VLDB 2026 Research / reviewers in the wild / expert
Thomas Prantl
dblp:251/5431
· DBLP profile ↗
11ranked-venue papers
9as first author
10since 2021 · last 2025
0000-0003-4044-8494ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 3 first-author · 4 since 2021Computer networks · 3 · 2 first-author · 3 since 2021Software engineering, systems software and programming languages · 2 · 2 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Quo Vadis CKKS: Comparison of the realization of basic mathematical functions for the homomorphic cryptosystem CKKS using De Bello and polynomial approximationsabstractAs data storage and processing increasingly shift to the cloud, the risk of data breaches also rises. One way to address this is using Homomorphic Encryption (HE), which allows for data processing while the data remains encrypted, unlike traditional methods. However, current HE libraries support only addition and multiplication, requiring users to implement other mathematical functions themselves. To this end, we developed and analyzed basic mathematical functions in a previous work. Since polynomial approximations are more common in HE, this paper expands on that by examining and comparing polynomial approximations of these functions with the previously implemented methods. Our findings indicate that while polynomial approximations offer the benefit of low multiplication depth, the previously implemented methods generally outperform them in most scenarios despite their higher computational cost. Thomas Prantl, Lukas Horn, Simon Engel, André Bauer 0001, Samuel Kounev |
J. Inf. Secur. Appl. | 1 |
| 2024 | Security Analysis of a Decentralized, Revocable and Verifiable Attribute-Based Encryption SchemeabstractIn recent years, digital services have experienced significant growth, exemplified by platforms like Netflix achieving unprecedented revenue levels. Some of these services employ subscription models, with certain content requiring additional payments or offering third-party products. To ensure the widespread availability of diverse digital services anytime and anywhere, providers must have control over content accessibility. To address the multifaceted challenges in this domain, one promising solution is the adoption of attribute-based encryption (ABE). Over the years, various approaches have been proposed in the literature, offering a wide range of features. In a prior study [18], we assessed the security of one of these proposed approaches and identified one that did not meet its promised security standards. In this research we focuses on conducting a security analysis for another ABE scheme to pinpoint its shortcomings and emphasize the critical importance of evaluating the safety and effectiveness of newly proposed schemes. Specifically, we uncover an attack vector within this ABE scheme, which enables malicious users to decrypt content without the required permissions or attributes. Furthermore, we propose a solution to rectify this identified vulnerability. Thomas Prantl, Marco Lauer, Lukas Horn, Simon Engel, David Dingel, André Bauer 0001, Christian Krupitzer, Samuel Kounev |
ARES | 1 |
| 2023 | Performance Impact Analysis of Homomorphic Encryption: A Case Study Using Linear Regression as an Example
Thomas Prantl, Simon Engel, Lukas Horn, Dennis Kaiser, Lukas Iffländer, André Bauer 0001, Christian Krupitzer, Samuel Kounev |
ISPEC | 1 |
| 2022 | Investigating the Predictability of QoS Metrics in Cellular NetworksabstractApplications on mobile devices face varying network conditions in cellular networks. The connected radio cell is often changing, especially with moving devices. Different access technologies, varying signal strengths, or distance to the connected radio tower influence the Quality of Service (QoS) of mobile applications. Existing technologies like buffering or adaptive video streaming work reactive, i.e., they react to a decreasing download bitrate. In contrast, these technologies and mobile applications in general could benefit from early knowledge of the expected connection quality.This work investigates the predictability of QoS metrics in cellular networks based on the experience of previous measurements. For this, we developed an Android app to measure download bitrates with minimal data consumption. We performed over 90 000 measurements using a single network operator and analyzed how precise QoS indicators like packet round trip times and download bitrates can be predicted. We developed a methodology to predict the expected download bitrate along a route and present our approach of aggregating measurements into hexagons of dynamic size. The core contributions of this work are (i) a methodology and implementation of systematic measurement data collection, (ii) an open data publication of our measurement data set, and (iii) an approach for predicting QoS metrics in cellular networks based on aggregated measurements. Our results show, that our approach is able to predict the downlink bitrate, the packet round trip time (ping), or DNS query duration along a given route. Stefan Herrnleben, Johannes Grohmann, Veronika Lesch, Thomas Prantl, Florian Metzger, Tobias Hoßfeld, Samuel Kounev |
IWQoS | 4 |
