The Experts below are selected from a list of 117 Experts worldwide ranked by ideXlab platform

Pedro José Marrón - One of the best experts on this subject based on the ideXlab platform.

  • PerCom Workshops - PIggy-backed key exchange using online services (PIKE)
    2013 IEEE International Conference on Pervasive Computing and Communications Workshops (PERCOM Workshops), 2013
    Co-Authors: Wolfgang Apolinarski, Marcus Handte, Muhammad Umer Iqbal, Pedro José Marrón
    Abstract:

    This demonstration presents PIKE, a piggybacked key exchange protocol that uses social networks (like Facebook) or business tools (like Google Calendar) to enable secure personal interaction. PIKE minimizes the configuration effort that is necessary to set up a secure communication channel among a set of devices. To do this, it piggybacks the exchange of cryptographic keys on existing online services which perform user authentication and enable the (secure) sharing of resources. To Support Encryption or authentication without Internet connection, PIKE relies on the automatic detection of triggers for upcoming personal interactions and exchanges keys before they take place. To demonstrate the broad applicability of PIKE, we present two example applications that show how its secure key exchange can be used in the real world. The first application uses PIKE to automatically share resources - in our case the readings of a GPS receiver - among a set of devices, when an event takes place. The second application relies on PIKE to enable the secure and automatic identification of individual visitors at the registration desk of a conference.

  • PerCom - PIKE: Enabling secure interaction with piggybacked key-exchange
    2013 IEEE International Conference on Pervasive Computing and Communications (PerCom), 2013
    Co-Authors: Wolfgang Apolinarski, Marcus Handte, Muhammad Umer Iqbal, Pedro José Marrón
    Abstract:

    Online collaboration tools such as Google+, Face-book or Dropbox have become an important and ubiquitous mediator of many human interactions. In the virtual world, they enable secure interaction by controlling access to shared resources. Yet relying on them to Support synchronous direct interactions, such as face-to-face meetings, might be suboptimal as they require reliable online connectivity and even then often introduce delays. A much more efficient way of co-located resource sharing is the use of local communications, such as ad-hoc WiFi. Yet setting up the necessary Encryption and authentication mechanisms is often cumbersome. In this paper, we present PIKE, a key exchange protocol that minimizes this configuration effort. PIKE piggybacks the exchange of keys on top of an existing service infrastructure. To Support Encryption or authentication without Internet connection, PIKE relies on triggers for upcoming personal interactions and exchanges keys before they take place. To evaluate PIKE, we present two example applications and we perform an experimental as well as an analytical analysis of its characteristics. The evaluation indicates that PIKE is broadly applicable, scales well enough to Support larger events and provides a level of security that is (at least) comparable to the one provided by the underlying service.

Michael Grace - One of the best experts on this subject based on the ideXlab platform.

  • WISEC - HanGuard: SDN-driven protection of smart home WiFi devices from malicious mobile apps
    Proceedings of the 10th ACM Conference on Security and Privacy in Wireless and Mobile Networks, 2017
    Co-Authors: Soteris Demetriou, Nan Zhang, Yeonjoon Lee, Xiaofeng Wang, Carl A. Gunter, Xiaoyong Zhou, Michael Grace
    Abstract:

    A new development of smart-home systems is to use mobile apps to control IoT devices across a Home Area Network (HAN). As verified in our study, those systems tend to rely on the Wi-Fi router to authenticate other devices. This treatment exposes them to the attack from malicious apps, particularly those running on authorized phones, which the router does not have information to control. Mitigating this threat cannot solely rely on IoT manufacturers, which may need to change the hardware on the devices to Support Encryption, increasing the cost of the device, or software developers who we need to trust to implement security correctly. In this work, we present a new technique to control the communication between the IoT devices and their apps in a unified, backward-compatible way. Our approach, called HanGuard, does not require any changes to the IoT devices themselves, the IoT apps or the OS of the participating phones. HanGuard uses an SDN-like approach to offer fine-grained protection: each phone runs a non-system userspace Monitor app to identify the party that attempts to access the protected IoT device and inform the router through a control plane of its access decision; the router enforces the decision on the data plane after verifying whether the phone should be allowed to talk to the device. We implemented our design over both Android and iOS (> 95% of mobile OS market share) and a popular router. Our study shows that HanGuard is both efficient and effective in practice.

