Michael Roland 0001

dblp:26/11488-1 · DBLP profile ↗
← Back
12ranked-venue papers
2as first author
7since 2021 · last 2025
0000-0003-4675-0539ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Unveiling the Critical Attack Path for Implanting Backdoors in Supply Chains: Practical Experience from XZ
Mario Lins, René Mayrhofer, Michael Roland 0001
CANS3
2024 BioDSSL: A Domain Specific Sensor Language for Global, Distributed, Biometric Identification Systems
abstract
With biometric identification systems becoming increasingly ubiquitous, their complexity is escalating due to the integration of diverse sensors and modalities, aimed at minimizing error rates. The current paradigm for these systems involves hard-coded aggregation instructions, presenting challenges in system maintenance, scalability, and adaptability. These challenges become particularly prominent when deploying new sensors or adjusting security levels to respond to evolving threat models. To address these concerns, this research introduces BioDSSL, a Domain Specific Sensor Language to simplify the integration and dynamic adjustment of security levels in biometric identification systems. Designed to address the increasing complexity due to diverse sensors and modalities, BioDSSL promotes system maintainability and resilience while ensuring a balance between usability and security for specific scenarios. Furthermore, it facilitates decentralization of biometric identification systems, by improving interoperability and abstraction. Decentralization inherently disperses the concentration of sensitive biometric data across various nodes, which could indirectly enhance privacy protection and limit the potential damage from localized security breaches. Therefore, BioDSSL is not just a technical improvement, but a step towards decentralized, resilient, and more secure biometric identification systems. This approach holds the promise of indirectly improving privacy while enhancing the reliability and adaptability of these systems amidst evolving threat landscapes and technological advancements.
Philipp Hofer 0003, Michael Roland 0001, René Mayrhofer
IS2
2023 Efficient Aggregation of Face Embeddings for Decentralized Face Recognition Deployments
Philipp Hofer 0003, Michael Roland 0001, Philipp Schwarz, René Mayrhofer
ICISSP2
2023 Face to Face with Efficiency: Real-Time Face Recognition Pipelines on Embedded Devices
Philipp Hofer 0003, Michael Roland 0001, Philipp Schwarz, René Mayrhofer
MoMM2
2022 Automating the Quantitative Analysis of Reproducibility for Build Artifacts derived from the Android Open Source Project
abstract
This work proposes a modular automation toolchain to analyze current state and over-time changes of reproducibility of build artifacts derived from the Android Open Source Project (AOSP). While perfect bit-by-bit equality of binary artifacts would be a desirable goal to permit independent verification if binary build artifacts really are the result of building a specific state of source code, this form of reproducibility is often not (yet) achievable in practice. Certain complexities in the Android ecosystem make assessment of production firmware images particularly difficult. To overcome this, we introduce "accountable builds" as a form of reproducibility that allows for legitimate deviations from 100 percent bit-by-bit equality. Using our framework that builds AOSP in its native build system, automatically compares artifacts, and computes difference scores, we perform a detailed analysis of differences, identify typical accountable changes, and analyze current major issues leading to non-reproducibility and non-accountability. We find that pure AOSP itself builds mostly reproducible and that Project Treble helped through its separation of concerns. However, we also discover that Google's published firmware images deviate from the claimed codebase (partially due to side-effects of Project Mainline).
Manuel Pöll, Michael Roland 0001
WISEC2
2022 Decentralized, Privacy-Preserving, Single Sign-On
abstract
In current single sign-on authentication schemes on the web, users are required to interact with identity providers securely to set up authentication data during a registration phase and receive a token (credential) for future access to services and applications. This type of interaction can make authentication schemes challenging in terms of security and availability. From a security perspective, a main threat is theft of authentication reference data stored with identity providers. An adversary could easily abuse such data to mount an offline dictionary attack for obtaining the underlying password or biometric. From a privacy perspective, identity providers are able to track user activity and control sensitive user data. In terms of availability, users rely on trusted third-party servers that need to be available during authentication. We propose a novel decentralized privacy-preserving single sign-on scheme through the Decentralized Anonymous Multi-Factor Authentication (DAMFA), a new authentication scheme where identity providers no longer require sensitive user data and can no longer track individual user activity. Moreover, our protocol eliminates dependence on an always-on identity provider during user authentication, allowing service providers to authenticate users at any time without interacting with the identity provider. Our approach builds on threshold oblivious pseudorandom functions (TOPRF) to improve resistance against offline attacks and uses a distributed transaction ledger to improve availability. We prove the security of DAMFA in the universal composibility (UC) model by defining a UC definition (ideal functionality) for DAMFA and formally proving the security of our scheme via ideal-real simulation. Finally, we demonstrate the practicability of our proposed scheme through a prototype implementation.
