VLDB 2026 Research / reviewers in the wild / expert
Stephan Krenn
dblp:63/7821
· DBLP profile ↗
39ranked-venue papers
11as first author
12since 2021 · last 2026
0000-0003-2835-9093ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 35 · 10 first-author · 9 since 2021Theory of computation · 3 · 2 first-authorComputer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Topology-Hiding Path Validation for Large-Scale Quantum Key Distribution Networks
Stephan Krenn, Omid Mir, Thomas Lorünser, Sebastian Ramacher, Florian Wohner |
ACNS (3) | 1 |
| 2026 | bPk#: Delegatable Pseudonyms And Their Applications to National eID SystemsabstractElectronic identities (eIDs) are crucial in an increasingly digitalized environment. Pseudonyms, as offered by Austria's governmental sector-specific personal identifiers (bPks), can significantly improve privacy by ensuring that personal data is not universally traceable across public services and private companies. However, the current architecture comes with several challenges regarding availability, privacy, and authenticity, due to a fully centralized design. This paper proposes bPk#, a distributed architecture to address these issues, reducing reliance on the central authority, while still providing all functional requirements to the existing bPk system. In particular, users are delegated the rights to compute their own pseudonyms, thereby minimizing metadata revealed to the central authority, while (subsets of) service providers may receive the right to compute pseudonyms only within their own domain, thereby reducing the availability needs of the central authority. To the best of our knowledge, we provide the first formal framework for such delegatable pseudonym systems, together with a generic construction for which we provide formal security proofs. Furthermore, we propose a concrete instantiation of our construction, together with a reference implementation demonstrating the practical efficiency. Stephan Krenn, Doryan Lesaignoux, Sebastian Ramacher |
AsiaCCS | 1 |
| 2025 | Protecting Privacy in Federated Time Series Analysis: A Pragmatic Technology Review for Application Developers
Daniel Bachlechner, Ruben Helmut Hetfleisch, Stephan Krenn, Thomas Lorünser, Michael Rader |
CLOSER | 3 |
| 2025 | Seamless Post-Quantum Transition: Agile and Efficient Encryption for Data-at-Rest
Federico Valbusa, Stephan Krenn, Thomas Lorünser, Sebastian Ramacher |
SECRYPT | 2 |
| 2024 | NEWSROOM: Towards Automating Cyber Situational Awareness Processes and Tools for Cyber DefenceabstractCyber Situational Awareness (CSA) is an important element in both cyber security and cyber defence to inform processes and activities on strategic, tactical, and operational level. Furthermore, CSA enables informed decision making. The ongoing digitization and interconnection of previously unconnected components and sectors equally affects the civilian and military sector. In defence, this means that the cyber domain is both a separate military domain as well as a cross-domain and connecting element for the other military domains comprising land, air, sea, and space. Therefore, CSA must support perception, comprehension, and projection of events in the cyber space for persons with different roles and expertise. This paper introduces NEWSROOM, a research initiative to improve technologies, methods, and processes specifically related to CSA in cyber defence. For this purpose, NEWSROOM aims to improve methods for attacker behavior classification, cyber threat intelligence (CTI) collection and interaction, secure information access and sharing, as well as human computer interfaces (HCI) and visualizations to provide persons with different roles and expertise with accurate and easy to comprehend mission- and situation-specific CSA. Eventually, NEWSROOM’s core objective is to enable informed and fast decision-making in stressful situations of military operations. The paper outlines the concept of NEWSROOM and explains how its components can be applied in relevant application scenarios. Markus Wurzenberger, Stephan Krenn, Max Landauer, Florian Skopik, Cora Lisa Perner, Jarno Lötjönen, Jani Päijänen, Georgios Gardikis, Nikos Alabasis, Liisa Sakerman, Kristiina Omri, Juha Röning, Kimmo Halunen, Vincent Thouvenot, Martin Weise, Andreas Rauber, Vasileios Gkioulos, Sokratis K. Katsikas, Luigi Sabetta, Jacopo Bonato, Rocío Ortíz, Daniel Navarro, Nikolaos Stamatelatos, Ioannis Avdoulas, Rudolf Mayer, Andreas Ekelhart, Ioannis Giannoulakis, Emmanouil Kafetzakis, Antonello Corsi, Ulrike Lechner, Corinna Schmitt |
ARES | 2 |
| 2024 | Integrating Secure Multiparty Computation into Data Spaces
Veronika Siska, Thomas Lorünser, Stephan Krenn, Christoph Fabianek |
CLOSER | 3 |
