VLDB 2026 Research / reviewers in the wild / expert
Philipp Mundhenk
dblp:130/1360
· DBLP profile ↗
15ranked-venue papers
5as first author
4since 2021 · last 2024
0000-0001-6132-3901ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 11 · 5 first-author · 2 since 2021Software engineering, systems software and programming languages · 3 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Introduction to the Special Issue on Automotive CPS Safety & Security: Part 2abstractresearch-article Share on Introduction to the Special Issue on Automotive CPS Safety & Security: Part 2 Authors: Samarjit Chakraborty The University of North Carolina at Chapel Hill, Chapel Hill, United States The University of North Carolina at Chapel Hill, Chapel Hill, United States 0000-0002-0503-6235View Profile , Somesh Jha University of Wisconsin-Madison, Madison, United States University of Wisconsin-Madison, Madison, United States 0000-0001-5877-0436View Profile , Soheil Samii Linköping University, Linkoping, Sweden Linköping University, Linkoping, Sweden 0000-0002-9572-1091View Profile , Philipp Mundhenk Robert Bosch GmbH, Renningen, Germany Robert Bosch GmbH, Renningen, Germany 0000-0001-6132-3901View Profile Authors Info & Claims ACM Transactions on Cyber-Physical SystemsVolume 8Issue 2Article No.: 10pp 1–17https://doi.org/10.1145/3650210Published:15 May 2024Publication History 0citation71DownloadsMetricsTotal Citations0Total Downloads71Last 12 Months71Last 6 weeks42 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Publisher SiteGet Access Samarjit Chakraborty, Somesh Jha, Soheil Samii, Philipp Mundhenk |
ACM Trans. Cyber Phys. Syst. | 4 |
| 2023 | The Cyber-Physical Metaverse - Where Digital Twins and Humans Come TogetherabstractThe concept of Digital Twins (DTs) has been discussed intensively for the past couple of years. Today we have instances of digital twins that range from static descriptions of manufacturing data and material properties over live interfaces on operational data of cyber physical systems to the functions and services they provide. Currently, there are no standardized interfaces to aggregate atomic DTs (e.g., the twin of the lowest-level function of a machine) to higher-level DTs providing more complex services in the virtual world. Additionally, there is no existing infrastructure to reliably link the DTs in the virtual world to the integrated CPSs in the physical world, such as a car consisting of many ECUs with even more functions. The concept of the Metaverse is gaining increasing traction and has been explored from different angles, usually centered around a human user, true to its original definition. Beyond social interactions, the Metaverse offers possibilities to integrate layers of interconnected Digital Twins (DTs) representing parts of and interacting with the physical world in real-time, enabling not only analysis and representation of current state, but also feedback loops and control. This paper describes how the Metaverse can become the virtual world where DTs of humans and machines live, and how to reliably connect DTs to the physical world. Dirk Elias, Dirk Ziegenbein, Philipp Mundhenk, Arne Hamann 0001, Anthony Rowe 0001 |
DATE | 3 |
| 2023 | Introduction to the Special Issue on Automotive CPS Safety & Security: Part 1abstractresearch-article Free Access Share on Introduction to the Special Issue on Automotive CPS Safety & Security: Part 1Just Accepted Authors: Samarjit Chakraborty University of North Carolina at Chapel Hill, USA University of North Carolina at Chapel Hill, USASearch about this author , Somesh Jha University of Wisconsin-Madison, USA University of Wisconsin-Madison, USASearch about this author , Soheil Samii Linköping University, Sweden Linköping University, SwedenSearch about this author , Philipp Mundhenk Robert Bosch GmbH, Germany Robert Bosch GmbH, GermanySearch about this author Authors Info & Claims ACM Transactions on Cyber-Physical SystemsAccepted on February 2023 https://doi.org/10.1145/3579986Published:23 February 2023Publication History 0citation0DownloadsMetricsTotal Citations0Total Downloads0Last 12 Months0Last 6 weeks0 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteeReaderPDF Samarjit Chakraborty, Somesh Jha, Soheil Samii, Philipp Mundhenk |
ACM Trans. Cyber Phys. Syst. | 4 |
| 2022 | Reliable Distributed SystemsabstractThe domains of Cyber-Physical Systems (CPSs) and Information Technology (IT) are converging. Driven by the need for increased compute performance, as well as the need for increased connectivity and runtime flexibility, IT hardware, such as microprocessors and Graphics Processing Units (GPUs), as well as software abstraction layers are introduced to CPS. These systems and components are being enhanced for the execution of hard real-time applications. This enables the convergence of embedded and IT: Embedded workloads can be executed reliably on top of IT infrastructure. This is the dawn of Reliable Distributed Systems (RDSs), a technology that combines the performance and cost of IT systems with the reliability of CPSs. The Fabric is a global RDS runtime environment, weaving the interconnections between devices and enabling abstractions for compute, communication, storage, sensing & actuation. This paper outlines the vision of RDS, introduces the aspects required for implementing RDSs and the Fabric, relates existing technologies, and outlines open research challenges. Philipp Mundhenk, Arne Hamann 0001, Andreas Heyl, Dirk Ziegenbein |
