Workshops








Attestation and its Applications


November 14-15, 2023
Orange Atalante, Cesson-Sévigné, France




Event description

Virtualization is the corner stone of new mobile network generations (5G and beyond). It enables dynamicity and flexibility to ensure multiple and diverse services while sharing the same physical infrastructure. In this context, since many stakeholders (e.g., verticals, physical and virtualized infrastructure providers, operators) are involved, operators need technical means to ensure the security and privacy of its networks and prove compliance to their commitments (collect evidence that could be accepted and approved by all the involved parties). Attestation frameworks and protocols are a promising solution to address those challenges.

Attestation protocols allow a prover to convince a verifier that a certain property (e.g., software integrity, geolocation, Proof of Transit, etc.) is satisfied. These protocols can then contribute to the set-up of the security of dynamic and heterogeneous networks, service maintenance, and the establishment and strengthening of trust between the operator and the involved stakeholders.

This workshop aims to gather technical experts in various areas touching upon attestation and trust establishment, in a two-day event. The first day will allow members of the research community to present and discuss upcoming results in attestation protocols related topics. The second day will enable industrials and standardization organizations to exchange and discuss the opportunities to consider this technology in industry.


Sponsors

Organizing team

Program

Speakers

Venue

Registration

Sponsors

This event is hosted by the project ANR MobiS5 and co-organized by XLIM / University of Limoges and Orange.

Orange
XLIM

Organizing team

Ghada Arfaoui

Ghada Arfaoui (Eng, PhD) is a senior research engineer working on services and networks security at Orange France. She received her Telecommunication Engineer degree from Télécom SudParis, Institut Mines-Télécom, in 2011. In 2015, she received her PhD in Computer Science from University of Orléans, INSA Centre Val de Loire, France. She contributed to French and European research projects and presented in national and international conferences and meetings. Her main research interests encompass Future Network Security, Mobile Network Infrastructure Security, Trusted Computing, Attestation, Applied Cryptography, Privacy.

Cristina Onete

Cristina Onete is an Associate Professor at the University Limoges. She has been involved in teaching and research activities in three different countries and has, at various times, been an active researcher at CASED (Darmstadt, Germany), Inria (Rennes, France), IRISA (Rennes, France), and XLIM (Limoges, France). Cristina is member and co-responsible for the CRYPTIS research team at XLIM, and a specialist in the provable security of cryptographic protocols, having worked on topics such as authentication, secure-channel establishment, asynchronous messaging protocols, secure attestation, and privacy-preserving delegation of computation. In addition, she has been involved in multiple ANR research projects and is the research coordinator of two ANR Collaborative Research-Industry Projects (PRCE) : MobiS5, which aims to provide a toolbox for security and privacy in 5G networks, and PRIVA-SIQ, aiming to guarantee privacy-preserving secure communication against subversions, interceptions, and quantum adversaries.

Jean-Philippe Wary

Jean-Philippe Wary is currently a Research Program Director at Orange Labs, since 2011, in charge of infrastructures security research for 5G and the IoT topics. Precedently, he has been at SFR for 15 years (French Mobile Operator) as a Security Expert and the Chief Information Security Officer for networks and services and he has been at Alcatel (real time, telecom, security, and electronic war) during 8 years.

