{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,4]],"date-time":"2026-03-04T17:20:44Z","timestamp":1772644844096,"version":"3.50.1"},"publisher-location":"Cham","reference-count":42,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031800191","type":"print"},{"value":"9783031800207","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,12,15]],"date-time":"2024-12-15T00:00:00Z","timestamp":1734220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,12,15]],"date-time":"2024-12-15T00:00:00Z","timestamp":1734220800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-031-80020-7_3","type":"book-chapter","created":{"date-parts":[[2024,12,14]],"date-time":"2024-12-14T07:30:03Z","timestamp":1734161403000},"page":"42-62","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["S-RFUP: Secure Remote Firmware Update Protocol"],"prefix":"10.1007","author":[{"given":"Rakesh","family":"Podder","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tyler","family":"Rios","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Indrajit","family":"Ray","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Presanna","family":"Raman","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Stefano","family":"Righi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,12,15]]},"reference":[{"key":"3_CR1","doi-asserted-by":"crossref","unstructured":"Alrawi, O., Lever, C., Antonakakis, M., Monrose, F.: SOK: security evaluation of home-based iot deployments. In: 2019 IEEE Symposium on Security and Privacy (SP), pp. 1362\u20131380. IEEE (2019)","DOI":"10.1109\/SP.2019.00013"},{"issue":"2","key":"3_CR2","doi-asserted-by":"publisher","first-page":"76","DOI":"10.1016\/j.ijcip.2013.04.004","volume":"6","author":"Z Basnight","year":"2013","unstructured":"Basnight, Z., Butts, J., Lopez, J., Jr., Dube, T.: Firmware modification attacks on programmable logic controllers. Int. J. Crit. Infrastruct. Prot. 6(2), 76\u201384 (2013)","journal-title":"Int. J. Crit. Infrastruct. Prot."},{"issue":"2","key":"3_CR3","doi-asserted-by":"publisher","first-page":"76","DOI":"10.1016\/j.ijcip.2013.04.004","volume":"6","author":"Z Basnight","year":"2013","unstructured":"Basnight, Z., Butts, J., Lopez, J., Jr., Dube, T.: Firmware modification attacks on programmable logic controllers. Int. J. Crit. Infrastruct. Prot. 6(2), 76\u201384 (2013). https:\/\/doi.org\/10.1016\/j.ijcip.2013.04.004","journal-title":"Int. J. Crit. Infrastruct. Prot."},{"key":"3_CR4","unstructured":"Bellissimo, A., Burgess, J., Fu, K.: Secure software updates: disappointments and new challenges. In: HotSec (2006)"},{"issue":"3","key":"3_CR5","doi-asserted-by":"publisher","first-page":"2027","DOI":"10.1109\/COMST.2016.2548426","volume":"18","author":"M Conti","year":"2016","unstructured":"Conti, M., Dragoni, N., Lesyk, V.: A survey of man in the middle attacks. IEEE Commun. Surv. Tutorials 18(3), 2027\u20132051 (2016)","journal-title":"IEEE Commun. Surv. Tutorials"},{"key":"3_CR6","doi-asserted-by":"crossref","unstructured":"Cooper, D., Polk, W., Regenscheid, A., Souppaya, M., et al.: Bios Protection Guidelines, vol. 800, p. 147. NIST Special Publication (2011)","DOI":"10.6028\/NIST.SP.800-147"},{"key":"3_CR7","unstructured":"Costin, A.: Hacking MFPS. In: The 28th Chaos Communication Congress (2011)"},{"key":"3_CR8","unstructured":"Cui, A., Costello, M., Stolfo, S.: When firmware modifications attack: a case study of embedded exploitation. In: NDSS (2013)"},{"key":"3_CR9","doi-asserted-by":"crossref","unstructured":"Dhakal, S., Jaafar, F., Zavarsky, P.: Private