DATE | 1 |
| 2018 | Dynamic vehicle software with AUTOCONTabstractFuture automotive software needs to deal with an increasing level of dynamicity, reasoned by the wish for connected driving, software updates, and dynamic feature activation. Such functionalities cannot be properly realized with today's classic AUTOSAR development approach, since it relies on the static configuration of all software units at build time. Christine Jakobs, Peter Tröger, Matthias Werner 0001, Philipp Mundhenk, Karsten Schmidt 0003 |
DAC | 4 |
| 2017 | Dynamic Platforms for Uncertainty Management in Future Automotive E/E Architectures: InvitedabstractCurrent automotive E/E architectures are comprised of hardware and software and are mostly designed in a monolithic approach, static over the lifetime of the vehicle. Design, implementation and updates are mostly performed on a per-component-basis, exchanging complete Electronic Control Units (ECUs) or their software image as a whole. With an increasing amount of functionality being realized in software, the benefits of software can be used increasingly. This includes modularization of components, which forms the basis for updates and addition of functions. Additionally, this modularization allows the consolidation of ECUs and supports a higher level of integration. Such modularization and dynamic behavior over the lifetime of a vehicle feet, as well as a single vehicle does, however, hold a lot of challenges for safety-critical systems. Safety-critical systems, such as cars, require their behavior to be deterministic. The design of such modular systems needs to consider and cope with uncertainties in modular architectures. This paper highlights some of the dimensions of uncertainty, which will exist in future E/E architectures and presents initial approaches on how to manage these. Philipp Mundhenk, Ghizlane Tibba, Licong Zhang, Felix Reimann, Debayan Roy, Samarjit Chakraborty |
DAC | 1 |
| 2017 | VEGa: A High Performance Vehicular Ethernet Gateway on Hybrid FPGAabstractModern vehicles employ a large amount of distributed computation and require the underlying communication scheme to provide high bandwidth and low latency. Existing communication protocols like Controller Area Network (CAN) and FlexRay do not provide the required bandwidth, paving the way for adoption of Ethernet as the next generation network backbone for in-vehicle systems. Ethernet would co-exist with safety-critical communication on legacy networks, providing a scalable platform for evolving vehicular systems. This requires a high-performance network gateway that can simultaneously handle high bandwidth, low latency, and isolation; features that are not achievable with traditional processor based gateway implementations. We present VEGa, a configurable vehicular Ethernet gateway architecture utilising a hybrid FPGA to closely couple software control on a processor with dedicated switching circuit on the reconfigurable fabric. The fabric implements isolated interface ports and an accelerated routing mechanism, which can be controlled and monitored from software. Further, reconfigurability enables the switching behaviour to be altered at runtime under software control, while the configurable architecture allows easy adaptation to different vehicular architectures using highlevel parameter settings. We demonstrate the architecture on the Xilinx Zynq platform and evaluate the bandwidth, latency, and isolation using extensive tests in hardware. Shanker Shreejith, Philipp Mundhenk, Andreas Ettner, Suhaib A. Fahmy, Sebastian Steinhorst, Martin Lukasiewycz, Samarjit Chakraborty |
IEEE Trans. Computers | 2 |
| 2017 | Automotive Electrical and Electronic Architecture Security via Distributed In-Vehicle Traffic MonitoringabstractDue to the growing interconnectedness and complexity of in-vehicle networks, in addition to safety, security is becoming an increasingly important topic in the automotive domain. In this paper, we study techniques for detecting security infringements in automotive electrical and electronic (E/E) architectures. Toward this we propose in-vehicle network traffic monitoring to detect increased transmission rates of manipulated message streams. Attacks causing timing violations can disrupt safety-critical functions and have severe consequences. To reduce costs and prevent single points of failure, our approach enables an automatic distribution of detection tasks among selected E/E architecture components, such as a subset of electronic control units. First, we analyze a concrete E/E system architecture to determine the communication parameters and properties necessary for detecting security attacks. These are then used for a parametrization of the corresponding detection algorithms and the distribution of attack detection tasks. We use a lightweight message monitoring method and optimize the placement of detection tasks to ensure a