Skip to content
View kamil-kielbasa's full-sized avatar

Block or report kamil-kielbasa

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
kamil-kielbasa/README.md

Hi, I'm Kamil

Embedded software engineer who likes to understand systems from first principles. I've been working professionally since 2018, mostly in C on IoT devices, focusing on secure communication, device provisioning, secure key management, cryptography and reliable storage.

LinkedIn Email

Open Source

A C implementation of EDHOC (RFC 9528), a lightweight authenticated key exchange for constrained IoT devices.

  • Handle-only key material: private keys and derived secrets stay in the key store (software, TrustZone or a secure element).
  • Post-quantum ready: the key exchange is modeled as a KEM, so post-quantum algorithms such as ML-KEM drop straight in.
  • PSK authentication: EDHOC-PSK for a lighter handshake, with session resumption.
  • Portable: runs on Linux, macOS and Zephyr RTOS, with no heap required.
  • Quality: verified against the RFC 9529 test vectors, with static analysis, sanitizers and fuzzing in CI.

A volume manager for raw flash on Zephyr RTOS, based on the design of Linux UBI.

  • Named volumes: created, resized and removed at runtime, with wear spread across the whole partition.
  • Power-loss safe: a block update either completes or leaves the old data intact.
  • Authenticated metadata: AES-CMAC over headers and the volume table, with damage and tampering reported separately.
  • Built for microcontrollers: no background threads and small, predictable stack usage.
  • Quality: model-based tests with injected power cuts, fuzzing, and testing on real hardware.

Other projects

  • AeternusDB: an embeddable, persistent key-value store in Rust, built on an LSM-tree.

Background

  • Software Engineer at ASSA ABLOY, Core IoT team
  • M.Sc. Eng. in Automation and Robotics, Wrocław University of Science and Technology

Popular repositories Loading

  1. libedhoc libedhoc Public

    EDHOC (RFC 9528): Lightweight authenticated key exchange in C for constrained IoT devices, post-quantum ready

    C 24 8

  2. aeternusdb aeternusdb Public

    An embeddable, persistent key-value store built on an LSM-tree architecture.

    Rust 6

  3. zephyr-ubi zephyr-ubi Public

    Wear-leveling volume manager for raw NOR flash on Zephyr RTOS, with authentication (AES-CMAC via PSA Crypto).

    C 3

  4. ai-infrastructure-book ai-infrastructure-book Public

    A field guide to running large language models on your own hardware — from a single laptop to a shared cluster. AI-drafted, human-reviewed.

    TypeScript 3

  5. ubi ubi Public

    Wear-leveling volume manager for raw NOR/NAND flash on Zephyr RTOS, with optional authenticated encryption (AES-128-CCM via PSA Crypto).

    C 1 1

  6. yubihsm2-aws-kms-byok yubihsm2-aws-kms-byok Public

    Key import from YubiHSM 2 FIPS to AWS KMS

    1