Program

1st Day: November 14th, 2023
8:15 - 8:45 Registration / Coffee
8:45 - 9:00 Opening
Jean Bolot, Orange Innovation Research Senior Vice President
9:00 - 9:50 Attestation in Network Routing (Remote)
Nancy Cam-Winget, CISCO
9:50 – 10:40 Attestation for automated certificate management and trust bootstrapping of secure storage for 5G NFs
Ben Smeets, Ericsson
10:40 – 11:00 Morning Break
11:00 - 11:50 Deep Attestation in single and multi-tenant environments
Cristina Onete, XLIM / University of Limoges
11:50 - 12:40 Runtime integrity attestation, from large to small
Antonio Lioy, Politecnico di Torino
12:40 - 14:00 Lunch
14:00 - 14:50 Securing the Swarm: Exploring State-of-the-Art Collective Attestation and Challenges
Edlira Dushku, Aalborg University
14:50 - 15:40 Advanced authentication mechanisms
Olivier Sanders, Orange
15:40 - 16:00 Afternoon Break
16:00 - 16:50 Introduction to Open-Source Project Veraison
Yogesh Deshpande, ARM
16:50 - 17:40 Attestation - A Fundamental Component of IT Infrastructure Security
Guerney D. H. Hunt, IBM
17:40 - 18:30 Intel Trust Authority (Remote)
Haidong Xia, Intel
2nd Day: November 15th, 2023
8:30 - 9:00 Registration / Coffee
9:00 - 9:15 Opening
9:15 - 10:30 Round Table
Animated by Vincent Lefebvre, Solidshield
Participants: ARM, AWS, Ericsson, IBM, Intel, Internet of Trust, Orange, Thales
10:30 – 11:00 Morning Break
11:00 - 11:30 Attesting what and how? Novel forms of attestations
Vincent Lefebvre, Solidshield
11:30 - 12:00 Attestation in ARM
Yogesh Deshpande, ARM
12:00 - 13:30 Lunch
13:30 - 14:10 Ensuring continuity and dynamism in certification: the imperative need in the Context of evolving European Cybersecurity Regulations
Mohamad Hajj, Internet of Trust
14:10 - 14:50 Attestation in ETSI NFV (Remote)
Leslie Willis, BT
14:50 - 15:30 IETF WG RATs (Remote)
Kathleen Moriarty, Center for Internet Security, and Ned Smith, Intel
15:30 - 16:00 Afternoon Break
16:00 - 16:40 Attestation: a Thales view
Anne-Marie Praden, Thales
16:40 - 17:20 Approach to attestation in Ericsson
Ben Smeets, Ericsson
17:20 - 17:35 Recap from IETF#118
Hannes Tschofenig, Siemens
17:35 - 17:50 An example of on demand SLA
Jean-Philippe Wary, Orange

Speakers

Cristina Onete

Cristina Onete is an Associate Professor at the University Limoges. She has been involved in teaching and research activities in three different countries and has, at various times, been an active researcher at CASED (Darmstadt, Germany), Inria (Rennes, France), IRISA (Rennes, France), and XLIM (Limoges, France). Cristina is member and co-responsible for the CRYPTIS research team at XLIM, and a specialist in the provable security of cryptographic protocols, having worked on topics such as authentication, secure-channel establishment, asynchronous messaging protocols, secure attestation, and privacy-preserving delegation of computation. In addition, she has been involved in multiple ANR research projects and is the research coordinator of two ANR Collaborative Research-Industry Projects (PRCE) : MobiS5, which aims to provide a toolbox for security and privacy in 5G networks, and PRIVA-SIQ, aiming to guarantee privacy-preserving secure communication against subversions, interceptions, and quantum adversaries.

Jean-Philippe Wary

Jean-Philippe Wary is currently a Research Program Director at Orange Labs, since 2011, in charge of infrastructures security research for 5G and the IoT topics. Precedently, he has been at SFR for 15 years (French Mobile Operator) as a Security Expert and the Chief Information Security Officer for networks and services and he has been at Alcatel (real time, telecom, security, and electronic war) during 8 years.

Nancy Cam-Winget

Nancy Cam-Winget is a Cisco Fellow in the Cisco Security Business Group Office of the CTO. She has over 20 years of experience in the Cybersecurity industry and is heavily involved with product and technology strategy, research and standards.
Nancy was a key contributor and editor for securing IEEE 802.11 and creator of EAP-FAST (and IETF's TEAP, RFC 7170). She was also the creator and initial architect for Cisco’s pxGrid and the main editor for pxGrid's standard framework: XMPP-Grid, e.g. IETF RFC 8600. In the Industrial IoT domain, Nancy was key contributor the security behind the Common Industrial Protocol (CIP) in the ODVA forum.
She continues to be involved in the IETF and other standards forums. She is currently the board treasurer for the OpenID Foundation. In the IETF, she is a member of the Security and IoT directorates and chairs several security focused working groups.

Ben Smeets

Ben Smeets' current work is focused on trusted computing technologies in connection with containers and secure enclaves.
Ben holds a Ph.D. in information theory from Lund University, Sweden, where he also serves as a professor. He joined Ericsson Mobile Communications in 1998, where he started out working on security solutions for mobile phone platforms. He currently is a Ericsson Senior Export in Security at Ericsson Research.

Antonio Lioy

Antonio Lioy holds a MSc in Electronic Engineering and a PhD in Computer Engineering. He is Full Professor of cybersecurity at the Politecnico di Torino, Italy, where he leads the TORSEC research group. Since 1996, he has taken part to more than 20 European research projects in the cybersecurity area and published more than 100 research papers. His research interests are in the fields of electronic identity, network security, trusted computing, and policy-based design and monitoring of modern IT infrastructures (IoT, cloud, SDN, NFV).
Prof. Lioy is frequently a consultant, evaluator, and reviewer for European and Italian institutions. Prof. Lioy is the leader of PROTECT-IT cybersecurity project funded by the Italian recovery fund for the years 2023-25, with the national action SERICS (SEcurity and RIghts in the CyberSpace).

