VLDB 2026 Research / reviewers in the wild / expert
Thomas Lorünser
dblp:50/4146
· DBLP profile ↗
25ranked-venue papers
6as first author
10since 2021 · last 2026
0000-0002-1829-4882ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 15 · 3 first-author · 6 since 2021Systems, architecture and hardware · 2 · 1 first-authorComputer networks · 1Software engineering, systems software and programming languages · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Topology-Hiding Path Validation for Large-Scale Quantum Key Distribution Networks
Stephan Krenn, Omid Mir, Thomas Lorünser, Sebastian Ramacher, Florian Wohner |
ACNS (3) | 3 |
| 2026 | A Pragmatic Comparison of Cryptographic Computation Technologies for Machine LearningabstractAs security demands increase, the importance of secure computation technologies grows, yet these technologies can often seem overwhelming to practitioners. Furthermore, many approaches focus only on a single technology, potentially overlooking superior alternatives. This work aims to address the issue of selecting the right technology for secure computation by presenting a comparative analysis of two highly relevant cryptographic methods and their software implementations, with a particular focus on machine learning. Firstly, we provide a theoretical summary and comparison of the secure computation paradigms of secure multi-party computation (SMPC) and fully homomorphic encryption (FHE). We outline the advantages and limitations of the protocols, as well as the relevant open-source software implementations. Secondly, we present the results of extensive benchmarking of the main software frameworks identified for machine learning operations and models. Regarding the current state of the art in FHE, we observe that it outperforms SMPC for regressions. Additionally it may be faster for simple dense networks using GPUs or Hybrid Models. Conversely, SMPC showed superior performance for complex models such as CNNs. Our results should pave the way for more technology-agnostic benchmarking of secure computation technologies for machine learning, providing guidance for practitioners looking to adopt these technologies. Marcus Taubert, Adam Skuta, Thomas Lorünser |
ICISSP (2) | 3 |
| 2025 | Protecting Privacy in Federated Time Series Analysis: A Pragmatic Technology Review for Application Developers
Daniel Bachlechner, Ruben Helmut Hetfleisch, Stephan Krenn, Thomas Lorünser, Michael Rader |
CLOSER | 4 |
| 2025 | Seamless Post-Quantum Transition: Agile and Efficient Encryption for Data-at-Rest
Federico Valbusa, Stephan Krenn, Thomas Lorünser, Sebastian Ramacher |
SECRYPT | 3 |
| 2024 | Integrating Secure Multiparty Computation into Data Spaces
Veronika Siska, Thomas Lorünser, Stephan Krenn, Christoph Fabianek |
CLOSER | 2 |
| 2024 | Feasibility of Privacy Preserving Minutiae-Based Fingerprint Matching
Julia Mader, Thomas Lorünser |
ICISSP | 2 |
| 2022 | Towards a Performance Model for Byzantine Fault Tolerant Services
Thomas Lorünser, Benjamin Rainer, Florian Wohner |
CLOSER | 1 |
| 2022 | A Distributed Architecture for Privacy-Preserving Optimization Using Genetic Algorithms and Multi-party Computation
Christoph G. Schütz, Thomas Lorünser, Samuel Jaburek, Kevin Schuetz, Florian Wohner, Roman Karl, Eduard Gringinger |
CoopIS | 2 |
| 2022 | A Privacy-Preserving Auction Platform with Public Verifiability for Smart Manufacturing
Thomas Lorünser, Florian Wohner, Stephan Krenn |
ICISSP | 1 |
| 2021 | Single-Use Delegatable Signatures Based on Smart ContractsabstractDelegation of cryptographic signing rights has found many application in the literature and the real world. However, despite very advanced functionalities and specific use cases, existing solutions share the natural limitation that the number of usages of these signing rights cannot be efficiently limited, but users can at most be disincentivized to abuse their rights. Stephan Krenn, Thomas Lorünser |
ARES | 2 |
| 2019 | Making secret sharing based cloud storage usableabstractPurpose The purpose of this paper is to develop a usable configuration management for Archistar, which utilizes secret sharing for redundantly storing data over multiple independent storage clouds in a secure and privacy-friendly manner. Selecting the optimal secret sharing parameters, cloud storage servers and other settings for securely storing the secret data shares, while meeting all of end user’s requirements and other restrictions, is a complex task. In particular, complex trade-offs between different protection goals and legal privacy requirements need to be made. Design/methodology/approach A human-centered design approach with structured interviews and cognitive walkthroughs of user interface mockups with system administrators and other technically skilled users was used. Findings Even technically skilled users have difficulties to adequately select secret sharing parameters and other configuration settings for adequately securing the data to be outsourced. Practical implications Through these automatic settings, not only system administrators but also non-technical users will be able to easily derive suitable configurations. Originality/value The authors present novel human computer interaction (HCI) guidelines for a usable configuration management, which propose to automatically set configuration parameters and to solve trade-offs based on the type of data to be stored in the cloud. Through these automatic settings, not only system administrators but also non-technical users will be able to easily derive suitable configurations. Erik Framner, Simone Fischer-Hübner, Thomas Lorünser, Ala Sarah Alaqra, John Sören Pettersson |
