VLDB 2026 Research / reviewers in the wild / expert
Jonas Röckl
dblp:249/4099
· DBLP profile ↗
7ranked-venue papers
4as first author
7since 2021 · last 2026
0000-0002-3970-5580ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 4 first-author · 7 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Plug'n'Trust: Fine-Grained USB Device Isolation for ARM TrustZone
Julian Funk, Yvonne Kothmeier, Jonas Röckl, Christian Lindenmeier, Tilo Müller |
ICISSP (2) | 3 |
| 2025 | TrustLeech: Privileged System Analysis using Nested VirtualizationabstractPrivileged system analysis, i.e., the analysis of a running virtual machine (VM) from the hypervisor, is a common and robust technique employed in digital forensics, incident response, and malware analysis. Its robustness stems from the analysis system running with higher privileges than the target. However, the complexity of modern hypervisors has increased the probability of vulnerabilities allowing privilege escalation, which may allow a VM to take over the hypervisor. To counter this threat, analysis tools are deployed at even higher privilege levels, such as the firmware level on ARMv8-A systems. However, moving complex software to the firmware merely shifts the dangers of vulnerabilities to another layer. To solve this dilemma, we propose using nested virtualization to introduce an additional analysis layer below the hypervisor but above the firmware. This layer can be initiated on demand using only minor modifications to the firmware. As a proof of concept, we present TrustLeech, which only adds a small loader consisting of 327 lines of code to the firmware. On-demand at runtime, TrustLeech virtualizes the existing hypervisor and its VMs using ARM's nested virtualization extensions, inserting an analysis hypervisor. TrustLeech therefore combines the advantages of firmware level initialization with a hypervisor's access to all hardware debugging features, allowing precise analysis. We show its applicability by integrating TrustLeech with LibVMI and analyzing rootkits in a running hypervisor. Matti Schulze, Paul Bergmann, Jonas Röckl, Felix C. Freiling |
ACSAC | 3 |
| 2025 | SH3ARS: Privilege Reduction for ARMv8.0-A Secure MonitorsabstractThe ARM TrustZone Trusted Execution Environment (TEE) allows software to run in an isolated environment, separated from the untrusted OS. The isolation is based on the Secure Monitor (SM), software running at the most privileged hardware level, with unrestricted access to all system resources, including those of the TEE. Critically, recent research revealed widespread vulnerabilities in SMs that break the TEE isolation and, thus, undermine the very purpose of the TEE. To this end, we present SH3ARS, a fundamental restructuration of the SM firmware that reduces the privileges of the SM and restores ARM TrustZone isolation. SH3ARS modifies the SM to irrevocably relinquish access to memory outside its own address space through a page table latching mechanism. Furthermore, we introduce guards, carefully crafted, gadget-free code sequences, that supervise the context switch to and from the TEE, preventing code-reuse attacks against the TEE - a technique we refer to as SMC-oriented programming. Relying on software changes, SH3ARS ensures TEE isolation guarantees, even if the SM is compromised. We apply SH3ARS to the reference implementation of the SM on ARMv8.0-A, as deployed on millions of devices. We implement a proof of concept on real hardware, and our evaluation shows that the overhead is lower than 6% for most workloads. Jonas Röckl, Julian Funk, Matti Schulze, Tilo Müller |
RAID | 1 |
| 2024 | TeeFilter: High-Assurance Network Filtering Engine for High-End IoT and Edge Devices based on TEEsabstractLarge botnets like Mirai, with 600,000 infected devices, prove that cyber criminals have recognized the potential of attacks against the fast-growing Internet of Things. Moreover, recent critical vulnerabilities like Ripple20 and Amnesia:33 show that taking over a remote system via the network is a real threat. Alarmingly, modern strains of malware rely on exploiting such vulnerabilities to spread, with an increasing tendency. Hence, effective techniques to mitigate the consequences of modern IoT malware are necessary. Jonas Röckl, Nils Bernsdorf, Tilo Müller |
AsiaCCS | 1 |
| 2023 | Veto: Prohibit Outdated Edge System Software from Booting
Jonas Röckl, Adam Wagenhäuser, Tilo Müller |
ICISSP | 1 |
| 2022 | Compiler-Aided Development of Trusted Enclaves with RustabstractTo optimally utilize Intel SGX, programs must be partitioned into trusted and untrusted parts. Writing the trusted part of a program with Intel’s SDK, however, requires manual effort that often becomes an obstacle for programmers. In this work, we investigate how compiler-level tooling can assist with the semi-automatic separation of code into a trusted and an untrusted partition. We present Cadote, a solution that generates SGX enclaves from programs written in Rust. Application developers are expected to mark functions as trusted, for which enclaves are then generated automatically. All other functions remain untrusted and are executed outside Intel SGX in the normal world. We implemented this concept using compiler optimization passes of the LLVM framework. Targeting Rust as input language allows us to benefit from high-level concepts, such as memory safety, which enable us to safely copy function parameters between the normal and trusted world in practice. Felix Dreissig, Jonas Röckl, Tilo Müller |
ARES | 2 |
| 2021 | Advanced System Resiliency Based on Virtualization Techniques for IoT DevicesabstractAn increasing number of powerful devices are equipped with network connectivity and are connected to the Internet of Things (IoT). Influenced by the steady growth of computing power of the devices, the paradigm of IoT-based service deployment is expected to change, following the example of cloud-based infrastructure: An embedded platform can be provided as-a-service to several independent application service suppliers. This fosters additional challenges concerning security and isolation. At the same time, recently revealed critical vulnerabilities like Ripple20 and Amnesia:33 show that embedded devices are not spared from wide-spread attacks. Jonas Röckl, Mykolai Protsenko, Monika Kamhuber, Tilo Müller, Felix C. Freiling |
ACSAC | 1 |