Change search
Link to record
Permanent link

Direct link
Publications (4 of 4) Show all publications
Höglund, J., Bouget, S., Furuhed, M., Preuß Mattsson, J., Selander, G. & Raza, S. (2024). AutoPKI: public key infrastructure for IoT with automated trust transfer. International Journal of Information Security, 23(3), 1859
Open this publication in new window or tab >>AutoPKI: public key infrastructure for IoT with automated trust transfer
Show others...
2024 (English)In: International Journal of Information Security, ISSN 1615-5262, E-ISSN 1615-5270, Vol. 23, no 3, p. 1859-Article in journal (Refereed) Published
Abstract [en]

IoT deployments grow in numbers and size, which makes questions of long-term support and maintainability increasingly important. Without scalable and standard-compliant capabilities to transfer the control of IoT devices between service providers, IoT system owners cannot ensure long-term maintainability, and risk vendor lock-in. The manual overhead must be kept low for large-scale IoT installations to be economically feasible. We propose AutoPKI, a lightweight protocol to update the IoT PKI credentials and shift the trusted domains, enabling the transfer of control between IoT service providers, building upon the latest IoT standards for secure communication and efficient encodings. We show that the overhead for the involved IoT devices is small and that the overall required manual overhead can be minimized. We analyse the fulfilment of the security requirements, and for a subset of them, we demonstrate that the desired security properties hold through formal verification using the Tamarin prover. 

Place, publisher, year, edition, pages
Springer Science and Business Media Deutschland GmbH, 2024
Keywords
Internet of things; Maintainability; Public key cryptography; Digital certificates; Embedded-system; Enrollment; IoT; Lock-in; Number and size; PKI; Public key infrastructure; Service provider; Trust transfer; Embedded systems
National Category
Electrical Engineering, Electronic Engineering, Information Engineering
Identifiers
urn:nbn:se:ri:diva-72880 (URN)10.1007/s10207-024-00825-z (DOI)2-s2.0-85186450576 (Scopus ID)
Funder
Swedish Foundation for Strategic ResearchEU, Horizon 2020, 101020259EU, Horizon 2020, 957197
Note

This research is partially funded by the Swedish SSF Institute PhD grant and by the EU H2020 projects ARCADIAN-IoT (Grant ID. 101020259) and VEDLIoT (Grant ID: 957197)

Available from: 2024-04-26 Created: 2024-04-26 Last updated: 2025-09-23Bibliographically approved
Höglund, R., Tiloca, M., Bouget, S. & Raza, S. (2023). Key Update for the IoT Security Standard OSCORE. In: 2023 IEEE International Conference on Cyber Security and Resilience (CSR): . Paper presented at 2023 IEEE International Conference on Cyber Security and Resilience (CSR). IEEE
Open this publication in new window or tab >>Key Update for the IoT Security Standard OSCORE
2023 (English)In: 2023 IEEE International Conference on Cyber Security and Resilience (CSR), IEEE , 2023Conference paper, Published paper (Refereed)
Abstract [en]

The standard Constrained Application Protocol (CoAP) is a lightweight, web-transfer protocol based on the REST paradigm and specifically suitable for constrained devices and the Internet-of-Things. Object Security for Constrained RESTful Environment (OSCORE) is a standard, lightweight security protocol that provides end-to-end protection of CoAP messages. A number of methods exist for managing keying material for OSCORE, as to its establishment and update. This paper provides a detailed comparison of such methods, in terms of their features, limitations and security properties. Also, it especially considers the new key update protocol KUDOS, for which it provides a more extended discussion about its features and mechanics, as well as a formal verification of its security properties.

Place, publisher, year, edition, pages
IEEE, 2023
National Category
Communication Systems
Identifiers
urn:nbn:se:ri:diva-67071 (URN)10.1109/csr57506.2023.10225002 (DOI)
Conference
2023 IEEE International Conference on Cyber Security and Resilience (CSR)
Note

This work was partly supported by the H2020 projectSIFIS-Home (Grant agreement 952652), the SSF projectSEC4Factory (Grant agreement RIT17-0032), and the H2020project ARCADIAN-IoT (Grant agreement 101020259).

Available from: 2023-09-21 Created: 2023-09-21 Last updated: 2025-09-23Bibliographically approved
Bosk, D., Bouget, S. & Buchegger, S. (2020). Distance-bounding, privacy-preserving attribute-based credentials. In: International Conference on Cryptology and Network SecurityCANS 2020: Cryptology and Network Security: . Paper presented at International Conference on Cryptology and Network Security CANS 2020: Cryptology and Network Security 14 December 2020 through 16 December 2020. (pp. 147-166). Springer Science and Business Media Deutschland GmbH
Open this publication in new window or tab >>Distance-bounding, privacy-preserving attribute-based credentials
2020 (English)In: International Conference on Cryptology and Network SecurityCANS 2020: Cryptology and Network Security, Springer Science and Business Media Deutschland GmbH , 2020, p. 147-166Conference paper, Published paper (Refereed)
Abstract [en]