Inf. Comput. Secur. | 3 |
| 2018 | CryptSDLC: Embedding Cryptographic Engineering into Secure Software Development LifecycleabstractApplication development for the cloud is already challenging because of the complexity caused by the ubiquitous, interconnected, and scalable nature of the cloud paradigm. But when modern secure and privacy aware cloud applications require the integration of cryptographic algorithms, developers even need to face additional challenges: An incorrect application may not only lead to a loss of the intended strong security properties but may also open up additional loopholes for potential breaches some time in the near or far future. To avoid these pitfalls and to achieve dependable security and privacy by design, cryptography needs to be systematically designed into the software, and from scratch. We present a system architecture providing a practical abstraction for the many specialists involved in such a development process, plus a suitable cryptographic software development life cycle methodology on top of the architecture. The methodology is complemented with additional tools supporting structured inter--domain communication and thus the generation of consistent results: cloud security and privacy patterns, and modelling of cloud service level agreements. We conclude with an assessment of the use of the Cryptographic Software Design Life Cycle (CryptSDLC) in a EU research project. Thomas Lorünser, Henrich Christopher Pöhls, Leon Sell, Thomas Länger |
ARES | 1 |
| 2018 | C3S: Cryptographically Combine Cloud Storage for Cost-Efficient Availability and ConfidentialityabstractIncreasing the availability by using multiple cloud storage providers for replication comes at a price; not only does it increase storage costs with every replica, it also greatly disperses the information to different cloud storage systems. Thus, all storage locations must be trusted to not read that data. Contrary the cryptographic technique of secret sharing splits data into confidentiality protected shares and if the adversary does not have access to more than a pre-defined threshold k of those shares, then the data's confidentiality is protected. At the same time secret sharing also increases the availability because the legitimate user must only download the data from k out of n shares. The goal of this paper is to quantify the economic advantages of efficient and secure information dispersal strategies in multi-cloud settings based on the current market situation. Therefore, we put together a database of 63 cloud storage offers and analyzed opportunities to combine them into virtual storage services delivering availabilities of 99.999% at the best price. Additionally, the combined multi-cloud storage is leaning towards data protection legislation of the European Union (EU), as any combination of k shares includes at least one from an EU-based provider. This inhibits non-EU jurisdictions to 'subpoena' the required number of shares to reconstruct data without the help of an EU-based provider. Our findings show that it is possible to find combinations which give the cloud storage consumer the wanted high availability and legal compliance guarantee at half the cost of any two providers from within the EU storing unencrypted replicas. Leon Sell, Henrich Christopher Pöhls, Thomas Lorünser |
CloudCom | 3 |
| 2018 | A fast and resource efficient FPGA implementation of secret sharing for storage applicationsabstractOutsourcing data into the cloud gives wide benefits and opportunities to customers. Beside these advantages, new challenges such as confidentiality and accessibility have to be addressed. One approach to overcome these challenges is by applying secret sharing in a distributed storage setting, known as cloud of clouds approach. For this purpose we present a new hardware architecture of a wide parametrizable secret sharing core. Performance metrics for various applied bit-widths of secret words are given, which are crucial for benefits of higher level protocols in the cloud of clouds approach. Additionally, a complete system which is able to operate in a network environment is presented. The achieved throughputs are in the order of Gbit/s. It is significantly faster than similar comparable hardware architectures and orders of magnitude higher than software implementations. Jakob Stangl, Thomas Lorünser, Sai Manoj Pudukotai Dinakarrao |