full-coverage of the E/E system architecture and a timely detection of an attack. Peter Waszecki, Philipp Mundhenk, Sebastian Steinhorst, Martin Lukasiewycz, Ramesh Karri, Samarjit Chakraborty |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2017 | Security in Automotive Networks: Lightweight Authentication and AuthorizationabstractWith the increasing amount of interconnections between vehicles, the attack surface of internal vehicle networks is rising steeply. Although these networks are shielded against external attacks, they often do not have any internal security to protect against malicious components or adversaries who can breach the network perimeter. To secure the in-vehicle network, all communicating components must be authenticated, and only authorized components should be allowed to send and receive messages. This is achieved through the use of an authentication framework. Cryptography is widely used to authenticate communicating parties and provide secure communication channels (e.g., Internet communication). However, the real-time performance requirements of in-vehicle networks restrict the types of cryptographic algorithms and protocols that may be used. In particular, asymmetric cryptography is computationally infeasible during vehicle operation. In this work, we address the challenges of designing authentication protocols for automotive systems. We present Lightweight Authentication for Secure Automotive Networks (LASAN), a full lifecycle authentication approach. We describe the core LASAN protocols and show how they protect the internal vehicle network while complying with the real-time constraints and low computational resources of this domain. By leveraging the fixed structure of automotive networks, we minimize bandwidth and computation requirements. Unlike previous work, we also explain how this framework can be integrated into all aspects of the automotive product lifecycle, including manufacturing, vehicle maintenance, and software updates. We evaluate LASAN in two different ways: First, we analyze the security properties of the protocols using established protocol verification techniques based on formal methods. Second, we evaluate the timing requirements of LASAN and compare these to other frameworks using a new highly modular discrete event simulator for in-vehicle networks, which we have developed for this evaluation. Philipp Mundhenk, Andrew Paverd, Artur Mrowca, Sebastian Steinhorst, Martin Lukasiewycz, Suhaib A. Fahmy, Samarjit Chakraborty |
ACM Trans. Design Autom. Electr. Syst. | 1 |
| 2016 | Schedule Management Framework for Cloud-Based Future Automotive Software SystemsabstractThe innovation in the automotive domain is shifting considerably to the Electrical/Electronics system and software. The evolution cycle of the electronic system and the software is significantly shorter than the life cycle of a vehicle and therefore the functionality of a vehicle might become 'outdated' easily in the future. Thus, it would be advantageous if new applications can be installed or existing applications can be upgraded via cloud services after sales in a plug-and-play fashion. This requires that the underlying system possesses a certain degree of adaptivity and reconfigurability. One important issue in this case is the allocation of computation and communication resources. In the case of a time-triggered system, the task and network schedules need to be adapted to accommodate new applications. Towards addressing this problem, we propose a schedule management framework to obtain, synthesize and manage schedules efficiently online for Ethernet-based time-triggered systems in the automotive context. This framework is based on a client-server architecture and each side consists of a web module, a synthesis module and a configuration pool. It utilizes the Internet access of modern vehicles to exploit the computation and storage capacity on the server in a cloud-computing manner and can facilitate the reuse of generated schedule sets. In the synthesis module, a four-stage strategy is introduced to reduce the synthesis time and the disturbance to existing applications. The experimental results show that the proposed framework can be applied to generate and manage schedules online and benefit from both onboard and cloud-based schedule synthesis. The result also shows the applicability of the introduced four-stage synthesis~strategy. Licong Zhang, Debayan Roy, Philipp Mundhenk, Samarjit Chakraborty |
RTCSA | 3 |
