Sayon

Sayon Duttagupta

Postdoctoral Researcher in COSIC at KU Leuven
Applied Cryptography & IoT Security


About Me


👋 Hi! I’m Sayon, a postdoctoral researcher in the COSIC research group at KU Leuven. I recently defended my PhD, Analysis and Design of Cryptographic Protocols for IoT Devices, under the supervision of Bart Preneel and Dave SingelĂ©e.


My research examines how cryptographic protocols behave in real connected systems once they are embedded into products, standards, and large-scale ecosystems. I work at the intersection of applied cryptography, wireless security, and usable security, with a focus on IoT and cyber-physical systems where security decisions are shaped by usability, deployment constraints, and user interaction.


A core theme of my work is secure device onboarding at scale. I study authentication, pairing, and key establishment protocols for constrained and consumer-facing devices, analysing how convenience-driven design choices can introduce subtle but serious security and privacy risks. Through a combination of protocol analysis, system-level evaluation, and empirical experimentation, I aim to uncover these weaknesses and provide principled guidance for more robust designs.


More broadly, my interests include protocol design and analysis for embedded and wireless systems, key management in resource-constrained environments, security mechanisms that rely on proximity and context, and the tension between usability and security in modern connected products. Across my work, I focus on real-world cryptography, analysing how security protocols interact with deployment constraints, wireless environments, and system-level realities.


My ErdƑs number is 4, and my Dijkstra number is 4. Outside research, I enjoy racquet sports, exploring gastronomy, learning new languages, and the occasional dive into etymology and politics.


Please feel free to get in touch!


My PGP public key 🔑



Publications (7)

Thumbnail: What’s the Matter? An In-Depth Security Analysis of the Matter Protocol

What’s the Matter? An In-Depth Security Analysis of the Matter Protocol

Sayon Duttagupta, Arman Kolozyan, Georgio Nicolas, Bart Preneel, Dave SingelĂ©e

IACR Cryptology ePrint Archive, 2025

Thumbnail: CARPOOL: Secure And Reliable Proof of Location

CARPOOL: Secure And Reliable Proof of Location

Sayon Duttagupta, Dave SingelĂ©e, Xavier Carpent, Volkan Guler, Takahito Yoshizawa, Seyed Farhad Aghili, Aysajan Abidin, Bart Preneel

IACR Cryptology ePrint Archive, 2025

Thumbnail: PathSafe: Secure Path Verification in Software-Defined Networks

PathSafe: Secure Path Verification in Software-Defined Networks

Doriana Monaco, Nikola Antonijević, Sayon Duttagupta, Dave SingelĂ©e, Alessio Sacco, Eduard Marin, Bart Preneel

IEEE NOMS 2025

Thumbnail: HAT: Secure and Practical Key Establishment for Implantable Medical Devices

HAT: Secure and Practical Key Establishment for Implantable Medical Devices

Sayon Duttagupta, Eduard Marin, Dave SingelĂ©e, Bart Preneel

ACM CODASPY 2023

Thumbnail: T-HIBE: A Novel Key Establishment Solution for Decentralized, Multi-Tenant IoT Systems

T-HIBE: A Novel Key Establishment Solution for Decentralized, Multi-Tenant IoT Systems

Sayon Duttagupta, Dave SingelĂ©e, Bart Preneel

IEEE CCNC 2022


Updates


News, talks, and updates


  • 🎓 Jan 2026 Defended my PhD! đŸ„ł

  • đŸ—žïž Jan 2026 WhisperPair received broad media coverage, including WIRED and The New York Times. For a full list of coverage, see the media coverage section on the project website.

  • 🔐 Jan 2026 We disclosed the WhisperPair vulnerability as CVE-2025-36911. We also shot a demo video!

  • 📄 Jul 2025 Our security analysis of Matter is available on ePrint – IACR ePrint 2025/1268

  • đŸŽ€ Jan 2025 Presented PISA at IEEE CCNC 2025 in Las Vegas, USA.

  • đŸŽ€ Oct 2024 Invited talk at the imec Wireless Event in Leuven, Belgium, on Secure Localisation-based Device Commissioning.

  • đŸ§‘â€âš–ïž Nov 2023 Programme Committee member, ACM WiSec 2024.

  • đŸŽ€ Aug 2023 Invited talk at IFIP WG 11.4 in Amsterdam, The Netherlands, on Security Protocols for IoT.

  • đŸŽ€ Apr 2023 Presented HAT at ACM CODASPY 2023 in Charlotte, USA.



Extras

Research Projects

I have contributed to and coordinated research activities across national, regional, and European projects focused on security and privacy for connected and embedded systems.

  • FWO SPITE - Security and Privacy in an Internet of Things Environment (Grant #S002417N)

  • VLAIO TRUSTI - Secure remote software updates in IoT (Grant #HBC.2021.0742)

  • EU TELEMETRY - Trustworthy mEthodologies, open knowLedgE and autoMated tools for sEcurity Testing of IoT software, hardware, and ecosystems (Grant #101119747)



Master’s Thesis Supervision

I have supervised master’s theses across KU Leuven and international partner institutions, covering applied cryptography, network security, and secure systems design.



Internship Supervision

I have supervised research internships focused on protocol design and implementaion, security analysis, and real world system evaluation.

  • Quinten Pinkhof, 2021, Location based Authentication
  • Nikola Antonijević, 2022, Location based Device Commissioning
  • Arman Kolozyan, 2024, Security Analysis of the Matter Protocol
  • Seppe Wyns, 2025, Security Analysis of the Google Fast Pair Protocol
  • Francesco Milizia, 2025, Symmetric Key Authentication with PFS for IoT Systems
  • Neeranuch Jitkhajornwanich, 2026, Dissymmetric Modes for Symmetric Cryptography in IoT Protocols

Selected Media Coverage



Teaching

  • Fall 2025 - Cryptographic Protocols (H0Q28A)