DATE | 2 |
| 2017 | The Archistar Secret-Sharing Backup ProxyabstractCloud-Storage has become part of the standard toolkit for enterprise-grade computing. While being cost- and energy-efficient, cloud storage's availability and data confidentiality can be problematic. A common approach of mitigating those issues are cloud-of-cloud solutions. Another challenge is the integration of such a solution into existing legacy systems. This paper introduces the Archistar Backup Proxy which allows integration of multi-cloud storage into existing legacy enterprise computing landscapes by overloading the industry-standard Amazon S3 protocol. The paper provides multiple lessons-learned during implementation and concludes with a performance evaluation with traditional backup solutions utilizing redundant remote storage. Andreas Happe, Florian Wohner, Thomas Lorünser |
ARES | 3 |
| 2017 | Towards Attribute-Based Credentials in the Cloud
Stephan Krenn, Thomas Lorünser, Anja Salzer, Christoph Striecks |
CANS | 2 |
| 2017 | Batch-verifiable Secret Sharing with Unconditional Privacy
Stephan Krenn, Thomas Lorünser, Christoph Striecks |
ICISSP | 2 |
| 2016 | Efficient and Privacy Preserving Third Party Auditing for a Distributed Storage SystemabstractWhen using distributed storage systems to outsource data storage into the cloud, it is often vital that this is done in a privacy preserving way, i.e., without the storage servers learning anything about the stored data. Especially when storing critical data, one often further requires efficient means to check whether the data is actually stored correctly on these servers. In the best case, such an auditing could itself be outsourced to a third party which does not need to be trusted by the data owner. That is, also the auditing mechanism should guarantee privacy, even if the auditor collaborates with a (sub) set of the storage servers. However, so far only a small number of privacy preserving third party auditing mechanisms has been presented for single server storage solutions, and no such protocols exist at all for a distributed storage setting. In this paper, we therefore define and instantiate a privacy preserving auditable distributed storage system. Our instantiation can be based on any homomorphic secret sharing scheme, and is fully keyless, efficient, and information-theoretically private. Furthermore, it supports batch audits, and is backward compatible with existing secret sharing based storage solutions. Denise Demirel, Stephan Krenn, Thomas Lorünser, Giulia Traverso |
ARES | 3 |
| 2016 | Towards a Unified Secure Cloud Service Development and Deployment Life-CycleabstractDesigning and developing cloud services is a challenging task that includes requirements engineering, secure service deployment, maintenance, assurance that proper actions have been taken to support security and, in addition, considering legal aspects. This is unfortunately not possible by taking current methods and techniques into consideration. Therefore, we require a systematic and comprehensive approach for building such services that starts the integration of security concerns from early stages of design and development, and continuous to refines and integrate them in the deployment phase. In this paper we therefore propose a solution that integrates security requirements engineering and continuous refinement in a comprehensive security development and deployment life-cycle for cloud services and applications. Our approach is focused on iterative refinement of the security-based requirements during both software engineering (development phase) and software maintenance (deployment phase). Aleksandar Hudic, Matthias Flittner, Thomas Lorünser, Philipp M. Radl, Roland Bless |
ARES | 3 |
| 2016 | PRISMACLOUD Tools: A Cryptographic Toolbox for Increasing Security in Cloud ServicesabstractThe EC Horizon 2020 project PRISMACLOUD aims at cryptographically addressing several severe risks threatening end user security and privacy in current cloud settings. This shall be achieved by the provision of a reusable toolbox encapsulating cryptographic functionality from which dependably secure cloud services can be assembled. In order to provide a tangible abstraction of the complexity involved with the construction of cryptographically secured cloud services, we introduce the four-layer PRISMACLOUD architecture. Top down, it consists of a use cases (application) layer, a services layer, a tools layer, and a cryptographic primitives and protocols layer. In this paper we provide a detailed description of the PRISMACLOUD tools in terms of functional components, as well as how they interact to provide the desired security functionality. We also briefly describe the cutting-edge cryptographic primitives which are encompassed by the tools. Both the toolbox and the cryptographic primitives and protocols are being currently developed and will be provided as reference implementation by project end in July 2018. Thomas Lorünser, Daniel Slamanig, Thomas Länger, Henrich Christopher Pöhls |
