Sayon

Sayon Duttagupta

Postdoctoral Researcher in COSIC at KU Leuven
Applied Cryptography & IoT Security


About Me


👋 Hi! I’m Sayon, a postdoctoral researcher in the COSIC research group at KU Leuven. I recently defended my PhD, Analysis and Design of Cryptographic Protocols for IoT Devices, under the supervision of Bart Preneel and Dave Singelée.


My research examines how cryptographic protocols behave in real connected systems once they are embedded into products, standards, and large-scale ecosystems. I work at the intersection of applied cryptography, wireless security, and usable security, with a focus on IoT and cyber-physical systems where security decisions are shaped by usability, deployment constraints, and user interaction.


A core theme of my work is secure device onboarding at scale. I study authentication, pairing, and key establishment protocols for constrained and consumer-facing devices, analysing how convenience-driven design choices can introduce subtle but serious security and privacy risks. Through a combination of protocol analysis, system-level evaluation, and empirical experimentation, I aim to uncover these weaknesses and provide principled guidance for more robust designs.


More broadly, my interests include protocol design and analysis for embedded and wireless systems, key management in resource-constrained environments, security mechanisms that rely on proximity and context, and the tension between usability and security in modern connected products. Across my work, I focus on real-world cryptography, analysing how security protocols interact with deployment constraints, wireless environments, and system-level realities.


My Erdős number is 4, and my Dijkstra number is 4. Outside research, I enjoy racquet sports, exploring gastronomy, learning new languages, and the occasional dive into etymology and politics.


Please feel free to get in touch!


My PGP public key 🔑



Selected Publications

Thumbnail: What’s the Matter? An In-Depth Security Analysis of the Matter Protocol

What’s the Matter? An In-Depth Security Analysis of the Matter Protocol

Sayon Duttagupta, Arman Kolozyan, Georgio Nicolas, Dave Singelée, Bart Preneel

IEEE S&P (Oakland) 2027 (Acceptance rate: 15.8%)

Thumbnail: HASAC: Energy Adaptive Secure Firmware Updates for Critical IoT Systems

HASAC: Energy Adaptive Secure Firmware Updates for Critical IoT Systems

Sayon Duttagupta

IFIP SEC 2026 (Acceptance rate: 23.8%)

Thumbnail: CARPOOL: Secure And Reliable Proof of Location

CARPOOL: Secure And Reliable Proof of Location

Sayon Duttagupta, Dave Singelée, Xavier Carpent, Takahito Yoshizawa, Farhad Aghili, Aysajan Abidin, Bart Preneel

ACM SACMAT 2026 (Acceptance rate: 28.5%)

Thumbnail: HAT: Secure and Practical Key Establishment for Implantable Medical Devices

HAT: Secure and Practical Key Establishment for Implantable Medical Devices

Sayon Duttagupta, Eduard Marin, Dave Singelée, Bart Preneel

ACM CODASPY 2023 (Acceptance rate: 25.3%)


Updates


News, talks, and updates


  • 📄 Sep 2026 Our security analysis of Matter got accepted at IEEE S&P (Oakland) 2027! 🎉

  • 🧑‍⚖️ Aug 2026 Programme Committee member, USENIX Security 2027.

  • 🎤 Apr 2026 Presented WhisperPair at Black Hat Asia 2026 in Singapore.

  • 📄 Mar 2026 Our WhisperPair paper got accepted at IEEE S&P (Oakland) 2026! 🎉

  • 📄 Feb 2026 My first solo author paper HASAC got accepted at IFIP SEC 2026! 🎉

  • 🎓 Jan 2026 Defended my PhD! 🥳

  • 🗞️ Jan 2026 WhisperPair received broad media coverage, including WIRED and The New York Times. For a full list of coverage, see the media coverage section on the project website.


Extras

Research Projects

I have contributed to and coordinated research activities across national, regional, and European projects focused on security and privacy for connected and embedded systems.

  • FWO SPITE - Security and Privacy in an Internet of Things Environment (Grant #S002417N)

  • VLAIO TRUSTI - Secure remote software updates in IoT (Grant #HBC.2021.0742)

  • EU TELEMETRY - Trustworthy mEthodologies, open knowLedgE and autoMated tools for sEcurity Testing of IoT software, hardware, and ecosystems (Grant #101119747)



Academic Service

I serve on programme committees for security and cryptography venues, review for several others, and teach at KU Leuven.

Programme Committee

  • USENIX Security 2027
  • ACM WiSec 2024

External Review Committee

  • ACM WiSec 2026, 2025, 2023, 2022
  • USENIX Security 2025
  • ACNS 2025, 2024
  • CANS 2025
  • AfricaCrypt 2023, 2022
  • ESORICS 2022

Teaching

  • Fall 2025 – Cryptographic Protocols (H0Q28A)


Supervision

I have supervised master’s theses and research internships at KU Leuven and international partner institutions, covering applied cryptography, protocol design, and security analysis.

Master’s Theses

Research Internships

  • Daksh Pandey, 2026, Secure Communication Protocols for LLM-based Multi-Agent Systems
  • Abel Stuker, 2026, Security Analysis of CCC Digital Key 4.0
  • Romir Zadoo, 2026, Security Analysis of AirDrop ↔ Quick Share Interoperability
  • Pushkar Dube, 2026, Practical Attacks on Consumer UWB Devices
  • Lakshya Chopra, 2026, MRAE and Out-of-Order Modes in IoT Protocols
  • Neeranuch Jitkhajornwanich, 2026, Bidirectional AEAD Modes for IoT Protocols
  • Francesco Milizia, 2025, Symmetric Key Authentication with PFS for IoT Systems
  • Seppe Wyns, 2025, Security Analysis of the Google Fast Pair Protocol
  • Arman Kolozyan, 2024, Security Analysis of the Matter Protocol
  • Nikola Antonijević, 2022, Location based Device Commissioning
  • Quinten Pinkhof, 2021, Location based Authentication


Selected Media Coverage