Omid Mir, Michael Roland 0001, René Mayrhofer
Secur. Commun. Networks2
2021 Analyzing inconsistencies in the Tor consensus
abstract
Every distributed system needs some way to list its current participants. The Tor networks consensus is one way of tackling this challenge. But creating a shared list of participants and their properties without a central authority is a challenging task, especially if the system is constantly targeted by nation state attackers. This work carefully examines the Tor consensuses created in the last two years, identifies weaknesses that did already impact users, and proposes improvements to strengthen the Tor consensus in the future. Our results show undocumented voting behavior by directory authorities and suspicious groups of relays that try to conceal the fact that they are all operated by the same entity.
Tobias Höller, Michael Roland 0001, René Mayrhofer
iiWAS2
2016 Real-World Identification: Towards a Privacy-Aware Mobile eID for Physical and Offline Verification
Michael Hölzl, Michael Roland 0001, René Mayrhofer
MoMM2
2014 Mobile Application to Java Card Applet Communication using a Password-authenticated Secure Channel
abstract
With the increasing popularity of security and privacy sensitive systems on mobile devices, such as mobile banking, mobile credit cards, mobile ticketing, or mobile digital identities, challenges for the protection of personal and security sensitive data of these use cases emerged. A common approach for the protection of sensitive data is to use additional hardware such as smart cards or secure elements. The communication between such dedicated hardware and back-end management systems uses strong cryptography. However, the data transfer between applications on the mobile device and so-called applets on the dedicated hardware is often either unencrypted (and interceptable by malicious software) or encrypted with static keys stored in applications. To address this issue we present a solution for fine-grained secure application-to-applet communication based on Secure Remote Password (SRP-6a), an authenticated key agreement protocol, with a user-provided password at run-time. By exploiting the Java Card cryptographic API and minor adaptations to the protocol, which do not affect the security, we were able to implement this scheme on Java Cards with reasonable computation time.
Michael Hölzl, Endalkachew Asnake, René Mayrhofer, Michael Roland 0001
MoMM4
2013 Requirements for an Open Ecosystem for Embedded Tamper Resistant Hardware on Mobile Devices
abstract
Insufficient security and privacy on mobile devices have made it difficult to utilize sensitive systems like mobile banking, mobile credit cards, mobile ticketing or mobile passports. Solving these challenges in security and privacy, could result in better mobility and a higher level of confidence for the end-user services in such systems. Our approach for a higher security and privacy level on mobile devices introduces an open ecosystem for tamper resistant hardware. Big advantages of these modules are the protection against unauthorized access and the on-device cryptographic operations they can perform. In this paper, we analyse the requirements and performance restrictions of these hardware modules and present an interface concept for a tight integration of their security features.
Michael Hölzl, René Mayrhofer, Michael Roland 0001
MoMM3
2013 (Ab)using foreign VMs: Running Java Card Applets in non-Java Card Virtual Machines
abstract
Creating Java Card applications for Near Field Communication's card emulation mode requires access to a secure smartcard chip (the secure element). Today, even for development purposes, it is difficult to get access to the secure element in most current smart phones. Therefore, it would be useful to have an environment that emulates a secure element for rapid prototyping and debugging. Our approach to such an environment is emulation of Java Card applets on top of non-Java Card virtual machines (e.g. Android's Dalvik VM). However, providing a Java Card run-time environment on top of another Java virtual machine faces one big problem: The Java Card virtual machine's operation principle is based on persistent memory technology. As a result, the VM and the applications that run on top of it have a significantly different life-cycle compared to other Java VMs. Based on specific scenarios for secure element emulators for the Android platform, we evaluate these differences and their impact on Java VM-based Java Card emulation. Further, we propose possible solutions to the problems that arise from these differences in the life-cycles.
Michael Roland 0001, Josef Langer, René Mayrhofer
MoMM1
2012 Relay Attacks on Secure Element-Enabled Mobile Devices - Virtual Pickpocketing Revisited
Michael Roland 0001, Josef Langer, Josef Scharinger
SEC1