Thomas Zefferer

dblp:30/5214 · DBLP profile ↗
← Back
23ranked-venue papers
6as first author
4since 2021 · last 2023
0000-0001-5037-0657ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 10 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 10 · 4 first-author · 1 since 2021Systems, architecture and hardware · 2Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2023 Smoothing the Ride: Providing a Seamless Upgrade Path from Established Cross-Border eID Workflows Towards eID Wallet Systems
Roland Czerny, Christian Kollmann, Blaz Podgorelec, Bernd Prünster, Thomas Zefferer
SECRYPT5
2022 What is a (Digital) Identity Wallet? A Systematic Literature Review
abstract
Identity management is crucial for any electronic service that needs to authenticate its users. Different identity-management models have been introduced and rolled out on a large scale during the past decades. Key distinguishing criteria of these models are the storage location of users' identity data and the degree of involvement of central entities such as identity providers, which can potentially track user behavior. Growing privacy awareness has led to a renaissance of user-centric identity-management models during the past few years. In this context, especially the concept of wallets applied to the digital identity domain has recently attracted attention, putting users into direct control of their identity data. Various approaches and solutions relying on this concept have been introduced recently. However, no generally accepted definitions of the concept “digital identity wallet” and of its related features and implementations exist so far, leading to considerable confusion in this domain. This paper addresses this issue by providing a systematic literature review on wallets applied to the digital identity domain to identify, analyze, and compare existing definitions, features, and capabilities of such solutions. By means of two research questions, this paper thereby contributes to a better understanding of identity wallets and the various recent developments in this domain.
Blaz Podgorelec, Lukas Alber, Thomas Zefferer
COMPSAC3
2022 Total Eclipse of the Heart - Disrupting the InterPlanetary File System
Bernd Prünster, Alexander Marsalek, Thomas Zefferer
USENIX Security Symposium3
2021 Compressing the Bitcoin Blockchain using Incremental Snapshots
abstract
Blockchains are append-only data structures, meaning their size increases steadily. As of March 2021, new nodes connecting to the Bitcoin blockchain already need to synchronize and validate more than 330 GB of data. Already now, this is an issue for resource-constrained thin clients who lack the required download, storage, or computing capacities to achieve this. In future, this issue will become even more relevant when blockchain technology is applied to new domains like the Internet of Things (IoT). We propose a new blockchain architecture that addresses this issue. Our proposal relies on incremental snapshot blocks that allow new and occasionally used clients to synchronize with the current state of the blockchain efficiently. The snapshot blocks form a second linked blockchain and are secured by the blockchain consensus algorithm. In this paper, we describe the proposed architecture in detail and evaluate its storage-saving potential using the Bitcoin blockchain. The evaluations performed show that our design can reduce the volume of data that needs to be downloaded and stored by up to 98%, thus facilitating secure blockchain-based applications also on resource-constrained thin clients like smartphones, netbooks, or IoT devices.
Alexander Marsalek, Thomas Zefferer
TrustCom2
2019 Privacy-preserving attribute aggregation in eID federations
abstract
Personalized electronic services, e.g. from the e-government domain, need to reliably identify and authenticate users. During user-authentication processes, the electronic identity of the respective user is determined and required additional attributes, e.g. name and date of birth, linked to this identity are collected. This attribute-collection process can become complex, especially if required attributes are distributed over various attribute providers that are organized in a federated identity-management system. In many cases, these identity management systems rely on different ontologies and make use of different languages. Hence, identity federations, such as the one currently established across the European Union, require effective solutions to collect user attributes from different heterogeneous sources and aggregate them to a holistic user facet. At the same time, these solutions need to comply with minimum disclosure rules to preserve users’ privacy. In this article, we propose and introduce a solution for privacy-preserving attribute aggregation. Our solution combines attributes from different domains using ontology alignment and makes use of locality sensitive hashing functions to preserve users’ privacy. Evaluation results obtained from conducted experiments demonstrate our solution’s advantages for both, service providers and users. While service providers can be provided with a larger set of attributes, users remain in full control of their data and can decide on which of their attributes shall be revealed.
Walter Priesnitz Filho, Carlos Ribeiro, Thomas Zefferer
Future Gener. Comput. Syst.3
2018 A Security Analysis of FirstCoin
Alexander Marsalek, Christian Kollmann, Thomas Zefferer
SEC3
2018 A Hierarchical Evaluation Scheme for Pilot-based Research Projects
Thomas Zefferer
WEBIST1
2017 Hybrid Mobile Edge Computing: Unleashing the Full Potential of Edge Computing in Mobile Device Use Cases
abstract
Many different technologies fostering and supporting distributed and decentralized computing scenarios emerged recently. Edge computing provides the necessary on-demand computing power for Internet-of-Things (IoT) devices where it is needed. Computing power is moved closer to the consumer, with the effect of reducing latency and increasing fail-safety due to absent centralized structures. This is an enabler for applications requiring high-bandwidth uplinks and low latencies to computing units. In this paper, a new use case for edge computing is identified. Mobile devices can overcome their battery limitations and performance constraints by dynamically using the edge-computing-provided computational power. We call this new technology Hybrid Mobile Edge Computing. We present a general architecture and framework, which targets the mobile device use case of hybrid mobile edge computing, not only considering the improvement of performance and energy consumption, but also providing means to protect user privacy, sensitive data and computations. The achieved results are backed by the results of our analysis, targeting the energy saving potentials and possible performance improvements.
