Stephen Herwig

dblp:205/2182 · DBLP profile ↗
← Back
10ranked-venue papers
2as first author
6since 2021 · last 2026
0000-0003-2459-2867ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 2 first-author · 5 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Calypso: Fine-Grained Access Control for Zero-Trust Cloud Service Discovery
Pankaj Niroula, Peyton Boggs, Aashutosh Poudel, Stephen Herwig
SACMAT4
2026 Lambada: Autoscaling Confidential Function Chains without Centralized Trust
abstract
Function-as-a-Service (FaaS) platforms enable developers to build event-driven applications by composing lightweight functions into complex workflows. Many such workflows process sensitive data, raising confidentiality risks from untrusted cloud providers and compromised infrastructure. Existing confidential FaaS systems mitigate these risks with secure hardware enclaves (e.g., Intel SGX) but still depend on a trusted key-provisioning enclave for autoscaling, creating a single point of compromise.
Aashutosh Poudel, Matthew Berthoud, Stephen Herwig
SACMAT3
2026 AttestLens: A Large-Scale Measurement of Play Integrity Adoption in Android Apps
Collin MacDonald, Stephen Herwig
WISEC2
2026 CODoH: Privacy-Preserving Caching for Oblivious DNS over HTTPS
abstract
Oblivious DNS over HTTPS (ODoH) enhances DNS privacy by routing queries through a proxy so that no single party can link a client's IP address with its DNS queries. However, because ODoH encrypts each query individually, the proxy cannot cache responses. We present CODoH (Cacheable Oblivious DNS over HTTPS), a cacheable extension to ODoH that reduces DNS resolution latency while preserving ODoH's separation of knowledge. CODoH places a proxy-side cache inside a trusted execution environment--namely, an Intel SGX enclave--and uses end-to-end encryption to ensure that the proxy never learns plaintext queries or cached responses. To prevent caching from becoming a new inference surface, CODoH defends against cache-state probing and set-difference (bracketing) attacks with (i) cover responses supplied by the resolver, (ii) batched cache updates that mix many clients' inserts, and (iii) an oblivious RAM (ORAM) backend that hides cache access patterns. CODoH also enforces correctness and freshness of cached records via resolver authorization and replay protection. We implement CODoH as CoreDNS extensions and evaluate it on an Azure SGX testbed. CODoH reduces median latency by 2.7x over ODoH on cache hits (18.0 vs. 48.0 ms) and by 2.2x under Zipf traffic (22.3 vs. 48.6 ms), with under 1 ms of SGX overhead.
Pankaj Niroula, Lily Gloudemans, Aashutosh Poudel, Collin MacDonald, Stephen Herwig
Proc. Priv. Enhancing Technol.5
2025 Akeso: Bringing Post-Compromise Security to Cloud Storage
abstract
Although cloud providers offer many options for encrypting object storage and rotating the encryption key, the cloud ultimately possesses the key, leaving data vulnerable to insider attacks, legal demands, and storage bugs. Moreover, current key rotation methods do not re-encrypt existing objects, exposing the data indefinitely to adversaries with stolen keys. This paper introduces Akeso, the first cloud storage system to achieve post-compromise security, thus restoring data confidentiality after a key compromise. For efficient key rotation, Akeso adapts the asynchronous group key agreement protocols of messaging applications to storage clients. For scalable object re-encryption, Akeso makes novel use of a cloud-side enclave to coordinate an updatable encryption scheme among untrusted cloud functions. Our evaluations demonstrate that Akeso re-encrypts a 10 GB bucket 2.5× faster than a naïve method that fetches and re-encrypts each object, with a monthly expense that is only 15.6–19.3% higher than the current, less secure, provider encryption options.
Lily Gloudemans, Pankaj Niroula, Aashutosh Poudel, Collin MacDonald, Stephen Herwig
Proc. Priv. Enhancing Technol.5
2021 Bento: safely bringing network function virtualization to Tor
abstract
Tor is a powerful and important tool for providing anonymity and censorship resistance to users around the world. Yet it is surprisingly difficult to deploy new services in Tor—it is largely relegated to proxies and hidden services—or to nimbly react to new forms of attack. Conversely, “non-anonymous” Internet services are thriving like never before because of recent advances in programmable networks, such as Network Function Virtualization (NFV) which provides programmable in-network middleboxes.
Michael Reininger, Arushi Arora, Stephen Herwig, Nicholas Francino, Jayson Hurst, Christina Garman, Dave Levin
SIGCOMM3
2020 Bento: Bringing Network Function Virtualization to Tor
abstract
Tor is a powerful and important tool for providing anonymity and censorship resistance to users around the world. Yet it is surprisingly difficult to deploy new services in Tor---it is largely relegated to proxies and hidden services---or to nimbly react to new forms of attack. Conversely, "non-anonymous" Internet services are thriving like never before because of recent advances in programmable networks, such as Network Function Virtualization (NFV) which provides programmable in-network middleboxes.
Michael Reininger, Arushi Arora, Stephen Herwig, Nicholas Francino, Christina Garman, Dave Levin
CCS3
2020 Achieving Keyless CDNs with Conclaves
Stephen Herwig, Christina Garman, Dave Levin
USENIX Security Symposium1
2019 Measurement and Analysis of Hajime, a Peer-to-peer IoT Botnet
Stephen Herwig, Katura Harvey, George Hughey, Dave Levin
NDSS1
2017 DeTor: Provably Avoiding Geographic Regions in Tor
Stephen Herwig, Dave Levin
USENIX Security Symposium2