VLDB 2026 Research / reviewers in the wild / expert
Henrich Christopher Pöhls
dblp:69/154 · also Henrich C. Pöhls
· DBLP profile ↗
26ranked-venue papers
9as first author
3since 2021 · last 2025
0000-0002-7256-0387ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 22 · 9 first-author · 3 since 2021Computer networks · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Checking the Impact of Security Standardization - A Case Study on Bluetooth LE Pairing of Internet-of-Things Devices
Henrich Christopher Pöhls, Lukas Steffens |
SEC (2) | 1 |
| 2024 | MQfilTTr: Strengthening Smart Home Privacy Through MQTT Traffic Manipulation
Henrich Christopher Pöhls, Sven Gebauer, Fabian Scharnböck, Korbinian Spielvogel, Joachim Posegga |
WISTP | 1 |
| 2021 | Towards GDPR-compliant data processing in modern SIEM systems
Florian Menges, Tobias Latzo, Manfred Vielberth, Sabine Sobola, Henrich Christopher Pöhls, Benjamin Taubmann, Johannes Köstler, Alexander Puchta, Felix C. Freiling, Hans P. Reiser, Günther Pernul |
Comput. Secur. | 5 |
| 2020 | Fully invisible protean signatures schemesabstractProtean signatures (PSs), recently introduced by Krenn et al . (CANS ‘18), allow a semi‐trusted third party (the sanitiser ), to modify a signed message in a controlled way: the signer can define the message parts to be arbitrarily editable by the sanitiser, as well as message parts which can be redacted (but not altered otherwise) by the sanitiser. Thus, PS s generalise both redactable signatures (RSs) and sanitisable signatures (SSs) into a single notion. Invisibility for PSs guarantees that no outsider (i.e. any party not being signer or sanitiser) can decide which message parts can be edited. However, the current definition of invisibility does not prohibit that an outsider can decide which parts are redactable – only which parts can be edited are hidden. This negatively impacts the privacy guarantees provided by this definition. The authors extend PSs to be fully invisible. Their notion guarantees that an outsider can identify neither editable nor redactable parts. They, therefore, introduce the new notions of invisible RS s and invisible non‐accountable SSs ( ), along with a consolidated framework for aggregate signatures. Using those building blocks, their resulting construction is significantly more efficient than the original scheme by Krenn et al ., which they demonstrate in a prototypical implementation. Stephan Krenn, Henrich Christopher Pöhls, Kai Samelin, Daniel Slamanig |
IET Inf. Secur. | 2 |
| 2018 | CryptSDLC: Embedding Cryptographic Engineering into Secure Software Development LifecycleabstractApplication development for the cloud is already challenging because of the complexity caused by the ubiquitous, interconnected, and scalable nature of the cloud paradigm. But when modern secure and privacy aware cloud applications require the integration of cryptographic algorithms, developers even need to face additional challenges: An incorrect application may not only lead to a loss of the intended strong security properties but may also open up additional loopholes for potential breaches some time in the near or far future. To avoid these pitfalls and to achieve dependable security and privacy by design, cryptography needs to be systematically designed into the software, and from scratch. We present a system architecture providing a practical abstraction for the many specialists involved in such a development process, plus a suitable cryptographic software development life cycle methodology on top of the architecture. The methodology is complemented with additional tools supporting structured inter--domain communication and thus the generation of consistent results: cloud security and privacy patterns, and modelling of cloud service level agreements. We conclude with an assessment of the use of the Cryptographic Software Design Life Cycle (CryptSDLC) in a EU research project. Thomas Lorünser, Henrich Christopher Pöhls, Leon Sell, Thomas Länger |
ARES | 2 |
| 2018 | Protean Signature Schemes
Stephan Krenn, Henrich Christopher Pöhls, Kai Samelin, Daniel Slamanig |
CANS | 2 |
| 2018 | C3S: Cryptographically Combine Cloud Storage for Cost-Efficient Availability and ConfidentialityabstractIncreasing the availability by using multiple cloud storage providers for replication comes at a price; not only does it increase storage costs with every replica, it also greatly disperses the information to different cloud storage systems. Thus, all storage locations must be trusted to not read that data. Contrary the cryptographic technique of secret sharing splits data into confidentiality protected shares and if the adversary does not have access to more than a pre-defined threshold k of those shares, then the data's confidentiality is protected. At the same time secret sharing also increases the availability because the legitimate user must only download the data from k out of n shares. The goal of this paper