Edlira Dushku

Edlira Dushku is currently an Assistant Professor in Cyber Security at Aalborg University. She received the Ph.D. degree in Computer Science from Sapienza University of Rome, Italy, in 2020. After her Ph.D., she was a Postdoctoral Researcher in Secure Pervasive Computing at DTU Compute, Technical University of Denmark. She is a member of the Young Academy of Technology, Science and Innovation (YATSI) in Denmark. Her research interests include Internet of Things security, Remote Attestation, Fog Computing, and Trusted Computing.

Olivier Sanders

Olivier Sanders (PhD) is a cryptographic engineer at Orange. He published 25+ papers in peer reviewed international journals and conferences, mostly on the topic of cryptography for privacy, and holds several associated patents. He is also involved in some standardization bodies such as GSMA and 3GPP. The signatures he designed jointly with David Pointcheval serve as the basis of some standardized mechanisms in ISO 20008-2.

Yogesh Deshpande

Yogesh Deshpande who is a Principal Security Architect and works in Architecture and Technology Group in ARM. His main areas of work includes core contributions to Open-Source Project Veraison (on Attestation) along with contributions on evolving Attestation Standards in IETF and TCG Work Groups. He is also a member of the Supply Chain Security Working Group (SCITT) in IETF.

Dr. Guerney D. H. Hunt

Dr. Guerney D. H. Hunt is a senior Research Scientist at IBM’s T. J. Watson Research Center. He has been working on various aspect of computer security since 2008. He is currently working on modifications for computer architecture which enable exploiting systems to be more secure. He is currently IBM’s voting member to the SPDM workgroup within DMTF and is also one of two IBM representatives in the CXL Security Workgroup. He is co-Chair of the RISC-V Trusted Execution Environment Task Group (TEE TG). He is also a member of the RISC-V Security Horizontal Committee.
Dr. Hunt participated in a team funded by the Department of Homeland Security and the Canadian government to develop an end-to-end security architecture. His work in computer security has included breaking into computer systems, in controlled environments, to demonstrate that certain attacks were possible. He joined IBM Research in 1995 as a member of the distributed computing group where he became the co-inventor of the technology used to scale all internet services today. He has worked in the secure intermediary infrastructures, advanced cluster systems, and distributed infrastructure groups before joining the Security Research Department in 2008. He was also the Principal Investigator of the Next Generation Secure Computer Architecture exploratory research project. His work has included blockchain security. Prior to joining IBM Research in 1995 after completing his Ph.D., Dr. Hunt worked for NCR from 1975-1981, and worked in IBM development from 1981-1989. His earlier work was in software and microcode development, IBM product engineering, and OS development for VM/370. Since joining IBM Research, he has held management and non-management positions.
Dr. Hunt holds a BS in mathematics from Michigan Technological University, 1973, and an MS and Ph.D. in computer science from Cornell University, (1975 & 1995). He is a senior member of the IEEE and a member of the ACM, was a founding member of the editorial board of IEEE Pervasive Computing, he holds more than 21 US and foreign patents, has published papers, and has been an IBM Master Inventor.

Haidong Xia

Haidong Xia is a principle engineer at Intel, and architect for Intel trust authority. He has been working in security for 20+ years, with experience in OS kernel, software stack, and cloud. During his spare time, Haidong likes to play different sports.

Vincent Lefebvre

Vincent Lefebvre is an IT engineer at SARL Tages Solidshield, Le Cannet, 06100 Alpes-Maritimes, France. His research interests include elaborating novel schemes for software security. Lefebvre received a master’s degree in electronics and computer science from the Institut d'Electronique et du Numérique (ISEN), Lille, France.

Mohamad Hajj

Mohamad Hajj is a Senior Cybersecurity Consultant at Internet of Trust with over 10 years of experience in security risk assessment (according to EBIOS RM, ISO 27005 and NIST 800-30) and security assurance (Self-assessment, Common Criteria, EUCC, GlobalPlatform, CSPN, IoT schemes, NESAS, etc.), with technologies including 5G, O-RAN, Cloud, Smart Cards, IoT devices, Digital identity, Digital signature and Automotive (ISO 21434). Prior to joining Internet of Trust, he was a certification expert (Common Criteria and other private certification schemes) at Thales (previously Gemalto/Trusted Labs). Mohamad gained a PhD in Electronic and Telecommunication from Limoges University, France, in 2009. Mohamad is a rapporteur of the ENISA EU5G certification scheme, and a member of the ENISA Ad-Hoc group on vulnerability handling, WG11 O-RAN alliance, and Eurosmart CDI.