| 2024 | Beyond selective disclosure: Extending distributed p-ABC implementations by commit-and-prove techniquesabstractThe increasing user awareness and regulatory framework (e.g., GDPR, eIDAS2) have contributed to considering data minimization and privacy-by-design as central guiding principles for new systems. Among others, this has led to a paradigm shift towards Self-Sovereign Identity solutions to put the user in full control over their data. Despite the promising landscape, privacy-preserving Attribute-Based Credentials (p-ABC) have not been widely adopted, mainly due to the lack of secure, flexible and efficient implementations that cover the basic and advanced needs in p-ABC systems. In this work, we tackle this gap by developing an improved zero-knowledge showing protocol of a distributed p-ABC scheme based on Pointcheval-Sanders Multi-Signatures to allow for modular extensions through commit-and-prove techniques. We use it to implement a flexible p-ABC system with decentralized issuance that, apart from the basic notions of p-ABCs, covers range proofs, pseudonyms, inspection and revocation. Lastly, we thoroughly evaluate the performance of the system under different testbed conditions, showing a significant efficiency improvement over previous implementations. Jesús García Rodríguez, Stephan Krenn, Jorge Bernal Bernabé, Antonio F. Skarmeta |
Comput. Networks | 2 |
| 2024 | To pass or not to pass: Privacy-preserving physical access controlabstractAnonymous or attribute-based credential (ABC) systems are a versatile and important cryptographic tool to achieve strong access control guarantees while simultaneously respecting the privacy of individuals. A major problem in the practical adoption of ABCs is their transferability, i.e., such credentials can easily be duplicated, shared or lent. One way to counter this problem is to tie ABCs to biometric features of the credential holder and to require biometric verification on every use. While this is certainly not a viable solution for all ABC use-cases, there are relevant and timely use-cases, such as vaccination credentials as widely deployed during the COVID-19 pandemic. In such settings, ABCs that are tied to biometrics, which we call Biometric-Bound Attribute-Based Credentials (bb-ABC ), allow to implement scalable and privacy-friendly systems to control physical access to (critical) infrastructure and facilities. While there are some previous works on bb-ABC in the literature, the state of affairs is not satisfactory. Firstly, in existing work the problem is treated in a very abstract way when it comes to the actual type of biometrics. Thus, it does not provide concrete solutions which allow for assessing their practicality when deployed in a real-world setting. Secondly, there is no formal model which rigorously captures bb-ABC systems and their security requirements, making it hard to assess their security guarantees. With this work we overcome these limitations and provide a rigorous formalization of bb-ABC systems. Moreover, we introduce two generic constructions which offer different trade-offs between efficiency and trust assumptions, and provide benchmarks from a concrete instantiation of such a system using facial biometrics. The latter represents a contact-less biometric feature that provides acceptable accuracy and seems particularly suitable to the above use-case. Jesús García Rodríguez, Stephan Krenn, Daniel Slamanig |
Comput. Secur. | 2 |
| 2023 | RiBAC: Strengthening Access Control Systems for Pandemic Risk Reduction while Preserving PrivacyabstractTraditional (physical) access control systems are well-established mechanisms, allowing organizations to determine who should be able to access which physical space. This can either be a facility such as a critical infrastructure with a well-defined set of individuals, e.g., employees, or public spaces where everyone can be subject to access control. During the Covid-19 pandemic, additional features to reduce the risks of individuals when entering spaces became popular or even mandatory, including automatic scanning for protective wear (e.g., whether an individual wears a mask), body temperature checks, or digital health certificates, certifying that one has been negatively tested for, or vaccinated against, Covid-19. We refer to this as risk-based access control (RiBAC). Stephan Krenn, Jan Orlicky, Daniel Slamanig, Tomas Trpisovský |
ARES | 1 |
| 2022 | A Privacy-Preserving Auction Platform with Public Verifiability for Smart Manufacturing
Thomas Lorünser, Florian Wohner, Stephan Krenn |
ICISSP | 3 |
| 2021 | Single-Use Delegatable Signatures Based on Smart ContractsabstractDelegation of cryptographic signing rights has found many application in the literature and the real world. However, despite very advanced functionalities and specific use cases, existing solutions share the natural limitation that the number of usages of these signing rights cannot be efficiently limited, but users can at most be disincentivized to abuse their rights. Stephan Krenn, Thomas Lorünser |