is to quantify the economic advantages of efficient and secure information dispersal strategies in multi-cloud settings based on the current market situation. Therefore, we put together a database of 63 cloud storage offers and analyzed opportunities to combine them into virtual storage services delivering availabilities of 99.999% at the best price. Additionally, the combined multi-cloud storage is leaning towards data protection legislation of the European Union (EU), as any combination of k shares includes at least one from an EU-based provider. This inhibits non-EU jurisdictions to 'subpoena' the required number of shares to reconstruct data without the help of an EU-based provider. Our findings show that it is possible to find combinations which give the cloud storage consumer the wanted high availability and legal compliance guarantee at half the cost of any two providers from within the EU storing unencrypted replicas. Leon Sell, Henrich Christopher Pöhls, Thomas Lorünser |
CloudCom | 2 |
| 2018 | The Road to Privacy in IoT: Beyond Encryption and Signatures, Towards Unobservable CommunicationabstractPrivacy requires more than just encryption of data before and during transmission. Privacy would actually demand hiding the sheer fact that communication takes place. This requires to protect meta-data from observation. We think that this feature is in particular useful and interesting for the Internet-of-Things. However, it requires strong cryptographic security mechanisms, like encryption of communication, to be in place. We motivate the need for strong privacy protection by highlighting privacy issues in a smart home use-case. We advance beyond encryption and discuss which existing techniques can be used to achieve unobservable communication. Then we describe the architecture needed to provide strong protection in this particular use-case. Lastly, we present the building blocks of the architecture we implemented so far on the Re-Mote sensor nodes running Contiki OS and sketch the computational and network overheads imposed by these techniques. Ralf C. Staudemeyer, Henrich Christopher Pöhls, Marcin Wójcik |
WOWMOM | 2 |
| 2017 | Position Paper: The Past, Present, and Future of Sanitizable and Redactable SignaturesabstractSanitizable signature schemes (SSS), as well as redactable signature schemes (RSS), gained a lot of attention in the recent past. In a nutshell, both types of signature schemes allow to alter signed data in a controlled way by a, potentially semi-trusted, third party. The resulting signatures still verify. Thus, the authenticity of the subsequently modified content is preserved. In this position paper, we discuss the state-of-the-art, and highlight potential future research opportunities. We hope this work gives rise to additional ideas, real-life use-cases, and interesting upcoming research, helping to bring both primitives into practice. Hence, this paper is meant as a starting point for readers interested in these primitives, looking for new research and application opportunities. In other words, we think that both primitives deserve further attention. Arne Bilzhause, Henrich Christopher Pöhls, Kai Samelin |
ARES | 2 |
| 2017 | Practical Strongly Invisible and Strongly Accountable Sanitizable Signatures
Michael Till Beck, Jan Camenisch, David Derler, Stephan Krenn, Henrich Christopher Pöhls, Kai Samelin, Daniel Slamanig |
ACISP (1) | 5 |
| 2016 | Cryptographically Enforced Four-Eyes PrincipleabstractThe 4-eyes principle (4EP) is a well-known access control and authorization principle, and used in many scenarios to minimize the likelihood of corruption. It states that at least two separate entities must approve a message before it is considered authentic. Hence, an adversarial party aiming to forge bogus content is forced to convince other parties to collude in the attack. We present a formal framework along with a suitable security model. Namely, a party sets a policy for a given message which involves multiple additional approvers in order to authenticate the message. Finally, we show how these signatures are black-box realized by secure sanitizable signature schemes. Arne Bilzhause, Manuel Huber 0001, Henrich Christopher Pöhls, Kai Samelin |
ARES | 3 |
| 2016 | PRISMACLOUD Tools: A Cryptographic Toolbox for Increasing Security in Cloud ServicesabstractThe EC Horizon 2020 project PRISMACLOUD aims at cryptographically addressing several severe risks threatening end user security and privacy in current cloud settings. This shall be achieved by the provision of a reusable toolbox encapsulating cryptographic functionality from which dependably secure cloud services can be assembled. In order to provide a tangible abstraction of the complexity involved with the construction of cryptographically secured cloud services, we introduce the four-layer PRISMACLOUD architecture. Top down, it consists of a use cases (application) layer, a services layer, a tools layer, and a cryptographic primitives and protocols layer. In this paper we provide a detailed description of the PRISMACLOUD tools in terms of functional components, as well as how they interact to provide the desired security functionality. We also briefly describe the cutting-edge cryptographic primitives which are encompassed by the tools. Both the toolbox and the cryptographic primitives and protocols are being currently developed and will be provided as reference implementation by project end in July 2018. Thomas Lorünser, Daniel Slamanig, Thomas Länger, Henrich Christopher Pöhls |