Leslie Willis

Leslie Willis joined BT Research and Development in 1996 as a graduate in Computer Science from the University of Teesside. Initial work involved creating some of the first web management systems for BT Conferencing platforms (BT MeetMe). In 2006 he moved into network security consultancy working on multiple networks across the UK and the rest of the world. Leslie is now a Principal Security Authority in BT and a Distinguished Engineer within the BT Tech Fellowship as well as the chair of the ETSI ISG NFV Security working group.

Kathleen Moriarty

Kathleen Moriarty, Chief Technology Officer, Center for Internet Security has over two decades of experience. Formerly as the Security Innovations Principal in Dell Technologies Office of the CTO, Kathleen worked on ecosystems, standards, and strategy. During her tenure in the Dell EMC Office of the CTO, Kathleen had the honor of being appointed and serving two terms as the Internet Engineering Task Force (IETF) Security Area Director and as a member of the Internet Engineering Steering Group from March 2014-2018. Named in CyberSecurity Ventures, Top 100 Women Fighting Cybercrime. She is a 2020 Tropaia Award Winner, Outstanding Faculty, Georgetown SCS.
Kathleen achieved over twenty years of experience driving positive outcomes across Information Technology Leadership, IT Strategy and Vision, Information Security, Risk Management, Incident Handling, Project Management, Large Teams, Process Improvement, and Operations Management in multiple roles with MIT Lincoln Laboratory, Hudson Williams, FactSet Research Systems, and PSINet.
Kathleen holds a Master of Science Degree in Computer Science from Rensselaer Polytechnic Institute, as well as, a Bachelor of Science Degree in Mathematics from Siena College.

Anne-Marie Praden

Anne-Marie Praden is a senior standardization expert at Thales Digital Identity and Security (DIS). She actively contributes in ETSI NFV Security group with the aim to enhance the security of the virtualized telecom networks. Across her 30 years of experience in Gemplus, then Gemalto and ultimately Thales, she has consistently represented her company at AFNOR, GAIA-X, 3GPP, Open Mobile Alliance, SIM Alliance, OIPF, BMCO Forum and DVB. Anne-Marie's background is in electronics and micro-electronics systems. She joined Gemplus in 1994, after gathering a solid experience in ASIC design and video compression. During the 30 years spent in Thales she acquired a solid experience in security and privacy with projects in Pay-TV, Smartcard, security hardening of a RISC processor, and cyber-security of 5G virtualized networks.

Ned Smith

Ned Smith is a Principal Engineer in the System Security Privacy and Mitigation group. He leads the Intel Attestation Core Team. He co-chairs the Remote Attestation Procedures (RATS) working group in the Internet Engineering Task Force (IETF) and the Attestation Working Group (ATWG) in the Trusted Computing Group (TCG). He received the 2019 Key Contributor and 2022 Leadership awards from the TCG. Ned has authored more than 30 industry standards related to trusted computing, device identity, network security, IoT security and attestation. He holds 402 US patents, has received 8 Top Inventor awards. He co-authored "Demystifying Internet of Things Security", APress Publishers, August 2019. He has 8 peer reviewed academic publications.

Nizar Kheir

Nizar Kheir is a Senior Solutions Architect at Amazon Web Services (AWS), with over 15 years of experience in the IT domain. He currently works with public sector customers in France and across Europe to help them modernize their IT infrastructure and foster innovation through harnessing the power of AWS cloud. Nizar is passionate about technology and the potential it has to simplify the life of citizens and address societal challenges. He also has a long track record of innovation, having filed over a dozen of patents in cutting-edge technology solutions.

Venue

This event is hosted by Orange Atalante at Cesson-Sévigné (near Rennes). Orange Atalante is a newly built eco-responsible site and fully accessible to PRM participants.

Address: 4, Rue du Clos Courtel, 35510 Cesson-Sévigné - France
From Rennes: Take Metro line B - Station Atalante

Rennes is easily accessible from European capitals thanks to its numerous connections from / to its airport (Airport Rennes Bretagne). By train, it takes just 1h25 from Paris on the LGV (Ligne à Grande Vitesse) High Speed Line.

Registration

Registration is required to participate in the workshop.
An identity card or a passport are required to access Orange site.



https://msurvey.orange.com/AttestationanditsApplications