VLDB 2026 Research / reviewers in the wild / expert
Richard Habeeb
dblp:203/0872 · also Richard Thomas Habeeb
· DBLP profile ↗
2ranked-venue papers
2as first author
2since 2021 · last 2026
0009-0000-2368-1177ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 1 · 1 first-author · 1 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
1 paper |
Hardware security and side channels · 100% | |
| Software engineering, system software, and programming languages
1 paper |
Operating systems · 100% | |
| Computer architecture, parallel and distributed computing, and storage systems
1 paper |
Embedded and real-time systems · 100% |
Topics — the 4 heaviest of 5, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Hardware security and side channels › trusted execution environments
ARM TrustZone |
1.0 | 1 | 2026 | Ringmaster: How to juggle high-throughput host OS system calls from TrustZone TEEs · MobiSys 2026 |
Hardware security and side channels
trusted execution environments |
1.0 | 1 | 2026 | Ringmaster: How to juggle high-throughput host OS system calls from TrustZone TEEs · MobiSys 2026 |
Operating systems › operating system interface
system call |
0.3 | 1 | 2026 | Ringmaster: How to juggle high-throughput host OS system calls from TrustZone TEEs · MobiSys 2026 |
Embedded and real-time systems › critical systems
safety-critical systems |
0.3 | 1 | 2026 | Ringmaster: How to juggle high-throughput host OS system calls from TrustZone TEEs · MobiSys 2026 |
Methods — techniques the papers use, named apart from their topics
io_uring · 3.0asynchronous system call · 3.0
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Ringmaster: How to juggle high-throughput host OS system calls from TrustZone TEEsabstractMany safety-critical systems require the timely processing of sensor inputs to avoid potential safety hazards. Additionally, to support useful application features, such systems increasingly have a large, rich operating system (OS) at the cost of potential security bugs. Thus, if a malicious party gains supervisor privileges, they could cause real-world damage by denying service to time-sensitive programs. Many past approaches to this problem completely isolate time-sensitive programs with a hypervisor; however, this prevents the programs from accessing useful OS services. We introduce Ringmaster, a novel framework that enables enclaves or TEEs (Trusted Execution Environments) to asynchronously access rich, but potentially untrusted, OS services via Linux's io_uring. When the untrusted OS denies service, enclaves continue to operate on Ringmaster's minimal ARM TrustZone kernel with access to small, critical device drivers. This approach balances the need for secure, time-sensitive processing with the convenience of rich OS services. Additionally, Ringmaster supports large unmodified programs as enclaves, offering lower overhead compared to existing systems. We demonstrate how Ringmaster helps us build a working, highly secure system with minimal engineering. In our experiments with an unmanned aerial vehicle, Ringmaster achieved nearly 1GiB/sec of data into enclaves on a Raspberry Pi4B, 0-3% throughput overhead compared to non-enclave tasks. Richard Habeeb, Man-Ki Yoon, Hao Chen 0023, Zhong Shao 0001 |
MobiSys | 1 |
| 2025 | It's a Non-Stop PARTEE! Practical Multi-Enclave Availability Through Partitioning and AsynchronyabstractDue to the growing third-party software stack necessary to build modern data-rich robotics and cyber-physical systems (CPS), it has become important to protect safety-critical and timing-sensitive programs and their communication—even against an adversarial rich operating system (OS). Enclaves and Trusted Execution Environments (TEEs) are often used to protect code and memory against an untrusted OS, but they generally do not have good availability protections. To illustrate, we present three attacks, showing that even with secure timer access and memory protections, existing TEE platforms still face challenges in achieving availability. In response, we present PARTEE, the first design and implementation of a “partitioning” TEE OS for the diverse, distributed, and time-sensitive robotics software ecosystem. PARTEE ensures time-sensitive enclaves cannot be denied service by partitioning system resources, providing reliable communication channels and a time-sensitive system call interface. We analyze the security and performance of PARTEE using an unmanned aerial vehicle implemented on the Raspberry Pi4B using the ARM TrustZone, and show that despite the behavior of an adversarial partition or a rich OS, the drone's most safety-critical enclaves remain available and can communicate to prevent harm or damage. Richard Habeeb, Hao Chen 0023, Man-Ki Yoon, Zhong Shao 0001 |
ACSAC | 1 |