ARES | 1 |
| 2015 | ARCHISTAR: Towards Secure and Robust Cloud Based Data SharingabstractCloud based collaboration gives rise to many new applications and business opportunities in both the private and the business domain. However, building such systems in a secure and robust manner is a challenging task. In this paper, we present a new architecture for secure cloud based data sharing called ARCHISTAR. It builds upon a distributed storage system and thus avoids any single point of trust or failure. Besides providing confidentiality of data, our focus is on availability and in particular on robustness against active attacks or failures. Our system provides full multi-user support and enables advanced sharing scenarios without complex key management and revocation mechanisms. We also present a prototype implementation of the ARCHISTAR system and discuss open issues. Thomas Lorünser, Andreas Happe, Daniel Slamanig |
CloudCom | 1 |
| 2015 | Passive ROADM Flexibility in Optical Access With Spectral and Spatial ReconfigurabilityabstractAn energy-aware solution for physical-layer reconfigurability in metro-access networks is presented. The dynamicity of optical switching is introduced in nodes that are perceived as fully-passive by the network. Energy scavenging at low optical feed level of -10dBm supports field-deployment without local electrical power supply. Two types of network nodes are demonstrated experimentally. First, a resilience node is evaluated for fast protection switching in 10.7 ms at the feeder segment. Optical switching is further exploited for the purpose of dynamic allocation of spectral slices and routing in a new class of reconfigurable optical add-drop multiplexer. The spectral bandwidth of drop segments can be extended on demand while intranetwork communication among different segments of the access network is also enabled. Finally, we discuss the potential for realizing self-powering by means of tapping optical signals traversing the access network rather than utilizing a dedicated pump source. Bernhard Schrenk, Fabian Laudenbach, Roland Lieger, Thomas Lorünser, Paraskevas Bakopoulos, Andreas Poppe, Martin Stierle, Hercules Avramopoulos, Helmut Leopold |
IEEE J. Sel. Areas Commun. | 4 |
| 2014 | A Multi-layer and MultiTenant Cloud Assurance Evaluation MethodologyabstractData with high security requirements is being processed and stored with increasing frequency in the Cloud. To guarantee that the data is being dealt in a secure manner we investigate the applicability of Assurance methodologies. In a typical Cloud environment the setup of multiple layers and different stakeholders determines security properties of individual components that are used to compose Cloud applications. We present a methodology adapted from Common Criteria for aggregating information reflecting the security properties of individual constituent components of Cloud applications. This aggregated information is used to categorise overall application security in terms of Assurance Levels and to provide a continuous assurance level evaluation. It gives the service owner an overview of the security of his service, without requiring detailed manual analyses of log files. Aleksandar Hudic, Markus Tauber, Thomas Lorünser, Maria Krotsiani, George Spanoudakis, Andreas Mauthe, Edgar R. Weippl |
CloudCom | 3 |
| 2008 | Security processor with quantum key distributionabstractWe present a fully operable security gateway prototype, integrating quantum key distribution and realised as a system-on-chip. It is implemented on a field-programmable gate array and provides a virtual private network with low latency and gigabit throughput. The seamless hard- and software integration of a quantum key distribution layer enables high key-update rates for the encryption modules. Hence, the amount of data encrypted with one session key can be significantly decreased. We realise a highly modular architecture and make extensive use of software/hardware partitioning. This work is the first approach towards application of a new key distribution technology in dedicated security processors. In particular, it elaborates requirements for the integration of quantum key distribution on a chip level. Thomas Lorünser, Edwin Querasser, Thomas Matyus, Momtchil Peev, Johannes Wolkerstorfer, Michael Hutter, Alexander Szekely, Ilse Wimberger, Christian Pfaffel-Janser, Andreas Neppach |
ASAP | 1 |
| 2008 | Key Management of Quantum Generated Keys in IPsec
Andreas Neppach, Christian Pfaffel-Janser, Ilse Wimberger, Thomas Lorünser, Michael Meyenburg, Alexander Szekely, Johannes Wolkerstorfer |
SECRYPT | 4 |