ARES | 1 |
| 2021 | Issuer-Hiding Attribute-Based Credentials
Jan Bobolz, Fabian Eidens, Stephan Krenn, Sebastian Ramacher, Kai Samelin |
CANS | 3 |
| 2020 | Privacy-Preserving Incentive Systems with Highly Efficient Point-CollectionabstractIncentive systems (such as customer loyalty systems) are omnipresent nowadays and deployed in several areas such as retail, travel, and financial services. Despite the benefits for customers and companies, this involves large amounts of sensitive data being transferred and analyzed. These concerns initiated research on privacy-preserving incentive systems, where users register with a provider and are then able to privately earn and spend incentive points. Jan Bobolz, Fabian Eidens, Stephan Krenn, Daniel Slamanig, Christoph Striecks |
AsiaCCS | 3 |
| 2020 | Fully invisible protean signatures schemesabstractProtean signatures (PSs), recently introduced by Krenn et al . (CANS ‘18), allow a semi‐trusted third party (the sanitiser ), to modify a signed message in a controlled way: the signer can define the message parts to be arbitrarily editable by the sanitiser, as well as message parts which can be redacted (but not altered otherwise) by the sanitiser. Thus, PS s generalise both redactable signatures (RSs) and sanitisable signatures (SSs) into a single notion. Invisibility for PSs guarantees that no outsider (i.e. any party not being signer or sanitiser) can decide which message parts can be edited. However, the current definition of invisibility does not prohibit that an outsider can decide which parts are redactable – only which parts can be edited are hidden. This negatively impacts the privacy guarantees provided by this definition. The authors extend PSs to be fully invisible. Their notion guarantees that an outsider can identify neither editable nor redactable parts. They, therefore, introduce the new notions of invisible RS s and invisible non‐accountable SSs ( ), along with a consolidated framework for aggregate signatures. Using those building blocks, their resulting construction is significantly more efficient than the original scheme by Krenn et al ., which they demonstrate in a prototypical implementation. Stephan Krenn, Henrich Christopher Pöhls, Kai Samelin, Daniel Slamanig |
IET Inf. Secur. | 1 |
| 2019 | Practical Group-Signatures with Privacy-Friendly OpeningsabstractGroup signatures allow creating signatures on behalf of a group, while remaining anonymous. To prevent misuse, there exists a designated entity, named the opener, which can revoke anonymity by generating a proof which links a signature to its creator. Still, many intermediate cases have been discussed in the literature, where not the full power of the opener is required, or the users themselves require the power to claim (or deny) authorship of a signature and (un-)link signatures in a controlled way. However, these concepts were only considered in isolation. Stephan Krenn, Kai Samelin, Christoph Striecks |
ARES | 1 |
| 2019 | iUC: Flexible Universal Composability Made Simple
Jan Camenisch, Stephan Krenn, Ralf Küsters, Daniel Rausch 0001 |
ASIACRYPT (3) | 2 |
| 2019 | Breaking and Fixing Anonymous Credentials for the Cloud
Ulrich Haböck, Stephan Krenn |
CANS | 2 |
| 2018 | Protean Signature Schemes
Stephan Krenn, Henrich Christopher Pöhls, Kai Samelin, Daniel Slamanig |
CANS | 1 |
| 2017 | Towards the Adoption of Secure Cloud Identity ServicesabstractEnhancing trust among service providers and end-users with respect to data protection is an urgent matter in the growing information society. In response, CREDENTIAL proposes an innovative cloud-based service for storing, managing, and sharing of digital identity information and other highly critical personal data with a demonstrably higher level of security than other current solutions. CREDENTIAL enables end-to-end confidentiality and authenticity as well as improved privacy in cloud-based identity management and data sharing scenarios. In this paper, besides clarifying the vision and use cases, we focus on the adoption of CREDENTIAL. Firstly, for adoption by providers, we elaborate on the functionality of CREDENTIAL, the services implementing these functions, and the physical architecture needed to deploy such services. Secondly, we investigate factors from related research that could be used to facilitate CREDENTIAL's adoption and list key benefits as convincing arguments. Alexandros Kostopoulos, Evangelos Sfakianakis, Ioannis P. Chochliouros, John Sören Pettersson, Stephan Krenn, Welderufael B. Tesfay, Andrea Migliavacca, Felix Hörandner |
ARES | 5 |
| 2017 | Practical Strongly Invisible and Strongly Accountable Sanitizable Signatures