Andreas Reiter, Bernd Prünster, Thomas Zefferer
CCGrid3
2017 Cryptographic Service Providers in Current Device Landscapes: An Inconvenient Truth
Florian Reimair, Johannes Feichtner, Dominik Ziegler 0001, Sandra Kreuzhuber, Thomas Zefferer
SECRYPT5
2015 WebCrySIL - Web Cryptographic Service Interoperability Layer
Florian Reimair, Peter Teufl, Thomas Zefferer
WEBIST3
2015 Towards Transactional Electronic Services on Mobile End-user Devices - A Sustainable Architecture for Mobile Signature Solutions
Thomas Zefferer
WEBIST1
2014 A Server-Based Signature Solution for Mobile Devices
abstract
Electronic signatures are frequently used in security-critical fields of application such as e-government or e-banking. During the past years, especially server-based signature solutions have gained popularity, as they solve usability problems of traditional client-based approaches. Unfortunately, server-based signature solutions and their underlying security concepts are usually tailored to classical end-user devices such as desktop PCs or laptops. Therefore, these solutions cannot be used on mobile end-user devices such as smartphones. This excludes an increasing number of potential users, who prefer mobile end-user devices to access e-government and e-banking applications. To solve this problem, we propose a new server-based signature solution that is tailored to the special characteristics of mobile devices. The proposed solution is evaluated by means of a concrete prototype implementation. This prototype proves the feasibility of the proposed solution and demonstrates its capability to leverage the use of electronic signature based applications on mobile end-user devices.
Thomas Zefferer
MoMM1
2014 An Implementation-independent Evaluation Model for Server-based Signature Solutions
Thomas Zefferer, Bernd Zwattendorfer
WEBIST (1)1
2014 An Overview of Cloud Identity Management-Models
abstract
Unique identification and secure authentication are essential processes in various areas of application, e.g. in e-Government, e-Health, or e-Business. During the past years several identity management-systems and models have evolved. Many organizations and enterprises or even countries for their national eID solutions rely on identity management-systems for securing their applications. Since more and more applications are migrated into the cloud, secure identification and authentication are also vital in the cloud domain. How- ever, cloud identity management-systems need to meet slightly different requirements than traditional identity management-systems and thus cannot be clustered into the same model types or categories. Therefore, in this paper we give an overview of different cloud identity management-models that have already emerged up to now. We further compare these models based on selected criteria, e.g. on practicability and privacy aspects.
Bernd Zwattendorfer, Thomas Zefferer, Klaus Stranacher
WEBIST (1)2
2013 Mobile Device Encryption Systems
Peter Teufl, Thomas Zefferer, Christof Stromberger
SEC2
2013 iOS Encryption Systems - Deploying iOS Devices in Security-critical Environments
Peter Teufl, Thomas Zefferer, Christof Stromberger, Christoph Hechenblaikner
SECRYPT2
2013 Policy-based Security Assessment of Mobile End-user Devices - An Alternative to Mobile Device Management Solutions for Android Smartphones
Thomas Zefferer, Peter Teufl
SECRYPT1
2013 Towards a Modular Architecture for Adaptable Signature-verification Tools
Thomas Lenz, Klaus Stranacher, Thomas Zefferer
WEBIST3
2012 Improving the Security of SMS-based Services using Electronic Signatures - Towards SMS-based Processing of Transactional m-Government Services
Thomas Zefferer, Arne Tauber, Bernd Zwattendorfer
WEBIST1
2012 The Prevalence of SAML within the European Union - An Empirical Study
Bernd Zwattendorfer, Thomas Zefferer, Arne Tauber
WEBIST2
2011 A privacy-preserving eID based Single Sign-On solution
abstract
Single Sign-On (SSO) has become a popular technology allowing users to identify and authenticate once and to gain access to different resources in a distributed computing environment. Austrian e-Government relies on a secure and privacy-preserving sectoral identity management model. Even if a sectoral identifier model improves privacy, it also negatively affects the usability of authentication processes. In Austria, most public sector applications use an open-source identity provider called MOA-ID. However, due to the sectoral identity management MOA-ID has not been Single Sign-On-capable. In this paper we present a security architecture that enables Single Sign-On between different governmental applications using MOA-ID as identity provider while meeting the requirements for sectoral data privacy protection at the same time. We achieve this by transforming unique sectoral identifiers of users with the help of an additional trusted attribute provider.
Bernd Zwattendorfer, Arne Tauber, Thomas Zefferer
NSS3
2011 Employing Multi-core Processor Architectures to Accelerate Java Cryptography Extensions
Mario Ivkovic, Thomas Zefferer
WEBIST2
2007 Evaluation of the Masked Logic Style MDPL on a Prototype Chip
Thomas Popp, Mario Kirschbaum, Thomas Zefferer, Stefan Mangard
CHES3