
Sayon Duttagupta
Postdoctoral Researcher in COSIC at KU Leuven
Applied Cryptography & IoT Security
About Me
👋 Hi! I’m Sayon, a postdoctoral researcher in the COSIC research group at KU Leuven. I recently defended my PhD, Analysis and Design of Cryptographic Protocols for IoT Devices, under the supervision of Bart Preneel and Dave Singelée.
My research examines how cryptographic protocols behave in real connected systems once they are embedded into products, standards, and large-scale ecosystems. I work at the intersection of applied cryptography, wireless security, and usable security, with a focus on IoT and cyber-physical systems where security decisions are shaped by usability, deployment constraints, and user interaction.
A core theme of my work is secure device onboarding at scale. I study authentication, pairing, and key establishment protocols for constrained and consumer-facing devices, analysing how convenience-driven design choices can introduce subtle but serious security and privacy risks. Through a combination of protocol analysis, system-level evaluation, and empirical experimentation, I aim to uncover these weaknesses and provide principled guidance for more robust designs.
More broadly, my interests include protocol design and analysis for embedded and wireless systems, key management in resource-constrained environments, security mechanisms that rely on proximity and context, and the tension between usability and security in modern connected products. Across my work, I focus on real-world cryptography, analysing how security protocols interact with deployment constraints, wireless environments, and system-level realities.
My Erdős number is 4, and my Dijkstra number is 4. Outside research, I enjoy racquet sports, exploring gastronomy, learning new languages, and the occasional dive into etymology and politics.
Please feel free to get in touch!
Selected Publications
Cite
@inproceedings{Matter,
author = {Duttagupta, Sayon and Kolozyan, Arman and Nicolas, Georgio and Singel{\'e}e, Dave and Preneel, Bart},
title = {{What's the Matter? An In-Depth Security Analysis of the Matter Protocol}},
booktitle = {2027 IEEE Symposium on Security and Privacy (S\&P)},
year = {2027},
note = {To appear}
}
Cite
@inproceedings{WhisperPair,
author = {Duttagupta, Sayon and Wyns, Seppe and Antonijevi{\'c}, Nikola and Singel{\'e}e, Dave and Preneel, Bart},
title = {{One Tap to Hijack Them All: A Security Analysis of the Google Fast Pair Protocol}},
booktitle = {2026 IEEE Symposium on Security and Privacy (S\&P)},
doi = {10.1109/SP63933.2026.00210},
pages = {1--18},
year = {2026}
}
Cite
@inproceedings{HASAC,
author = {Duttagupta, Sayon},
title = {{HASAC: Energy Adaptive Secure Firmware Updates for Critical IoT Systems}},
booktitle = {IFIP SEC},
year = {2026},
note = {To appear}
}Cite
@inproceedings{CARPOOL,
author = {Duttagupta, Sayon and Singel{\'e}e, Dave and Carpent, Xavier and Yoshizawa, Takahito and Aghili, Farhad and Abidin, Aysajan and Preneel, Bart},
title = {{CARPOOL: Secure And Reliable Proof of Location}},
booktitle = {Proceedings of the 31st ACM Symposium on Access Control Models and Technologies},
series = {SACMAT '26},
doi = {10.1145/3750555.3811885},
pages = {168--179},
numpages = {12},
year = {2026}
}
Cite
@inproceedings{HAT-imd,
author = {Duttagupta, Sayon and Marin, Eduard and Singel\'{e}e, Dave and Preneel, Bart},
title = {{HAT: Secure and Practical Key Establishment for Implantable Medical Devices}},
booktitle = {Proceedings of the Thirteenth ACM Conference on Data and Application Security and Privacy},
doi = {10.1145/3577923.3583646},
pages = {213–224},
numpages = {12},
series = {CODASPY '23},
year = {2023}
}
My PGP Public Key
-----BEGIN PGP PUBLIC KEY BLOCK----- xjMEZwll9xYJKwYBBAHaRw8BAQdAOCoOT1nDI9D9aPaAy9D120dxG/eCvlltKZlK vXXQkyPNNFNheW9uIER1dHRhZ3VwdGEgPFNheW9uLkR1dHRhZ3VwdGFAZXNhdC5r dWxldXZlbi5iZT7CjwQTFggANxYhBHFaPNeW4Xva48Sn6vFLRsI7KTa5BQJnCWX3 BQkFo5qAAhsDBAsJCAcFFQgJCgsFFgIDAQAACgkQ8UtGwjspNrmTqAEAxxxAxKGY th5FEeF3UYHsw2Ig7QEK0jIvS+/eyu5g2gwA/j5XSv2i1HVKOzkNbk2ORvGvCMR7 2QKt7NcGP7pTrsgCzjgEZwll+BIKKwYBBAGXVQEFAQEHQJOu8SgOwWO7HMI8yns+ C12vLqkkLkByL1VGeWBulHZQAwEIB8J+BBgWCAAmFiEEcVo815bhe9rjxKfq8UtG wjspNrkFAmcJZfgFCQWjmoACGwwACgkQ8UtGwjspNrn7uwEAgwpVrY1DadpwF+I3 0eEEdoRAJKfoZRHpGi/LN7iXcYIA/0CDY7MQMXYYAsTo+mkW5AEuDUpQDNLuznTe xkDt+McO =qmfs -----END PGP PUBLIC KEY BLOCK-----
Updates
News, talks, and updates
📄 Sep 2026 Our security analysis of Matter got accepted at IEEE S&P (Oakland) 2027! 🎉
🧑⚖️ Aug 2026 Programme Committee member, USENIX Security 2027.