Distance-bounding anonymous credentials could be used for any location proofs that do not need to identify the prover and thus could make even notoriously invasive mechanisms such as location-based services privacy-preserving. There is, however, no secure distance-bounding protocol for general attribute-based anonymous credentials. Brands and Chaum’s (EUROCRYPT’93) protocol combining distance-bounding and Schnorr identification comes close, but does not fulfill the requirements of modern distance-bounding protocols. For that, we need a secure distance-bounding zero-knowledge proof-of-knowledge resisting mafia fraud, distance fraud, distance hijacking and terrorist fraud. Our approach is another attempt toward combining distance bounding and Schnorr to construct a distance-bounding zero-knowledge proof-of-knowledge. We construct such a protocol and prove it secure in the (extended) DFKO model for distance bounding. We also performed a symbolic verification of security properties needed for resisting these attacks, implemented in Tamarin. Encouraged by results from Singh et al. (NDSS’19), we take advantage of lessened constraints on how much can be sent in the fast phase of the distance-bounding protocol and achieve a more efficient protocol. We also provide a version that does not rely on being able to send more than one bit at a time which yields the same properties except for (full) terrorist fraud resistance.

Place, publisher, year, edition, pages
Springer Science and Business Media Deutschland GmbH, 2020
Series
Part of the Lecture Notes in Computer Science book series (LNCS, volume 12579)
Keywords
Cryptography, Location based services, Privacy by design, Telecommunication services, Terrorism, Anonymous credential, Distance bounding protocols, Efficient protocols, General attributes, Privacy preserving, Security properties, Symbolic verification, Zero knowledge proof, Network security
National Category
Natural Sciences
Identifiers
urn:nbn:se:ri:diva-51963 (URN)10.1007/978-3-030-65411-5_8 (DOI)2-s2.0-85098261202 (Scopus ID)9783030654108 (ISBN)
Conference
International Conference on Cryptology and Network Security CANS 2020: Cryptology and Network Security 14 December 2020 through 16 December 2020.
Note

Funding details: Stiftelsen för Strategisk Forskning, SSF, SSF FFL09-0086, 830927; Funding text 1: D. Bosk—Thanks to Sébastien Gambs (UQAM), Cristina Onete (Univ. Limoges) and Douglas Wikström (KTH) for valuable discussions. Thanks to Mats Näslund (FRA, KTH) for reading the draft and pointing out several mistakes. Part of the work done while visiting the WIDE team in Inria/CNRS/IRISA/Univ. Rennes. Supported by the Swedish Foundation for Strategic Research grant SSF FFL09-0086. S. Bouget—Supported by the funding for H2020 project CONCORDIA (Grant Agreement No. 830927). Part of the work done while at KTH, funded by the Swdish Foundation for Strategic Research, grant SSF FFL09-0086. S. Buchegger—Supported by the Swedish Foundation for Strategic Research grant SSF FFL09-0086.

Available from: 2021-01-21 Created: 2021-01-21 Last updated: 2025-09-23Bibliographically approved
Aslam, M., Bouget, S. & Raza, S. (2020). Security and trust preserving inter- and intra-cloud VM migrations. International Journal of Network Management, Article ID e2103.
Open this publication in new window or tab >>Security and trust preserving inter- and intra-cloud VM migrations
2020 (English)In: International Journal of Network Management, ISSN 1055-7148, E-ISSN 1099-1190, article id e2103Article in journal (Refereed) Published
Abstract [en]

This paper focus on providing a secure and trustworthy solution for virtual machine (VM) migration within an existing cloud provider domain, and/or to the other federating cloud providers. The infrastructure-as-a-service (IaaS) cloud service model is mainly addressed to extend and complement the previous Trusted Computing techniques for secure VM launch and VM migration case. The VM migration solution proposed in this paper uses a Trust_Token based to guarantee that the user VMs can only be migrated and hosted on a trustworthy and/or compliant cloud platforms. The possibility to also check the compliance of the cloud platforms with the pre-defined baseline configurations makes our solution compatible with an existing widely accepted standards-based, security-focused cloud frameworks like FedRAMP. Our proposed solution can be used for both inter- and intra-cloud VM migrations. Different from previous schemes, our solution is not dependent on an active (on-line) trusted third party; that is, the trusted third party only performs the platform certification and is not involved in the actual VM migration process. We use the Tamarin solver to realize a formal security analysis of the proposed migration protocol and show that our protocol is safe under the Dolev-Yao intruder model. Finally, we show how our proposed mechanisms fulfill major security and trust requirements for secure VM migration in cloud environments. 

Place, publisher, year, edition, pages
John Wiley and Sons Ltd, 2020
Keywords
Compliance control, Infrastructure as a service (IaaS), Network security, Regulatory compliance, Virtual machine, Baseline configurations, Cloud service models, Computing techniques, Dolev-Yao intruders, Formal security analysis, Migration protocols, Security and trusts, Trusted third parties, Trusted computing
National Category
Natural Sciences
Identifiers
urn:nbn:se:ri:diva-44389 (URN)10.1002/nem.2103 (DOI)2-s2.0-85079698182 (Scopus ID)
Note

Funding details: Horizon 2020 Framework Programme, H2020, 833742, 783119; Funding text 1: This research has been supported by the funding for H2020 projects SECREDAS (grant agreement no. 783119), nIoVe (grant agreement no. 833742), and RISE Cybersecurity KP.

Available from: 2020-03-09 Created: 2020-03-09 Last updated: 2025-09-23Bibliographically approved
Organisations
Identifiers
ORCID iD: ORCID iD iconorcid.org/0000-0002-5165-2100

Search in DiVA

Show all publications