Michael Till Beck, Jan Camenisch, David Derler, Stephan Krenn, Henrich Christopher Pöhls, Kai Samelin, Daniel Slamanig |
ACISP (1) | 4 |
| 2017 | Towards Attribute-Based Credentials in the Cloud
Stephan Krenn, Thomas Lorünser, Anja Salzer, Christoph Striecks |
CANS | 1 |
| 2017 | Batch-verifiable Secret Sharing with Unconditional Privacy
Stephan Krenn, Thomas Lorünser, Christoph Striecks |
ICISSP | 1 |
| 2016 | Efficient and Privacy Preserving Third Party Auditing for a Distributed Storage SystemabstractWhen using distributed storage systems to outsource data storage into the cloud, it is often vital that this is done in a privacy preserving way, i.e., without the storage servers learning anything about the stored data. Especially when storing critical data, one often further requires efficient means to check whether the data is actually stored correctly on these servers. In the best case, such an auditing could itself be outsourced to a third party which does not need to be trusted by the data owner. That is, also the auditing mechanism should guarantee privacy, even if the auditor collaborates with a (sub) set of the storage servers. However, so far only a small number of privacy preserving third party auditing mechanisms has been presented for single server storage solutions, and no such protocols exist at all for a distributed storage setting. In this paper, we therefore define and instantiate a privacy preserving auditable distributed storage system. Our instantiation can be based on any homomorphic secret sharing scheme, and is fully keyless, efficient, and information-theoretically private. Furthermore, it supports batch audits, and is backward compatible with existing secret sharing based storage solutions. Denise Demirel, Stephan Krenn, Thomas Lorünser, Giulia Traverso |
ARES | 2 |
| 2016 | CREDENTIAL: A Framework for Privacy-Preserving Cloud-Based Data SharingabstractData sharing - and in particular sharing of identity information - plays a vital role in many online systems. While in closed and trusted systems security and privacy can be managed more easily, secure and privacy-preserving data sharing as well as identity management becomes difficult when the data are moved to publicly available and semi-trusted systems such as public clouds. CREDENTIAL is therefore aiming on the development of a secure and privacy-preserving data sharing and identity management platform which gives stronger security guarantees than existing solutions on the market. The results will be showcased close to market-readiness through pilots from the domains of eHealth, eBusiness, and eGovernment, where security and privacy are crucial. From a technical perspective, the privacy and authenticity guarantees are obtained from sophisticated cryptographic primitives such as proxy re-encryption and redactable signatures. Felix Hörandner, Stephan Krenn, Andrea Migliavacca, Florian Thiemer, Bernd Zwattendorfer |
ARES | 2 |
| 2016 | Universal Composition with Responsive Environments
Jan Camenisch, Robert R. Enderlein, Stephan Krenn, Ralf Küsters, Daniel Rausch 0001 |
ASIACRYPT (2) | 3 |
| 2016 | Signer-Anonymous Designated-Verifier Redactable Signatures for Cloud-Based Data Sharing
David Derler, Stephan Krenn, Daniel Slamanig |
CANS | 2 |
| 2016 | A counterexample to the chain rule for conditional HILL entropy
Stephan Krenn, Krzysztof Pietrzak, Akshay Wadia, Daniel Wichs |
Comput. Complex. | 1 |
| 2015 | Recovering Lost Device-Bound Credentials
Foteini Baldimtsi, Jan Camenisch, Lucjan Hanzlik, Stephan Krenn, Anja Lehmann, Gregory Neven |
ACNS | 4 |
| 2015 | Efficient Zero-Knowledge Proofs for Commitments from Learning with Errors over RingsabstractWe extend a commitment scheme based on the learning with errors over rings ( $$\mathsf{RLWE}$$ ) problem, and present efficient companion zero-knowledge proofs of knowledge. Our scheme maps elements from the ring (or equivalently, n elements from $$\mathbb F_q$$ ) to a small constant number of ring elements. We then construct $$\varSigma $$ -protocols for proving, in a zero-knowledge manner, knowledge of the message contained in a commitment. We are able to further extend our basic protocol to allow us to prove additive and multiplicative relations among committed values. Our protocols have a communication complexity of $$\mathcal {O}(Mn\log q)$$ and achieve a negligible knowledge error in one run. Here M is the constant from a rejection sampling technique that we employ, and can be set close to 1 by adjusting other parameters. Previously known $$\varSigma $$ -protocols for LWE-related languages only achieved a noticeable or even constant knowledge error (thus requiring many repetitions of the protocol), or relied on “smudging” out the error (which necessitates working over large fields, resulting in poor efficiency). Fabrice Benhamouda, Stephan Krenn, Vadim Lyubashevsky, Krzysztof Pietrzak |