🎤 Apr 2026 Presented WhisperPair at Black Hat Asia 2026 in Singapore.
📄 Mar 2026 Our WhisperPair paper got accepted at IEEE S&P (Oakland) 2026! 🎉
📄 Feb 2026 My first solo author paper HASAC got accepted at IFIP SEC 2026! 🎉
🎓 Jan 2026 Defended my PhD! 🥳
🗞️ Jan 2026 WhisperPair received broad media coverage, including WIRED and The New York Times. For a full list of coverage, see the media coverage section on the project website.
Extras
Research Projects
I have contributed to and coordinated research activities across national, regional, and European projects focused on security and privacy for connected and embedded systems.
FWO SPITE - Security and Privacy in an Internet of Things Environment (Grant #S002417N)
VLAIO TRUSTI - Secure remote software updates in IoT (Grant #HBC.2021.0742)
EU TELEMETRY - Trustworthy mEthodologies, open knowLedgE and autoMated tools for sEcurity Testing of IoT software, hardware, and ecosystems (Grant #101119747)
Academic Service
I serve on programme committees for security and cryptography venues, review for several others, and teach at KU Leuven.
Programme Committee
- USENIX Security 2027
- ACM WiSec 2024
External Review Committee
- ACM WiSec 2026, 2025, 2023, 2022
- USENIX Security 2025
- ACNS 2025, 2024
- CANS 2025
- AfricaCrypt 2023, 2022
- ESORICS 2022
Teaching
- Fall 2025 – Cryptographic Protocols (H0Q28A)
Supervision
I have supervised master’s theses and research internships at KU Leuven and international partner institutions, covering applied cryptography, protocol design, and security analysis.
Master’s Theses
Supriyo Banerjee (ISI Kolkata, India), 2024 – 2025, Multi party Key Establishment for Resource Constrained Devices
Rachit Parikh (ISI Kolkata, India), 2022 – 2023, TKBE: Two Key Broadcast Encryption for the IoT
Nikola Antonijević (ESAT, KU Leuven), 2022 – 2023, Secure Path Verification in Software Defined Networks
Ward van Gerwen (Computer Science, KU Leuven), 2021 – 2022, Blockchain Based Data Management System in an IoT Environment
Research Internships
- Daksh Pandey, 2026, Secure Communication Protocols for LLM-based Multi-Agent Systems
- Abel Stuker, 2026, Security Analysis of CCC Digital Key 4.0
- Romir Zadoo, 2026, Security Analysis of AirDrop ↔ Quick Share Interoperability
- Pushkar Dube, 2026, Practical Attacks on Consumer UWB Devices
- Lakshya Chopra, 2026, MRAE and Out-of-Order Modes in IoT Protocols
- Neeranuch Jitkhajornwanich, 2026, Bidirectional AEAD Modes for IoT Protocols
- Francesco Milizia, 2025, Symmetric Key Authentication with PFS for IoT Systems
- Seppe Wyns, 2025, Security Analysis of the Google Fast Pair Protocol
- Arman Kolozyan, 2024, Security Analysis of the Matter Protocol
- Nikola Antonijević, 2022, Location based Device Commissioning
- Quinten Pinkhof, 2021, Location based Authentication
Selected Media Coverage
- WIRED, “Hundreds of Millions of Audio Devices Need a Patch to Prevent Wireless Hacking and Tracking” by Andy Greenberg and Lily Hay Newman
- The New York Times, “Wireless Earbuds Can Be Hacked. Here’s How to Protect Yourself by Max Eddy
- Engadget, “Flaw in 17 Google Fast Pair audio devices could let hackers eavesdrop” by Will Shanklin
- The Register, “Fast Pair, loose security: Bluetooth accessories open to silent hijack” by Carly Page
- The Verge, “Sony, Anker, and other headphones have a serious Google Fast Pair security vulnerability” by Andrew Liszewski