Attesting the trustworthiness of a credential issuer
Published in: IARIA Cyber 2025 conference
Rainer Falk, Steffen Fries
Locally issued device certificates in industrial settings often lack the trust of those from centralized security infrastructures. To bridge this gap, we propose embedding a cryptographically verifiable integrity attestation of the credential issuer directly into issued authentication certificates. This allows relying parties to easily verify the issuer's trustworthiness during routine credential validation.
View at publisher's page
Optimizing certificate validation in OT environments by caching certificate validation results
Submitted to: NAIC '25: 2026 IARIA Journal on Advances in Security, vol 19, no 1&2
Rainer Falk, Steffen Fries, Andreas Güttinger
Certificate-based user and device authentication is vital in Operational Technology (OT), but validating full certificate chains strains resource-constrained devices. While offloading validation logic reduces computational overhead, efficiency gains remain limited. This paper reviews existing certificate handling techniques and offloading optimizations, proposing a novel approach to further boost validation efficiency in industrial OT environments.
View at publisher's page
Fault attacks against UOV-based signatures
Published in: IACR 2025
Sven Bauer
Unbalanced Oil and Vinegar (UOV) underpins key post-quantum signature schemes in NIST's standardization. This paper introduces single fault injection attacks on deterministic UOV variants, targeting MAYO and PROV on ARM Cortex-M4 processors. Requiring no precise fault injection or timing, cheap clock glitching recovers secret keys from just 2–3 signatures, exposing a severe implementation security threat.
View at publisher's page