VLDB 2026 Research / reviewers in the wild / expert
Carsten Weinhold
dblp:01/2772
· DBLP profile ↗
9ranked-venue papers
3as first author
4since 2021 · last 2026
0009-0005-5124-9513ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 7 · 3 first-author · 3 since 2021Software engineering, systems software and programming languages · 4 · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | TEEM³: Core-Independent and Cooperating Trusted Execution EnvironmentsabstractTrusted Execution Environments (TEEs) enable secure code execution on machines that are not fully trusted by the user who runs the workload. However, existing TEE solutions mostly target CPUs and are typically tied to one specific instruction set architecture. Although some accelerators also provide support for TEEs, this leads to multiple, different TEE implementations on the same system, increasing its complexity and trusted computing base (TCB). This challenge becomes particularly apparent when workloads span heterogeneous processing units, because the diversity of TEE implementations complicates the creation of secure communication channels between the individual TEEs. Nils Asmussen, Sebastian Haas, Carsten Weinhold, Nicholas Gordon, Stephan Gerhold, Friedrich Pauls, Nilanjana Das, Michael Roitzsch |
ASPLOS (2) | 3 |
| 2025 | Applying Modern Verification Techniques to a Root-of-Trust BootloaderabstractVerification tools have become more approachable over the last few years, especially those that allow developers to write proof annotations in the target programming language they already know. We applied one such tool, Verus, to the root-of-trust bootloader of an embedded platform. We report from the point of view of a systems developer, who wants to use verification as a quality-assurance tool for an existing codebase, which was not written with verification in mind. We discuss how we specified a key security property using pre- and post-conditions in the source code, guiding Verus to prove that this property does indeed hold. Nicholas Gordon, Carsten Weinhold |
PLOS@SOSP | 2 |
| 2025 | Separate but Together: Integrating Remote Attestation into TLS
Carsten Weinhold, Muhammad Usama Sardar, Ionut Mihalcea, Yogesh Deshpande, Hannes Tschofenig, Yaron Sheffer, Thomas Fossati, Michael Roitzsch |
USENIX ATC | 1 |
| 2022 | Efficient and scalable core multiplexing with M³vabstractThe M³ system (ASPLOS ’16) proposed a hardware/software co-design that simplifies integration between general-purpose cores and special-purpose accelerators, allowing users to easily utilize them in a unified manner. M³ is a tiled architecture, whose tiles (cores and accelerators) are partitioned between applications, such that each tile is dedicated to its own application. The M³x system (ATC ’19) extended M³ by trading off some isolation to enable coarse-grained multiplexing of tiles among multiple applications. With M³x, if source tile t₁ runs code of application p and sends a message m to destination tile t₂ while t₂ is currently not associated with p, then m is forwarded to the right place through a “slow path”, via some special OS tile. In this paper, we present M³v, which extends M³x by further trading off some isolation between applications to support “fast path” communication that does not require the said OS tile’s involvement. Thus, with M³v, a tile can be efficiently multiplexed between applications provided it is a general-purpose core. M³v achieves this goal by 1) adding a local multiplexer to each such core, and by 2) virtualizing the core’s hardware component responsible for cross-tile communications. We prototype M³v using RISC-V cores on an FPGA platform and show that it significantly outperforms M³x and may achieve competitive performance to Linux. Nils Asmussen, Sebastian Haas, Carsten Weinhold, Till Miemietz, Michael Roitzsch |
ASPLOS | 3 |
| 2019 | Corrected trees for reliable group communicationabstractDriven by ever increasing performance demands of compute-intensive applications, supercomputing systems comprise more and more nodes. This growth is a significant burden for fast group communication primitives and also makes those systems more susceptible to failures of individual nodes. In this paper we present a two-phase fault-tolerant scheme for group communication. Using broadcast as an example, we provide a full-spectrum discussion of our approach --- from a formal analysis to LogP-based simulations to a message-passing-based implementation running on a large cluster. Ultimately, we are able to reduce the complex problem of reliable and fault-tolerant collective group communication to a graph theoretical renumbering problem. Both, simulations and measurements, show our solution to achieve a latency reduction of 50% with up to six times fewer messages sent in comparison to existing schemes. Martin Küttler, Maksym Planeta, Jan Bierbaum, Carsten Weinhold, Hermann Härtig, Amnon Barak, Torsten Hoefler |
PPoPP | 4 |
| 2017 | Lateral Thinking for Trustworthy AppsabstractThe growing computerization of critical infrastructure as well as the pervasiveness of computing in everyday life has led to increased interest in secure application development. We observe a flurry of new security technologies like ARM TrustZone and Intel SGX, but a lack of a corresponding architectural vision. We are convinced that point solutions are not sufficient to address the overall challenge of secure system design. In this paper, we outline our take on a trusted component ecosystem of small individual building blocks with strong isolation. In our view, applications should no longer be designed as massive stacks of vertically layered frameworks, but instead as horizontal aggregates of mutually isolated components that collaborate across machine boundaries to provide a service. Lateral thinking is needed to make secure systems going forward. Hermann Härtig, Michael Roitzsch, Carsten Weinhold, Adam Lackorzynski |
ICDCS | 3 |
| 2017 | Sandcrust: Automatic Sandboxing of Unsafe Components in RustabstractSystem-level development has been dominated by traditional programming languages such as C and C++ for decades. These languages are inherently unsafe regarding memory management. Even experienced developers make mistakes that open up security holes or compromise the safety properties of software. The Rust programming language is targeted at the systems domain and aims to eliminate memory-related programming errors by enforcing a strict memory model at the language and compiler level. Unfortunately, these compile-time guarantees no longer hold when a Rust program is linked against a library written in unsafe C, which is commonly required for functionality where an implementation in Rust is not yet available. Benjamin Lamowski, Carsten Weinhold, Adam Lackorzynski, Hermann Härtig |
PLOS@SOSP | 2 |
| 2011 | jVPFS: Adding Robustness to a Secure Stacked File System with Untrusted Local Storage Components
Carsten Weinhold |
USENIX ATC | 1 |
| 2008 | VPFS: building a virtual private file system with a small trusted computing baseabstractIn this paper we present the lessons we learned when developing VPFS, a virtual private file system that is based on both a small amount of trusted storage and an untrusted legacy file system residing on the same machine. VPFS' purpose is to provide secure and reliable storage to highly sensitive applications running on top of a microkernel, which may concurrently execute untrusted software. The confidentiality and integrity guarantees of VPFS do not only apply to file contents, but also to all meta data including integrity of the directory structure. Carsten Weinhold, Hermann Härtig |
EuroSys | 1 |