23 citations · 28 across the 6 of their papers we have counts for
6 papers · 1 filter
Misbinding Raw Public Keys to Identities in TLS
Mariam Moustafa, Mohit Sethi, Tuomas Aura
The adoption of security protocols such as Transport Layer Security (TLS) has significantly improved the state of traffic encryption and integrity protection on the Internet. Despi…
Threat modeling framework for mobile communication systems
Siddharth Prakash Rao, Silke Holtmanns, Tuomas Aura
Due to the complex nature of mobile communication systems, most of the security efforts in its domain are isolated and scattered across underlying technologies. This has resulted i…
Client-side Vulnerabilities in Commercial VPNs
Thanh Bui, Siddharth Prakash Rao, Markku Antikainen +1
Internet users increasingly rely on commercial virtual private network (VPN) services to protect their security and privacy. The VPN services route the client's traffic over an enc…
XSS Vulnerabilities in Cloud-Application Add-Ons
Thanh Bui, Siddharth Rao, Markku Antikainen +1
Cloud-application add-ons are microservices that extend the functionality of the core applications. Many application vendors have opened their APIs for third-party developers and c…
Misbinding Attacks on Secure Device Pairing and Bootstrapping
Mohit Sethi, Aleksi Peltonen, Tuomas Aura
In identity misbinding attacks against authenticated key-exchange protocols, a legitimate but compromised participant manipulates the honest parties so that the victim becomes unkn…
Key exchange with the help of a public ledger
Thanh Bui, Tuomas Aura
Blockchains and other public ledger structures promise a new way to create globally consistent event logs and other records. We make use of this consistency property to detect and…