ESORICS (1) | 2 |
| 2015 | Formal Treatment of Privacy-Enhancing Credential Systems
Jan Camenisch, Stephan Krenn, Anja Lehmann, Gert Læssøe Mikkelsen, Gregory Neven, Michael Østergaard Pedersen |
SAC | 2 |
| 2014 | Better Zero-Knowledge Proofs for Lattice Encryption and Their Application to Group Signatures
Fabrice Benhamouda, Jan Camenisch, Stephan Krenn, Vadim Lyubashevsky, Gregory Neven |
ASIACRYPT (1) | 3 |
| 2013 | Learning with Rounding, Revisited - New Reduction, Properties and Applications
Joël Alwen, Stephan Krenn, Krzysztof Pietrzak, Daniel Wichs |
CRYPTO (1) | 2 |
| 2013 | A Counterexample to the Chain Rule for Conditional HILL Entropy - And What Deniable Encryption Has to Do with It
Stephan Krenn, Krzysztof Pietrzak, Akshay Wadia |
TCC | 1 |
| 2012 | Commitments and Efficient Zero-Knowledge Proofs from Learning Parity with Noise
Abhishek Jain 0002, Stephan Krenn, Krzysztof Pietrzak, Aris Tentes |
ASIACRYPT | 2 |
| 2012 | Full proof cryptography: verifiable compilation of efficient zero-knowledge protocolsabstractDevelopers building cryptography into security-sensitive applications face a daunting task. Not only must they understand the security guarantees delivered by the constructions they choose, they must also implement and combine them correctly and efficiently. Cryptographic compilers free developers from this task by turning high-level specifications of security goals into efficient implementations. Yet, trusting such tools is hard as they rely on complex mathematical machinery and claim security properties that are subtle and difficult to verify. In this paper we present ZKCrypt, an optimizing cryptographic compiler achieving an unprecedented level of assurance without sacrificing practicality for a comprehensive class of cryptographic protocols, known as Zero-Knowledge Proofs of Knowledge. The pipeline of ZKCrypt integrates purpose-built verified compilers and verifying compilers producing formal proofs in the CertiCrypt framework. By combining the guarantees delivered by each stage, ZKCrypt provides assurance that the output implementation securely realizes the abstract proof goal given as input. We report on the main characteristics of ZKCrypt, highlight new definitions and concepts at its foundations, and illustrate its applicability through a representative example of an anonymous credential system José Bacelar Almeida, Manuel Barbosa, Endre Bangerter, Gilles Barthe, Stephan Krenn, Santiago Zanella-Béguelin |
CCS | 5 |
| 2011 | A Framework for Practical Universally Composable Zero-Knowledge Protocols
Jan Camenisch, Stephan Krenn, Victor Shoup |
ASIACRYPT | 2 |
| 2011 | Cache Games - Bringing Access-Based Cache Attacks on AES to PracticeabstractSide channel attacks on cryptographic systems exploit information gained from physical implementations rather than theoretical weaknesses of a scheme. In recent years, major achievements were made for the class of so called access-driven cache attacks. Such attacks exploit the leakage of the memory locations accessed by a victim process. In this paper we consider the AES block cipher and present an attack which is capable of recovering the full secret key in almost real time for AES-128, requiring only a very limited number of observed encryptions. Unlike previous attacks, we do not require any information about the plaintext (such as its distribution, etc.). Moreover, for the first time, we also show how the plaintext can be recovered without having access to the cipher text at all. It is the first working attack on AES implementations using compressed tables. There, no efficient techniques to identify the beginning of AES rounds is known, which is the fundamental assumption underlying previous attacks. We have a fully working implementation of our attack which is able to recover AES keys after observing as little as 100 encryptions. It works against the OpenS SL 0.9.8n implementation of AES on Linux systems. Our spy process does not require any special privileges beyond those of a standard Linux user. A contribution of probably independent interest is a denial of service attack on the task scheduler of current Linux systems (CFS), which allows one to observe (on average) every single memory access of a victim process. David Gullasch, Endre Bangerter, Stephan Krenn |
IEEE Symposium on Security and Privacy | 3 |
| 2010 | A Certifying Compiler for Zero-Knowledge Proofs of Knowledge Based on Sigma-Protocols
José Bacelar Almeida, Endre Bangerter, Manuel Barbosa, Stephan Krenn, Ahmad-Reza Sadeghi, Thomas Schneider 0003 |
ESORICS | 4 |
| 2010 | Efficiency Limitations for Σ-Protocols for Group Homomorphisms
Endre Bangerter, Jan Camenisch, Stephan Krenn |
TCC | 3 |