| 2022 | SCRAPS: Scalable Collective Remote Attestation for Pub-Sub IoT Networks with Untrusted Proxy Verifier
Lukas Petzi, Ala Eddine Ben Yahya, Alexandra Dmitrienko, Gene Tsudik, Thomas Prantl, Samuel Kounev |
USENIX Security Symposium | 5 |
| 2022 | An Experience Report on the Suitability of a Distributed Group Encryption Scheme for an IoT Use CaseabstractThe critical component in any IoT application is the communication between devices. This must not only function smoothly, but also be secured. An important step in securing IoT communication is its encryption. However, in order for IoT devices to encrypt their communication with each other, they must first agree on appropriate cryptographic keys. In practice, the generation and distribution of such keys is usually managed by a central authority. However, this centralized approach has the disadvantages that (i) a central authority must be trusted, (ii) the central authority represents a single point of failure, and (iii) the central authority may be far away and thus communication with it takes a long time. To overcome these drawbacks, distributed group key agreement approaches have also been proposed. Since these distributed approaches were not originally developed for IoT devices, their performance on such devices is unknown. Therefore, in this work, we investigate the performance of a distributed group encryption scheme on IoT devices. To this end, we have built a measurement environment for distributed group encryption schemes and compare centralized and distributed group encryption schemes for IoT. Our measurements show that under perfect network conditions, the distributed approach performs worse than the centralized approaches in terms of time and memory requirements. However, our measurements also show that the distributed approach allows a group of 5 members to agree on a key in less than a minute. Thus, the distributed method can be used for small IoT groups if agreeing on a key is not time-sensitive. Thomas Prantl, Simon Engel, André Bauer 0001, Ala Eddine Ben Yahya, Stefan Herrnleben, Lukas Iffländer, Alexandra Dmitrienko, Samuel Kounev |
VTC Spring | 1 |
| 2021 | Benchmarking of Pre- and Post-Quantum Group Encryption Schemes with Focus on IoTabstractIn the next few years, both the number of IoT devices and the performance of quantum computers will increase. Both technologies pose a challenge to our current crypto-strategies. Therefore, post-quantum n-to-n communication encryption is a crucial field of research. Here, the development of new schemes and the analysis, and comparison of existing schemes is necessary. However, current work only investigates the performance of post-quantum schemes only for 1-to-1 communication. Therefore, in this paper, we analyze existing post-quantum schemes concerning n-to-n communication and compare them with pre-quantum schemes. Our results show that the pre-quantum schemes perform better regarding computation times than the post-quantum schemes, but the differences are sometimes only marginal. However, these marginal differences in computation times lead to the lower energy efficiency of the post-quantum schemes. In terms of features, there is no difference between both scheme classes. We show that the post-quantum schemes require unicast, whereas some pre-quantum schemes also support broadcast. Deciding whether to use pre- or post-quantum schemes for n-to-n encryption in IoT use cases depends on (i) whether energy efficiency is essential – e.g., in case of limited power supply – and (ii) whether unicast or broadcast is available. Thomas Prantl, Dominik Prantl, André Bauer 0001, Lukas Iffländer, Alexandra Dmitrienko, Samuel Kounev, Christian Krupitzer |
IPCCC | 1 |
| 2021 | Performance Evaluation for a Post-Quantum Public-Key CryptosystemabstractQuantum Computing threatens security of today’s systems. Confidence in today’s security technologies largely relies on Public Key Cryptography (PKC), which depends on computational difficulty of mathematical problems that cannot be solved efficiently using any technology available today. This will, however, change once a sufficiently capable quantum computer will become available. Similarly, security of symmetric crypto algorithms will also be substantially weakened. Current progress in research proves that Quantum Computing is no longer science fiction. Hence, research and development of post-quantum cryptographic algorithms that can withstand attacks in Quantum Computing era are of paramount importance. This paper complements existing research in this domain with a performance analysis of a post-quantum cryptosystem capable of encrypting and decrypting messages either bit-wise or string-wise. Specifically, we describe a workflow for implementing the scheme, design a reproducible hardware performance evaluation testbed for an IoT and an online shopping scenario, define performance metrics, and perform performance evaluation case studies. Our performance analysis shows that bit-wise encryption and decryption and the corresponding key generation fits resource-constrained IoT microcontrollers as well as on average laptops. The encryption and decryption of a bit each take less than 30 ms and the key generation less than 300 ms. Thomas Prantl, Dominik Prantl, Lukas Beierlieb, Lukas Iffländer, Alexandra Dmitrienko, Samuel Kounev, Christian Krupitzer |
