third-Party) Software installation on devices while maintaining strong security guarantees. More specifically, Sancus can remotely attest to a Software provider that a specific Software module is running uncompromised, and can authenticate messages from Software modules to Software providers. Software modules can securely maintain local state, and can securely interact with other Software modules that they choose to trust. The most distinguishing feature of Sancus is that it achieves these security guarantees without trusting any infrastructural Software on the device. The Trusted Computing Base (TCB) on the device is only the hardware. Moreover, the hardware cost of Sancus is low. We describe the design of Sancus, and develop and evaluate a prototype FPGA implementation of a Sancus-enabled device. The prototype extends an MSP430 processor with hardware support for the memory access control and cryptographic functionality required to run Sancus. We also develop a C compiler that targets our device and that can compile standard C modules to Sancus protected Software modules.

Jean-pierre Attal - One of the best experts on this subject based on the ideXlab platform.

  • understanding dental cad cam for restorations dental milling machines from a mechanical engineering viewpoint part a chairside milling machines
    International journal of computerized dentistry, 2016
    Co-Authors: Nicolas Lebon, Laurent Tapie, Francois Duret, Jean-pierre Attal
    Abstract:

    Nowadays, dental numerical controlled (NC) milling machines are available for dental laboratories (labside solution) and dental production centers. This article provides a mechanical engineering approach to NC milling machines to help dental technicians understand the involvement of technology in digital dentistry practice. The technical and economic criteria are described for four labside and two production center dental NC milling machines available on the market. The technical criteria are focused on the capacities of the embedded technologies of milling machines to mill prosthetic materials and various restoration shapes. The economic criteria are focused on investment cost and interoperability with third-Party Software. The clinical relevance of the technology is discussed through the accuracy and integrity of the restoration. It can be asserted that dental production center milling machines offer a wider range of materials and types of restoration shapes than labside solutions, while labside solutions offer a wider range than chairside solutions. The accuracy and integrity of restorations may be improved as a function of the embedded technologies provided. However, the more complex the technical solutions available, the more skilled the user must be. Investment cost and interoperability with third-Party Software increase according to the quality of the embedded technologies implemented. Each private dental practice may decide which fabrication option to use depending on the scope of the practice.

Bart Preneel - One of the best experts on this subject based on the ideXlab platform.

  • Open access to the Proceedings of the 22nd USENIX Security Symposium is sponsored by USENIX Sancus: Low-cost Trustworthy Extensible Networked Devices with a Zero-Software Trusted Computing Base Sancus: Low-cost trustworthy extensible networked devices wit
    2020
    Co-Authors: Job Noorman, Pieter Agten, Wilfried Daniels, Raoul Strackx, Christophe Huygens, Frank Piessens, Bart Preneel, Ingrid Verbauwhede, Anthony Van Herrewege, K U Leuven
    Abstract:

    Abstract In this paper we propose Sancus, a security architecture for networked embedded devices. Sancus supports extensibility in the form of remote (even third-Party) Software installation on devices while maintaining strong security guarantees. More specifically, Sancus can remotely attest to a Software provider that a specific Software module is running uncompromised, and can authenticate messages from Software modules to Software providers. Software modules can securely maintain local state, and can securely interact with other Software modules that they choose to trust. The most distinguishing feature of Sancus is that it achieves these security guarantees without trusting any infrastructural Software on the device. The Trusted Computing Base (TCB) on the device is only the hardware. Moreover, the hardware cost of Sancus is low. We describe the design of Sancus, and develop and evaluate a prototype FPGA implementation of a Sancusenabled device. The prototype extends an MSP430 processor with hardware support for the memory access control and cryptographic functionality required to run Sancus. We also develop a C compiler that targets our device and that can compile standard C modules to Sancus protected Software modules

  • sancus 2 0 a low cost security architecture for iot devices
    ACM Transactions on Privacy and Security (TOPS), 2017
    Co-Authors: Job Noorman, Frank Piessens, Bart Preneel, Ingrid Verbauwhede, Jo Van Bulck, Jan Tobias Muhlberg, Pieter Maene, Johannes Gotzfried, Tilo Muller, Felix C Freiling
    Abstract:

    The Sancus security architecture for networked embedded devices was proposed in 2013 at the USENIX Security conference. It supports remote (even third-Party) Software installation on devices while maintaining strong security guarantees. More specifically, Sancus can remotely attest to a Software provider that a specific Software module is running uncompromised and can provide a secure communication channel between Software modules and Software providers. Software modules can securely maintain local state and can securely interact with other Software modules that they choose to trust. Over the past three years, significant experience has been gained with applications of Sancus, and several extensions of the architecture have been investigated—both by the original designers as well as by independent researchers. Informed by these additional research results, this journal version of the Sancus paper describes an improved design and implementation, supporting additional security guarantees (such as confidential deployment) and a more efficient cryptographic core. We describe the design of Sancus 2.0 (without relying on any prior knowledge of Sancus) and develop and evaluate a prototype FPGA implementation. The prototype extends an MSP430 processor with hardware support for the memory access control and cryptographic functionality required to run Sancus. We report on our experience using Sancus in a variety of application scenarios and discuss some important avenues of ongoing and future work.