  • Guardian of the HAN: Thwarting Mobile Attacks on Smart-Home Devices Using OS-level Situation Awareness.
    arXiv: Cryptography and Security, 2017
    Co-Authors: Soteris Demetriou, Nan Zhang, Yeonjoon Lee, Xiaofeng Wang, Carl A. Gunter, Xiaoyong Zhou, Michael Grace
    Abstract:

    A new development of smart-home systems is to use mobile apps to control IoT devices across a Home Area Network (HAN). Those systems tend to rely on the Wi-Fi router to authenticate other devices; as verified in our study, IoT vendors tend to trust all devices connected to the HAN. This treatment exposes them to the attack from malicious apps, particularly those running on authorized phones, which the router does not have information to control, as confirmed in our measurement study. Mitigating this threat cannot solely rely on IoT manufacturers, which may need to change the hardware on the devices to Support Encryption, increasing the cost of the device, or software developers who we need to trust to implement security correctly. In this work, we present a new technique to control the communication between the IoT devices and their apps in a unified, backward-compatible way. Our approach, called Hanguard, does not require any changes to the IoT devices themselves, the IoT apps or the OS of the participating phones. Hanguard achieves a fine-grained, per-app protection through bridging the OS-level situation awareness and the router-level per-flow control: each phone runs a non-system userspace Monitor app to identify the party that attempts to access the protected IoT device and inform the router through a control plane of its access decision; the router enforces the decision on the data plane after verifying whether the phone should be allowed to talk to the device. Hanguard uses a role-based access control (RBAC) schema which leverages type enforcement (TE) and multi-category security (MCS) primitives to define highly flexible access control rules. We implemented our design over both Android and iOS (>95% of mobile OS market share) and a popular router. Our study shows that Hanguard is both efficient and effective in practice.

Wolfgang Apolinarski - One of the best experts on this subject based on the ideXlab platform.

  • PerCom Workshops - PIggy-backed key exchange using online services (PIKE)
    2013 IEEE International Conference on Pervasive Computing and Communications Workshops (PERCOM Workshops), 2013
    Co-Authors: Wolfgang Apolinarski, Marcus Handte, Muhammad Umer Iqbal, Pedro José Marrón
    Abstract:

    This demonstration presents PIKE, a piggybacked key exchange protocol that uses social networks (like Facebook) or business tools (like Google Calendar) to enable secure personal interaction. PIKE minimizes the configuration effort that is necessary to set up a secure communication channel among a set of devices. To do this, it piggybacks the exchange of cryptographic keys on existing online services which perform user authentication and enable the (secure) sharing of resources. To Support Encryption or authentication without Internet connection, PIKE relies on the automatic detection of triggers for upcoming personal interactions and exchanges keys before they take place. To demonstrate the broad applicability of PIKE, we present two example applications that show how its secure key exchange can be used in the real world. The first application uses PIKE to automatically share resources - in our case the readings of a GPS receiver - among a set of devices, when an event takes place. The second application relies on PIKE to enable the secure and automatic identification of individual visitors at the registration desk of a conference.

  • PerCom - PIKE: Enabling secure interaction with piggybacked key-exchange
    2013 IEEE International Conference on Pervasive Computing and Communications (PerCom), 2013
    Co-Authors: Wolfgang Apolinarski, Marcus Handte, Muhammad Umer Iqbal, Pedro José Marrón
    Abstract:

    Online collaboration tools such as Google+, Face-book or Dropbox have become an important and ubiquitous mediator of many human interactions. In the virtual world, they enable secure interaction by controlling access to shared resources. Yet relying on them to Support synchronous direct interactions, such as face-to-face meetings, might be suboptimal as they require reliable online connectivity and even then often introduce delays. A much more efficient way of co-located resource sharing is the use of local communications, such as ad-hoc WiFi. Yet setting up the necessary Encryption and authentication mechanisms is often cumbersome. In this paper, we present PIKE, a key exchange protocol that minimizes this configuration effort. PIKE piggybacks the exchange of keys on top of an existing service infrastructure. To Support Encryption or authentication without Internet connection, PIKE relies on triggers for upcoming personal interactions and exchanges keys before they take place. To evaluate PIKE, we present two example applications and we perform an experimental as well as an analytical analysis of its characteristics. The evaluation indicates that PIKE is broadly applicable, scales well enough to Support larger events and provides a level of security that is (at least) comparable to the one provided by the underlying service.

Moon-seog Jun - One of the best experts on this subject based on the ideXlab platform.

  • Design of Secure Dynamic Clustering Algorithm using SNEP and μTESLA in Sensor network
    2006
    Co-Authors: Kun-won Jang, Sang-hun Lee, Moon-seog Jun
    Abstract:

    Contrary to general network, sensor network has many restrictions such as energy recharge. Accordingly, security mechanism used to general network cannot be applied to sensor network. Many researchers propose method of security and energy efficiency separately. To maximize energy efficiency, the methods to Support data aggregation and clusterhead selection algorithm are proposed. To strengthen the security, the methods to Support Encryption techniques and manage a secret key that is applicable to sensor network are proposed. However, energy and security issues are trade-off. This paper is devoted to design secure routing protocol combining conventional routing protocol with security protocol. This new protocol is that Encryption algorithm and key management method are applied to specific routing protocol.