blockchain network for IoT device firmware integrity verification and update. In: 2019 IEEE 19th International Symposium on High Assurance Systems Engineering (HASE), pp. 164\u2013170. IEEE (2019)","DOI":"10.1109\/HASE.2019.00033"},{"key":"3_CR10","unstructured":"DMTF: Mctp base specification 1.2.0. DSP0236 (2009). http:\/\/dmtf.org\/sites\/default\/files\/standards\/documents\/DSP0236_1.2.0.pdf"},{"key":"3_CR11","unstructured":"DMTF: Platform level data model (pldm) base specification 1.0. DSP0240 (2009). http:\/\/dmtf.org\/sites\/default\/files\/standards\/documents\/DSP0240_1.0.0.pdf"},{"key":"3_CR12","unstructured":"DMTF: Platform level data model (pldm) for firmware update specification 1.0.1. DSP0267 (2009). https:\/\/dmtf.org\/sites\/default\/files\/standards\/documents\/DSP0267_1.0.1.pdf"},{"issue":"2","key":"3_CR13","doi-asserted-by":"publisher","first-page":"198","DOI":"10.1109\/TIT.1983.1056650","volume":"29","author":"D Dolev","year":"1983","unstructured":"Dolev, D., Yao, A.: On the security of public key protocols. IEEE Trans. Inf. Theory 29(2), 198\u2013208 (1983)","journal-title":"IEEE Trans. Inf. Theory"},{"issue":"1","key":"3_CR14","first-page":"1","volume":"18","author":"S Falas","year":"2021","unstructured":"Falas, S., Konstantinou, C., Michael, M.K.: A modular end-to-end framework for secure firmware updates on embedded systems. ACM J. Emerg. Technol. Comput. Syst. (JETC) 18(1), 1\u201319 (2021)","journal-title":"ACM J. Emerg. Technol. Comput. Syst. (JETC)"},{"key":"3_CR15","unstructured":"Frisch, D., Rei\u00dfmann, S., Pape, C.: An over the air update mechanism for esp8266 microcontrollers. In: Proceedings of the ICSNC, the Twelfth International Conference on Systems and Networks Communications, Athens, Greece, pp. 8\u201312 (2017)"},{"key":"3_CR16","series-title":"IFIP Advances in Information and Communication Technology","doi-asserted-by":"publisher","first-page":"276","DOI":"10.1007\/978-3-319-33630-5_19","volume-title":"ICT Systems Security and Privacy Protection","author":"A Fuchs","year":"2016","unstructured":"Fuchs, A., Krau\u00df, C., Repp, J.: Advanced remote firmware upgrades using TPM 2.0. In: Hoepman, J.-H., Katzenbeisser, S. (eds.) SEC 2016. IAICT, vol. 471, pp. 276\u2013289. Springer, Cham (2016). https:\/\/doi.org\/10.1007\/978-3-319-33630-5_19"},{"key":"3_CR17","unstructured":"He, Y., et al.: $$\\{$$RapidPatch$$\\}$$: firmware hotpatching for $$\\{$$Real-Time$$\\}$$ embedded devices. In: 31st USENIX Security Symposium (USENIX Security 22), pp. 2225\u20132242 (2022)"},{"key":"3_CR18","unstructured":"Jack, B.: Jackpotting automated teller machines redux. Black Hat USA (2010)"},{"key":"3_CR19","doi-asserted-by":"crossref","unstructured":"Jain, N., Mali, S.G., Kulkarni, S.: Infield firmware update: challenges and solutions. In: 2016 International Conference on Communication and Signal Processing (ICCSP), pp. 1232\u20131236. IEEE (2016)","DOI":"10.1109\/ICCSP.2016.7754349"},{"key":"3_CR20","doi-asserted-by":"crossref","unstructured":"Keleman, L., Mati\u0107, D., Popovi\u0107, M., Ka\u0161telan, I.: Secure firmware update in embedded systems. In: 2019 IEEE 9th International Conference on Consumer Electronics (ICCE-Berlin), pp. 16\u201319. IEEE (2019)","DOI":"10.1109\/ICCE-Berlin47944.2019.8966174"},{"key":"3_CR21","unstructured":"Kelly, B.: Project cerberus security architecture overview specification. Open Compute Project (2017). https:\/\/learn.microsoft.com\/en-us\/azure\/security\/fundamentals\/project-cerberus"},{"key":"3_CR22","doi-asserted-by":"crossref","unstructured":"Langiu, A., Boano, C.A., Schu\u00df, M., R\u00f6mer, K.: Upkit: an open-source, portable, and lightweight update framework for constrained IoT devices. In: 2019 IEEE 39th International Conference on Distributed Computing Systems (ICDCS), pp. 2101\u20132112. IEEE (2019)","DOI":"10.1109\/ICDCS.2019.00207"},{"key":"3_CR23","series-title":"LNCS","doi-asserted-by":"publisher","first-page":"214","DOI":"10.1007\/978-3-031-54129-2_13","volume-title":"ESORICS 2023","author":"PT Lau","year":"2023","unstructured":"Lau, P.T., Katzenbeisser, S.: Firmware-based dos attacks in wireless sensor network. In: Katsikas, S., et al. (eds.) ESORICS 2023. LNCS, vol. 14399, pp. 214\u2013232. Springer, Cham (2023). https:\/\/doi.org\/10.1007\/978-3-031-54129-2_13"},{"key":"3_CR24","unstructured":"Maassen, A.: Network bluepill-stealth router-based botnet has been ddosing dronebl for the last couple of weeks (2009). https:\/\/www.dronebl.org\/blog\/8"},{"issue":"19","key":"3_CR25","doi-asserted-by":"publisher","first-page":"7572","DOI":"10.3390\/s22197572","volume":"22","author":"F Mahfoudhi","year":"2022","unstructured":"Mahfoudhi, F., Sultania, A.K., Famaey, J.: Over-the-air firmware updates for constrained NB-IoT devices. Sensors 22(19), 7572 (2022)","journal-title":"Sensors"},{"key":"3_CR26","unstructured":"Miller, C., Valasek, C.: Remote exploitation of an unaltered passenger vehicle. Black Hat USA 2015(S 91), 1\u201391 (2015)"},{"key":"3_CR27","doi-asserted-by":"publisher","DOI":"10.21236\/ADA610495","volume-title":"Supply chain attack framework and attack patterns","author":"JF Miller","year":"2013","unstructured":"Miller, J.F.: Supply chain attack framework and attack patterns. The MITRE Corporation, MacLean, VA (2013)"},{"key":"3_CR28","doi-asserted-by":"crossref","unstructured":"Moran, B., Tschofenig, H., Brown, D., Meriac, M.: A firmware update architecture for internet of things. Internet Requests for Comments, RFC Editor, RFC 9019 (2021)","DOI":"10.17487\/RFC9019"},{"issue":"7","key":"3_CR29","doi-asserted-by":"publisher","first-page":"1328","DOI":"10.3390\/electronics13071328","volume":"13","author":"BP Neves","year":"2024","unstructured":"Neves, B.P., Santos, V.D., Valente, A.: Innovative firmware update method to microcontrollers during runtime. Electronics 13(7), 1328 (2024)","journal-title":"Electronics"},{"key":"3_CR30","doi-asserted-by":"crossref","unstructured":"Niesler, C., Surminski, S., Davi, L.: Hera: Hotpatching of embedded real-time applications. In: NDSS (2021)","DOI":"10.14722\/ndss.2021.24159"},{"key":"3_CR31","doi-asserted-by":"crossref","unstructured":"Podder, R., Abdelgawad, M., Ray, I., Ray, I., Santharam, M., Righi, S.: Correctness and security analysis of the protection in transit (pit) protocol. Available at SSRN 4980331 (2024)","DOI":"10.2139\/ssrn.4980329"},{"key":"3_CR32","doi-asserted-by":"crossref","unstructured":"Podder, R., Barai, R.K.: Hybrid encryption algorithm for the data security of esp32 based IoT-enabled robots. In: 2021 Innovations in Energy Management and Renewable Resources (52042), pp.