IPCCC | 1 |
| 2021 | Performance Impact Analysis of Securing MQTT Using TLSabstractThe interconnectivity of devices on the Internet of Things (IoT) provides many new and smart applications. However, the integration of many devices - especially by inexperienced users - might introduce several security threats. Further, several often used communication protocols in the IoT domain are not out-of-the-boxsecured. On the other hand, security inherently introduces overhead, resulting in a decrease in performance. The Message QueuingTelemetry Transport (MQTT) protocol is a popular communication protocol for IoT applications - for example, in Industry 4.0, railways, automotive, or smart homes. This paper analyzes the influence on performance when using MQTT with TLS in terms of throughput, connection build-up times, and energy efficiency using a reproducible testbed based on a standard off-the-shelf microcontroller. The results indicate that the impact of TLS on performance across all QoS levels depends on (i) the network situation and (ii) the connection reestablishment frequency. Thus, a negative influence of TLS on the performance is noticeable only in deteriorated networksituations or at a high connection reestablishment frequency. Thomas Prantl, Lukas Iffländer, Stefan Herrnleben, Simon Engel, Samuel Kounev, Christian Krupitzer |
ICPE | 1 |
| 2021 | Towards a Group Encryption Scheme Benchmark: A View on Centralized Schemes with Focus on IoTabstractThe number of devices connected to the Internet of Things (IoT) is continuously increasing to several billion nowadays. As those devices often share sensitive data, encryption of those data is an important issue. The pure volume of data and the complexity of communication patterns increases, and, accordingly, the importanceof group encryption is recently gaining more importance. Still, the choice of the best-suited group encryption scheme for a specific application is complicated. Benchmarks can support this choice. However, while literature distinguishes three categories for theschemes (central, decentral, and hybrid), a one-fits-all benchmark seems challenging to achieve. In this paper, we go the first step towards a structured benchmark for group encryption schemes by presenting a benchmark for centralized group encryption schemes in an IoT scenario. To this end, our benchmark includes a descriptionof workloads, a baseline scheme, a measurement setup, and metrics while also considering the requirements and features of centralized group encryption schemes. Thomas Prantl, Peter Ten, Lukas Iffländer, Stefan Herrnleben, Alexandra Dmitrienko, Samuel Kounev, Christian Krupitzer |
ICPE | 1 |
| 2020 | Evaluating the Performance of a State-of-the-Art Group-oriented Encryption Scheme for Dynamic Groups in an IoT ScenarioabstractNew emerging technologies, such as autonomous driving, intelligent buildings, and smart cities, are promising to revolutionize user experience and offer new services. The world has to undergo large scale deployment of billions of things - cost-efficient intelligent sensors that will be interconnected into extensive networks and will collect and supply data to intelligent algorithms - to make it happen. To date, however, it is challenging to secure such an infrastructure for many-fold reasons, such as resource constraints of things, large scale deployment, many-to-many communication patterns, and dynamically changing communication groups. All these factors rule out most of the state-of-the-art encryption and key-management techniques. Group encryption algorithms are well-suitable for many-to-many communication patterns typical for IoT networks, and many of them can deal with dynamic groups. There are, however, very few constructions that could potentially fulfill the computational and storage constraints of IoT devices while providing sufficient scalability for large networks. The promising candidates, such as construction by Nishat et al. [1], were not evaluated using IoT platforms and under constraints typical for IoT networks. In this paper, we aim to fill this gap and present the evaluation of a state-of-the-art group-oriented encryption scheme by Nishat et al. to identify its applicability to IoT systems. In detail, we provide a measurement workflow, a revised version of the approach, and describe a reproducible hardware testbed. Using this evaluation environment, we analyze the performance of the encryption scheme in a typical IoT scenario from a group member perspective. The results show that all calculation times can be assumed to be constant and are always below 2 seconds. The memory requirement for permanent parameters can also be considered to be constant and are below 8.5 kbit in each case. However, the information that has to be stored temporarily for group updates has turned out to be the bottleneck of the scheme, since their memory requirements increase linearly with the group size. Thomas Prantl, Peter Ten, Lukas Iffländer, Alexandra Dmitrienko, Samuel Kounev, Christian Krupitzer |
MASCOTS | 1 |