  • sancus low cost trustworthy extensible networked devices with a zero Software trusted computing base
    USENIX Security Symposium, 2013
    Co-Authors: Job Noorman, Pieter Agten, Wilfried Daniels, Raoul Strackx, Christophe Huygens, Anthony Van Herrewege, Bart Preneel, Ingrid Verbauwhede, Frank Piessens
    Abstract:

    In this paper we propose Sancus, a security architecture for networked embedded devices. Sancus supports extensibility in the form of remote (even third-Party) Software installation on devices while maintaining strong security guarantees. More specifically, Sancus can remotely attest to a Software provider that a specific Software module is running uncompromised, and can authenticate messages from Software modules to Software providers. Software modules can securely maintain local state, and can securely interact with other Software modules that they choose to trust. The most distinguishing feature of Sancus is that it achieves these security guarantees without trusting any infrastructural Software on the device. The Trusted Computing Base (TCB) on the device is only the hardware. Moreover, the hardware cost of Sancus is low. We describe the design of Sancus, and develop and evaluate a prototype FPGA implementation of a Sancus-enabled device. The prototype extends an MSP430 processor with hardware support for the memory access control and cryptographic functionality required to run Sancus. We also develop a C compiler that targets our device and that can compile standard C modules to Sancus protected Software modules.

Ingrid Verbauwhede - One of the best experts on this subject based on the ideXlab platform.

  • Open access to the Proceedings of the 22nd USENIX Security Symposium is sponsored by USENIX Sancus: Low-cost Trustworthy Extensible Networked Devices with a Zero-Software Trusted Computing Base Sancus: Low-cost trustworthy extensible networked devices wit
    2020
    Co-Authors: Job Noorman, Pieter Agten, Wilfried Daniels, Raoul Strackx, Christophe Huygens, Frank Piessens, Bart Preneel, Ingrid Verbauwhede, Anthony Van Herrewege, K U Leuven
    Abstract:

    Abstract In this paper we propose Sancus, a security architecture for networked embedded devices. Sancus supports extensibility in the form of remote (even third-Party) Software installation on devices while maintaining strong security guarantees. More specifically, Sancus can remotely attest to a Software provider that a specific Software module is running uncompromised, and can authenticate messages from Software modules to Software providers. Software modules can securely maintain local state, and can securely interact with other Software modules that they choose to trust. The most distinguishing feature of Sancus is that it achieves these security guarantees without trusting any infrastructural Software on the device. The Trusted Computing Base (TCB) on the device is only the hardware. Moreover, the hardware cost of Sancus is low. We describe the design of Sancus, and develop and evaluate a prototype FPGA implementation of a Sancusenabled device. The prototype extends an MSP430 processor with hardware support for the memory access control and cryptographic functionality required to run Sancus. We also develop a C compiler that targets our device and that can compile standard C modules to Sancus protected Software modules

  • sancus 2 0 a low cost security architecture for iot devices
    ACM Transactions on Privacy and Security (TOPS), 2017
    Co-Authors: Job Noorman, Frank Piessens, Bart Preneel, Ingrid Verbauwhede, Jo Van Bulck, Jan Tobias Muhlberg, Pieter Maene, Johannes Gotzfried, Tilo Muller, Felix C Freiling
    Abstract:

    The Sancus security architecture for networked embedded devices was proposed in 2013 at the USENIX Security conference. It supports remote (even third-Party) Software installation on devices while maintaining strong security guarantees. More specifically, Sancus can remotely attest to a Software provider that a specific Software module is running uncompromised and can provide a secure communication channel between Software modules and Software providers. Software modules can securely maintain local state and can securely interact with other Software modules that they choose to trust. Over the past three years, significant experience has been gained with applications of Sancus, and several extensions of the architecture have been investigated—both by the original designers as well as by independent researchers. Informed by these additional research results, this journal version of the Sancus paper describes an improved design and implementation, supporting additional security guarantees (such as confidential deployment) and a more efficient cryptographic core. We describe the design of Sancus 2.0 (without relying on any prior knowledge of Sancus) and develop and evaluate a prototype FPGA implementation. The prototype extends an MSP430 processor with hardware support for the memory access control and cryptographic functionality required to run Sancus. We report on our experience using Sancus in a variety of application scenarios and discuss some important avenues of ongoing and future work.

  • sancus low cost trustworthy extensible networked devices with a zero Software trusted computing base
    USENIX Security Symposium, 2013
    Co-Authors: Job Noorman, Pieter Agten, Wilfried Daniels, Raoul Strackx, Christophe Huygens, Anthony Van Herrewege, Bart Preneel, Ingrid Verbauwhede, Frank Piessens
    Abstract:

    In this paper we propose Sancus, a security architecture for networked embedded devices. Sancus supports extensibility in the form of remote (even third-Party) Software installation on devices while maintaining strong security guarantees. More specifically, Sancus can remotely attest to a Software provider that a specific Software module is running uncompromised, and can authenticate messages from Software modules to Software providers. Software modules can securely maintain local state, and can securely interact with other Software modules that they choose to trust. The most distinguishing feature of Sancus is that it achieves these security guarantees without trusting any infrastructural Software on the device. The Trusted Computing Base (TCB) on the device is only the hardware. Moreover, the hardware cost of Sancus is low. We describe the design of Sancus, and develop and evaluate a prototype FPGA implementation of a Sancus-enabled device. The prototype extends an MSP430 processor with hardware support for the memory access control and cryptographic functionality required to run Sancus. We also develop a C compiler that targets our device and that can compile standard C modules to Sancus protected Software modules.