VLDB 2026 Research / reviewers in the wild / expert
Sebastian Paul
dblp:218/1178
· DBLP profile ↗
6ranked-venue papers
5as first author
3since 2021 · last 2022
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 4 first-author · 3 since 2021Systems, architecture and hardware · 2 · 1 first-authorSoftware engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | Mixed Certificate Chains for the Transition to Post-Quantum Authentication in TLS 1.3abstractLarge-scale quantum computers will be able to efficiently solve the underlying mathematical problems of widely deployed public key cryptosystems in the near future. This threat has sparked increased interest in the field of Post-Quantum Cryptography (PQC) and standardization bodies like NIST, IETF, and ETSI are in the process of standardizing PQC schemes as a new generation of cryptography. This raises the question of how to ensure a fast, reliable, and secure transition to upcoming PQC standards in today's highly interconnected world. Sebastian Paul, Yulia Kuzovkova, Norman Lahr, Ruben Niederhagen |
AsiaCCS | 1 |
| 2022 | Towards post-quantum security for cyber-physical systems: Integrating PQC into industrial M2M communicationabstractThe threat of a cryptographically relevant quantum computer contributes to an increasing interest in the field of post-quantum cryptography (PQC). Compared to existing research efforts regarding the integration of PQC into the Transport Layer Security (TLS) protocol, industrial communication protocols have so far been neglected. Since industrial cyber-physical systems (CPS) are typically deployed for decades, protection against such long-term threats is needed. In this work, we propose two novel solutions for the integration of post-quantum (PQ) primitives (digital signatures and key establishment) into the industrial protocol Open Platform Communications Unified Architecture (OPC UA): a hybrid solution combining conventional cryptography with PQC and a solution solely based on PQC. Both approaches provide mutual authentication between client and server and are realized with certificates fully compliant to the X.509 standard. We implement the two solutions and measure and evaluate their performance across three different security levels. All selected algorithms (Kyber, Dilithium, and Falcon) are candidates for standardization by the National Institute of Standards and Technology (NIST). We show that Falcon is a suitable option – especially – when using floating-point hardware provided by our ARM-based evaluation platform. Our proposed hybrid solution provides PQ security for early adopters but comes with additional performance and communication requirements. Our solution solely based on PQC shows superior performance across all evaluated security levels in terms of handshake duration compared to conventional OPC UA but comes at the cost of increased handshake sizes. In addition to our performance evaluation, we provide a proof of security in the symbolic model for our two PQC-based variants of OPC UA. For this proof, we use the cryptographic protocol verifier ProVerif and formally verify confidentiality and authentication properties of our quantum-resistant variants. Sebastian Paul, Patrik Scheible, Friedrich Wiemer |
J. Comput. Secur. | 1 |
| 2021 | TPM-Based Post-Quantum Cryptography: A Case Study on Quantum-Resistant and Mutually Authenticated TLS for IoT EnvironmentsabstractThe prospect of large-scale quantum computers necessitates the design, development, and standardization of post-quantum cryptography (PQC). Industrial control systems (ICS) and critical infrastructures are expected to be among the first industrial environments to adopt PQC. As their components have a long life span (≥ 10 years) and are increasingly interconnected to form an Industrial Internet of Things (IIoT), they require strong and long-lasting security guarantees. Because of these high-security requirements, IIoT products are also increasingly equipped with additional hardware security elements — often Trusted Platform Modules (TPMs). Sebastian Paul, Felix Schick, Jan Seedorf |
ARES | 1 |
| 2020 | Towards Post-Quantum Security for Cyber-Physical Systems: Integrating PQC into Industrial M2M Communication
Sebastian Paul, Patrik Scheible |
ESORICS (2) | 1 |
| 2020 | Hybrid OPC UA: Enabling Post-Quantum Security for the Industrial Internet of ThingsabstractCyber-physical systems (CPS) are considered a crucial part for providing connectivity in industrial environments. However, the recent increase in connectivity has led to an extended attack vector. Therefore, it is important that CPS are secured against current and - due to their long life span - also against future threats, such as quantum computers. The security of present communication can be broken once a sufficiently powerful quantum computer is available. To protect against this attack vector, applications and protocols should start utilizing quantum-resistant primitives. One approach that maintains common security guarantees and protects against quantum computer attacks is to use hybrid constructions: a combination of classically secure and quantum-resistant schemes. In this work, we propose a hybrid key exchange mechanism for the industrial communication protocol Open Platform Communications Unified Architecture (OPC UA). We describe four distinct instantiations based on selected quantum-resistant key encapsulation mechanisms (KEMs), namely NewHope, NTRU, CRYSTALS-Kyber, and Saber. We implement our resulting quantum-resistant modifications of OPC UA on two different ARM based platforms and present detailed performance footprints. Finally, we show the feasibility of employing hybrid quantum-resistant key exchange within OPC UA preserving industrial communication against future threats. Sebastian Paul, Esther Guerin |
ETFA | 1 |
| 2018 | Highly efficient and accurate seizure prediction on constrained IoT devicesabstractIn this paper we present an efficient and accurate algorithm for epileptic seizure prediction on low-power and portable IoT devices. State-of-the-art algorithms suffer from two issues: computation intensive features and large internal memory requirement, which make them inapplicable for constrained devices. We reduce the memory requirement of our algorithm by reducing the size of data segments (i.e. the window of input stream data on which the processing is performed), and the number of required EEG channels. To respect the limitations of the processing capability, we reduce the complexity of our exploited features by only considering the simple features, which also contributes to reducing the memory requirements. Then, we provide new relevant features to compensate the information loss due to the simplifications (i.e. less number of channels, simpler features, shorter segment, etc.). We measured the energy consumption (12.41 mJ) and execution time (565 ms) for processing each segment (i.e. 5.12 seconds of EEG data) on a low-power MSP432 device. Even though the state-of-art does not fit to IoT devices, we evaluate the classification performance and show that our algorithm achieves the highest AUC score (0.79) for the held-out data and outperforms the state-of-the-art. Farzad Samie, Sebastian Paul, Lars Bauer, Jörg Henkel |
DATE | 2 |