  • Design of Secure Clustering Routing Protocol using SNEP and µTESLA on Sensor Network Communication
    2006
    Co-Authors: Kun-won Jang, Woo-sik Jung, Dong-kyu Shin, Moon-seog Jun
    Abstract:

    Summary Contrary to general network, sensor network has many restrictions such as energy recharge. Accordingly, security mechanism used to general network cannot be applied to sensor network. Many researchers propose method of security and energy efficiency separately. To maximize energy efficiency, the methods to Support data aggregation and cluster-head selection algorithm are proposed. To strengthen the security, the methods to Support Encryption techniques and manage a secret key that is applicable to sensor network are proposed. However, energy and security issues are trade-off. This paper is devoted to design secure routing protocol combining conventional routing protocol with security protocol. This new protocol is that Encryption algorithm and key management method are applied to specific routing protocol. Finally, we appreciate proposed protocol and look about future work.

Soteris Demetriou - One of the best experts on this subject based on the ideXlab platform.

  • WISEC - HanGuard: SDN-driven protection of smart home WiFi devices from malicious mobile apps
    Proceedings of the 10th ACM Conference on Security and Privacy in Wireless and Mobile Networks, 2017
    Co-Authors: Soteris Demetriou, Nan Zhang, Yeonjoon Lee, Xiaofeng Wang, Carl A. Gunter, Xiaoyong Zhou, Michael Grace
    Abstract:

    A new development of smart-home systems is to use mobile apps to control IoT devices across a Home Area Network (HAN). As verified in our study, those systems tend to rely on the Wi-Fi router to authenticate other devices. This treatment exposes them to the attack from malicious apps, particularly those running on authorized phones, which the router does not have information to control. Mitigating this threat cannot solely rely on IoT manufacturers, which may need to change the hardware on the devices to Support Encryption, increasing the cost of the device, or software developers who we need to trust to implement security correctly. In this work, we present a new technique to control the communication between the IoT devices and their apps in a unified, backward-compatible way. Our approach, called HanGuard, does not require any changes to the IoT devices themselves, the IoT apps or the OS of the participating phones. HanGuard uses an SDN-like approach to offer fine-grained protection: each phone runs a non-system userspace Monitor app to identify the party that attempts to access the protected IoT device and inform the router through a control plane of its access decision; the router enforces the decision on the data plane after verifying whether the phone should be allowed to talk to the device. We implemented our design over both Android and iOS (> 95% of mobile OS market share) and a popular router. Our study shows that HanGuard is both efficient and effective in practice.

  • Guardian of the HAN: Thwarting Mobile Attacks on Smart-Home Devices Using OS-level Situation Awareness.
    arXiv: Cryptography and Security, 2017
    Co-Authors: Soteris Demetriou, Nan Zhang, Yeonjoon Lee, Xiaofeng Wang, Carl A. Gunter, Xiaoyong Zhou, Michael Grace
    Abstract:

    A new development of smart-home systems is to use mobile apps to control IoT devices across a Home Area Network (HAN). Those systems tend to rely on the Wi-Fi router to authenticate other devices; as verified in our study, IoT vendors tend to trust all devices connected to the HAN. This treatment exposes them to the attack from malicious apps, particularly those running on authorized phones, which the router does not have information to control, as confirmed in our measurement study. Mitigating this threat cannot solely rely on IoT manufacturers, which may need to change the hardware on the devices to Support Encryption, increasing the cost of the device, or software developers who we need to trust to implement security correctly. In this work, we present a new technique to control the communication between the IoT devices and their apps in a unified, backward-compatible way. Our approach, called Hanguard, does not require any changes to the IoT devices themselves, the IoT apps or the OS of the participating phones. Hanguard achieves a fine-grained, per-app protection through bridging the OS-level situation awareness and the router-level per-flow control: each phone runs a non-system userspace Monitor app to identify the party that attempts to access the protected IoT device and inform the router through a control plane of its access decision; the router enforces the decision on the data plane after verifying whether the phone should be allowed to talk to the device. Hanguard uses a role-based access control (RBAC) schema which leverages type enforcement (TE) and multi-category security (MCS) primitives to define highly flexible access control rules. We implemented our design over both Android and iOS (>95% of mobile OS market share) and a popular router. Our study shows that Hanguard is both efficient and effective in practice.