\u00a01\u20135. IEEE (2021)","DOI":"10.1109\/IEMRE52042.2021.9386824"},{"key":"3_CR33","doi-asserted-by":"crossref","unstructured":"Podder, R., Sovereign, J., Ray, I., Santharam, M.B., Righi, S.: The pit-cerberus framework: preventing device tampering during transit. In: 2024 IEEE 24th International Conference on Software Quality, Reliability and Security (QRS), pp. 584\u2013595. IEEE (2024)","DOI":"10.1109\/QRS62785.2024.00064"},{"key":"3_CR34","doi-asserted-by":"crossref","unstructured":"Samuel, J., Mathewson, N., Cappos, J., Dingledine, R.: Survivable key compromise in software update systems. In: Proceedings of the 17th ACM Conference on Computer and Communications Security, pp. 61\u201372 (2010)","DOI":"10.1145\/1866307.1866315"},{"key":"3_CR35","unstructured":"Schmidt, S., Tausig, M., Hudler, M., Simhandl, G.: Secure firmware update over the air in the internet of things focusing on flexibility and feasibility. In: Internet of Things Software Update Workshop (IoTSU). Proceeding (2016)"},{"key":"3_CR36","unstructured":"Sun, S.: Design and implementation of partial firmware upgrade (2019)"},{"key":"3_CR37","doi-asserted-by":"crossref","unstructured":"Tsang, R., et al.: Fandemic: firmware attack construction and deployment on power management integrated circuit and impacts on IoT applications. In: NDSS (2022)","DOI":"10.14722\/ndss.2022.24349"},{"key":"3_CR38","doi-asserted-by":"crossref","unstructured":"Vrachkov, D.G., Todorov, D.G.: Research of the systems for firmware over the air (fota) and wireless diagnostic in the new vehicles. In: 2020 XXIX International Scientific Conference Electronics (ET), pp.\u00a01\u20134. IEEE (2020)","DOI":"10.1109\/ET50336.2020.9238345"},{"key":"3_CR39","doi-asserted-by":"crossref","unstructured":"Wara, M.S., Yu, Q.: New replay attacks on zigbee devices for internet-of-things (IoT) applications. In: 2020 IEEE International Conference on Embedded Software and Systems (ICESS), pp.\u00a01\u20136. IEEE (2020)","DOI":"10.1109\/ICESS49830.2020.9301593"},{"issue":"4","key":"3_CR40","doi-asserted-by":"publisher","first-page":"2350","DOI":"10.1109\/TCE.2010.5681111","volume":"56","author":"Y Wee","year":"2010","unstructured":"Wee, Y., Kim, T.: A new code compression method for FOTA. IEEE Trans. Consum. Electron. 56(4), 2350\u20132354 (2010)","journal-title":"IEEE Trans. Consum. Electron."},{"key":"3_CR41","unstructured":"Wu, Y., et al.: Your firmware has arrived: a study of firmware update vulnerabilities. In: USENIX Security Symposium (2023)"},{"issue":"1","key":"3_CR42","doi-asserted-by":"publisher","first-page":"145","DOI":"10.3390\/sym15010145","volume":"15","author":"Y Zhang","year":"2023","unstructured":"Zhang, Y., Li, Y., Li, Z.: Aye: a trusted forensic method for firmware tampering attacks. Symmetry 15(1), 145 (2023)","journal-title":"Symmetry"}],"container-title":["Lecture Notes in Computer Science","Information Systems Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-80020-7_3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,12,14]],"date-time":"2024-12-14T08:03:53Z","timestamp":1734163433000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-80020-7_3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,15]]},"ISBN":["9783031800191","9783031800207"],"references-count":42,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-80020-7_3","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,12,15]]},"assertion":[{"value":"15 December 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICISS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Information Systems Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Jaipur","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"India","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 December 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20 December 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"iciss2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/iciss.isrdc.in","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}