Marian Margraf

dblp:14/4256 · DBLP profile ↗
← Back
9ranked-venue papers
0as first author
3since 2021 · last 2024
0009-0005-8577-1318ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Systems, architecture and hardware · 2Security and privacy · 2Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2024 Achieving Third-party Deniability in Signature-based Credential Systems
abstract
Fostering the widespread adoption of digital credentials requires trust and confidence within the civilian population, which needs to be facilitated through strong privacy guarantees. In this context, the concept of third-party deniability, i.e., a credential verifier's inability to prove the authenticity of received personal data to third parties, is particularly important. This work gives a structured overview of signature-based authentication mechanisms which offer third-party deniability and can be applied to the setting of a three-party credential system for digital identity documents. The resulting primitives are then compared with respect to practical challenges and requirements arising from credential systems.
Magdalena Bertram, Maximilian Richter, Marian Margraf
COMPSAC3
2024 A black-box attack on fixed-unitary quantum encryption schemes
abstract
Abstract We show how fixed-unitary quantum encryption schemes can be attacked in a black-box setting. We use an efficient technique to invert a unitary transformation on a quantum computer to retrieve an encrypted secret quantum state $${|{\psi }\rangle }$$ | ψ ⟩ . This attack has a success rate of 100% and can be executed in constant time. We name a vulnerable scheme which security is fully broken by our attack and suggest how to improve the scheme to invalidate this attack. The proposed attack highlights the importance of carefully designing quantum encryption schemes to ensure their security against quantum adversaries, even in a black-box setting. We point to the faulty assumption and name a criterion for future quantum cipher design to prevent similar vulnerabilities.
Cezary Pilaszewicz, Lea R. Muth, Marian Margraf
Discov. Comput.3
2023 Cryptographic Requirements of Verifiable Credentials for Digital Identification Documents
abstract
1663
Maximilian Richter, Magdalena Bertram, Jasper Seidensticker, Marian Margraf
COMPSAC4
2020 The Shift PUF: Technique for Squaring the Machine Learning Complexity of Arbiter-based PUFs: Work-in-Progress
abstract
The physically unclonable function (PUF) is a hardware cryptographic primitive that provides identifications based on inevitable manufacturing variations, thus, as the name states, being physically unclonable. The arbiter PUF (APUF, [5] ) is a well-studied PUF design based on variational signal delays in silicon/electronic components. Using APUFs as building blocks, XOR APUF ( [12] ), lightweight secure PUF ( [9] ), feed forward APUF ( [6] , [7] ), etc. are proposed and expected to be more secure PUF designs. However, it is discovered that all of these canonical arbiter-based PUF designs suffer from machine learning modeling attacks ( [1] , [3] , [11] ). Recently, the interpose PUF (iPUF, [10] ) is proposed as a new arbiter-based PUF design that is resilient to state-of-the-art machine learning attacks. In this paper we propose a new PUF design called shift PUF that directly enhances APUF (which, to remark, is the building block of all arbiter-based PUF designs) by, as a conjecture, squaring its machine learning complexity, and consequently brings the same squaring benefit to all arbiter-based PUFs as well. To emphasize, the shift PUF itself is not a secure PUF design, and the technique of substituting APUFs with shift PUFs also not necessarily turns insecure PUF designs into secure PUF designs (the notion of security immediately follows in the next paragraph); nevertheless the technique greatly benefits already secure arbiter-based PUF designs with squared machine learning complexities.
Donghang Wu, Yongzhi Cao, Marian Margraf
CASES4
2019 Breaking the Lightweight Secure PUF: Understanding the Relation of Input Transformations and Machine Learning Resistance
Nils Wisiol, Georg T. Becker, Marian Margraf, Tudor A. A. Soroceanu, Johannes Tobisch, Benjamin Zengin
CARDIS3
2019 Sample Essentiality and Its Application to Modeling Attacks on Arbiter PUFs
abstract
Physically Unclonable Functions (PUFs), as an alternative hardware-based security method, have been challenged by some modeling attacks. As is known to all, samples are significant in modeling attacks on PUFs, and thus, some efforts have been made to expand sample sets therein to improve modeling attacks. A closer examination, however, reveals that not all samples contribute to modeling attacks equally. Therefore, in this article, we introduce the concept of sample essentiality for describing the contribution of a sample in modeling attacks and point out that any sample without sample essentiality cannot enhance some modeling attacks on PUFs. As a by-product, we find theoretically and empirically that the samples expanded by the procedures proposed by Chatterjee et al. do not satisfy our sample essentiality. Furthermore, we propose the notion of essential sample sets for datasets and discuss its basic properties. Finally, we demonstrate that our results about sample essentiality can be used to reduce samples efficiently and benefit sample selection in modeling attacks on arbiter PUFs.
Siwen Zhu, Junxiang Zheng 0002, Yongzhi Cao, Hanpin Wang, Yu Huang 0004, Marian Margraf
ACM Trans. Embed. Comput. Syst.7
2018 Attacking RO-PUFs with Enhanced Challenge-Response Pairs
Nils Wisiol, Marian Margraf
SEC2
2017 Enhancing Breeder Document Long-Term Security Using Blockchain Technology
abstract
In contrast to electronic travel documents (e.g. ePassports), the standardisation of breeder documents (e.g. birth certificates), regarding harmonisation of content and contained security features is in statu nascendi. Due to the fact that breeder documents can be used as an evidence of identity and enable the application for electronic travel documents, they pose the weakest link in the identity life cycle and represent a security gap for identity management. In this work, we present a cost efficient way to enhance the long-term security of breeder documents by utilizing blockchain technology. A conceptual architecture to enhance breeder document long-term security and an introduction of the concept's constituting system components is presented. Our investigations provide evidence that the Bitcoin blockchain is most suitable for breeder document long-term security.
Nicolas Buchmann, Christian Rathgeb, Harald Baier, Christoph Busch 0001, Marian Margraf
COMPSAC (2)5
2014 On Valid and Optimal Deployments for Mixed-Tenancy Problems in SaaS-Applications
abstract
Software-as-a-Service (SaaS) is a delivery model whose basic idea is to provide applications to the customer on demand over the Internet. Thereby, SaaS promotes multi-tenancy as a tool to exploit economies of scale. A major drawback of SaaS is the customers' hesitation of sharing infrastructure, application code, or data with other tenants. The common way in research to address this problem is to create new approaches to implement and improve the tenants' isolation on a commonly used instance. Our approach, called mixed-tenancy approach, tackles this hesitation differently. It allows customers to choose with whom they want to share the instances of an application as well as the underlying infrastructure, and a valid deployment is computed in accordance with customer's constraints. This paper addresses the major algorithmic problem related to the mixed-tenancy approach. In particular, we analyze the problem of computing valid and optimal deployments. In doing so, we provide a theoretical analysis of the complexity of this problem, proposing several heuristics and discussing their quality.
Steffen Lange, Marian Margraf, Stefan T. Ruehl, Stephan A. W. Verclas
SERVICES2