| 2016 | Security-Aware Obfuscated Priority Assignment for Automotive CAN PlatformsabstractSecurity in automotive in-vehicle networks is an increasing problem with the growing connectedness of road vehicles. This article proposes a security-aware priority assignment for automotive controller area network (CAN) platforms with the aim of mitigating scaling effects of attacks on vehicle fleets. CAN is the dominating field bus in the automotive domain due to its simplicity, low cost, and robustness. While messages might be encrypted to enhance the security of CAN systems, their priorities are usually identical for automotive platforms, comprising generally a large number of vehicle models. As a result, the identifier uniquely defines which message is sent, allowing attacks to scale across a fleet of vehicles with the same platform. As a remedy, we propose a methodology that is capable of determining obfuscated message identifiers for each individual vehicle. Since identifiers directly represent message priorities, the approach has to take the resulting response time variations into account while satisfying application deadlines for each vehicle schedule separately. Our approach relies on Quadratically Constrained Quadratic Program (QCQP) solving in two stages, specifying first a set of feasible fixed priorities and subsequently bounded priorities for each message. With the obtained bounds, obfuscated identifiers are determined, using a very fast randomized sampling. The experimental results, consisting of a large set of synthetic test cases and a realistic case study, give evidence of the efficiency of the proposed approach in terms of scalability. The results also show that the diversity of obtained identifiers is effectively optimized with our approach, resulting in a very good obfuscation of CAN messages in in-vehicle communication. Martin Lukasiewycz, Philipp Mundhenk, Sebastian Steinhorst |
ACM Trans. Design Autom. Electr. Syst. | 2 |
| 2015 | Security analysis of automotive architectures using probabilistic model checkingabstractThis paper proposes a novel approach to security analysis of automotive architectures at the system-level. With an increasing amount of software and connectedness of cars, security challenges are emerging in the automotive domain. Our proposed approach enables assessment of the security of architecture variants and can be used by decision makers in the design process. First, the automotive Electronic Control Units (ECUs) and networks are modelled at the system-level using parameters per component, including an exploitability score and patching rates that are derived from an automated or manual assessment. For any specific architecture variant, a Continuous-Time Markov Chain (CTMC) model is determined and analyzed in terms of confidentiality, integrity and availability, using probabilistic model checking. The introduced case study demonstrates the applicability of our approach, enabling, for instance, the exploration of parameters like patch rate targets for ECU manufacturers. Philipp Mundhenk, Sebastian Steinhorst, Martin Lukasiewycz, Suhaib A. Fahmy, Samarjit Chakraborty |
DAC | 1 |
| 2015 | Lightweight authentication for secure automotive networks
Philipp Mundhenk, Sebastian Steinhorst, Martin Lukasiewycz, Suhaib A. Fahmy, Samarjit Chakraborty |
DATE | 1 |
| 2013 | System architecture and software design for electric vehiclesabstractThis paper gives an overview of the system architecture and software design challenges for Electric Vehicles (EVs). First, we introduce the EV-specific components and their control, considering the battery, electric motor, and electric powertrain. Moreover, technologies that will help to advance safety and energy efficiency of EVs such as drive-by-wire and information systems are discussed. Regarding the system architecture, we present challenges in the domain of communication and computation platforms. A paradigm shift towards time-triggered in-vehicle communication systems becomes inevitable for the sake of determinism, making the introduction of new bus systems and protocols necessary. At the same time, novel computational devices promise high processing power at low cost which will make a reduction in the number of Electronic Control Units (ECUs) possible. As a result, the software design has to be performed in a holistic manner, considering the controlled component while transparently abstracting the underlying hardware architecture. For this purpose, we show how middleware and verification techniques can help to reduce the design and test complexity. At the same time, with the growing connectivity of EVs, security has to become a major design objective, considering possible threats and a security-aware design as discussed in this paper. Martin Lukasiewycz, Sebastian Steinhorst, Sidharta Andalam, Florian Sagstetter, Peter Waszecki, Wanli Chang 0001, Matthias Kauer, Philipp Mundhenk, Shanker Shreejith, Suhaib A. Fahmy, Samarjit Chakraborty |
DAC | 8 |
| 2013 | HMI development for a purpose-built electric taxi in SingaporeabstractIn this paper, we describe the development process of a human-machine interface (HMI) for a purpose-built electric taxi in Singapore. Based on the requirements of taxi drivers and passengers, we developed an automo-tive communication structure to support the connectivity between the vehicle HMI and mobile devices, support taxi-related functionalities and emphasize the charac-teristics of the electric vehicle. We carried out seven requirement studies in Singapore, implemented an integrated HMI platform, and developed different inter-face prototypes for the vehicle HMI and smart devices. This work contributes to the emerging field of automo-tive user interfaces by proposing a fully integrated HMI for an electric taxi. Sebastian Osswald, Daniel Zehe, Philipp Mundhenk, Pratik Sheth, Martin Schaller, Stephan Schickram, Daniel Gleyzes |
Mobile HCI | 3 |