ARES | 4 |
| 2016 | ECDSA on Things: IoT Integrity Protection in Practise
Johannes Bauer 0003, Ralf C. Staudemeyer, Henrich Christopher Pöhls, Alexandros G. Fragkiadakis |
ICICS | 3 |
| 2016 | Integrity and Authenticity Protection with Selective Disclosure Control in the Cloud & IoT
Christoph Frädrich, Henrich Christopher Pöhls, Wolfgang Popp, Noëlle Rakotondravony, Kai Samelin |
ICICS | 2 |
| 2016 | Towards quantifying the cost of a secure IoT: Overhead and energy consumption of ECC signatures on an ARM-based deviceabstractIn this paper, we document the overhead in terms of runtime, firmware size, communication and energy consumption for Elliptic Curve Cryptography (ECC) signatures of modern ARM-based constrained devices. The experiments we have undertaken show that the cryptographic capabilities of the investigated Zolertia Re-Mote based on a TI's CC2538 chipset running Contiki OS is indeed suitable for the Internet-of-Things (IoT): Computing a signature using a curve with a 192-bit key length adds an additional runtime of roughly 200 ms. However, we found that in comparison to sending an unsigned message approximately two-thirds of the runtime overhead is spent on cryptographic operations, while sending the signed message accounts for the remainder. We give real measurements which can be used as a basis for analytical models. Our measurements show that the saving gained by using curves with lower security levels (i. e., 160-bit key length) is not worth the sacrifice in protection. While signatures add non-negligible overhead, we still think that the additional 200 ms (signing with secp192r) is worth consideration. This paper gives an indication of the true costs of cryptographically protected message integrity which is greater or equal to the cost of encryption. We show what needs to be spent in order to verify the origin of the data in the application, since in the IoT it will have travelled through many `things'. Max Mossinger, Benedikt Petschkuhn, Johannes Bauer 0003, Ralf C. Staudemeyer, Marcin Wójcik, Henrich Christopher Pöhls |
WoWMoM | 6 |
| 2015 | Accountable Redactable SignaturesabstractRedactable signature schemes (RSS) allow removing blocks from signed data. State-of-the-art schemes have public redactions, i.e., Any party can remove parts from a signed message. This prohibits meaningful definitions of accountability. We address this gap by introducing the notion of accountable redactable signature schemes (ARSS). We present a generic construction which couples a sanitizable signature scheme (SSS) to profit from its accountability with an RSS to maintain the reduced malleability of RSSs. Depending on the building blocks, the resulting scheme offers transparency or public accountability. Transparency provides stronger privacy guarantees, while public accountability meets legal and application requirements. Henrich Christopher Pöhls, Kai Samelin |
ARES | 1 |
| 2014 | On Updatable Redactable Signatures
Henrich Christopher Pöhls, Kai Samelin |
ACNS | 1 |
| 2013 | Scope of Security Properties of Sanitizable Signatures RevisitedabstractSanitizable signature schemes allow for altering signed data in a signer-controlled way by a semi-trusted third party. This is contrary to standard digital signature schemes, which do not permit any modifications by any party without invalidating the signature. Due to transparency, a strong privacy notion, outsiders cannot see if the signature for a message was created by the signer or by the semi-trusted party. Accountability allows the signer to prove to outsiders if a message was original or touched by the semi-trusted party. Currently, block-level accountability requires to drop transparency. We allow for accountability for sanitizable signatures with transparency on the block-level. Additionally, we generalize the concept of block-level properties to groups. This offers a even more fine-grained control and leads to more efficient schemes. We prove that group-level definitions imply both the block-level and message-level notions. We derive a provably secure construction, achieving our enhanced notions. A further modification of our construction achieves efficient group-level non-interactive public accountability. This construction only requires a constant amount of signature generations to achieve this property. Finally, we have implemented our constructions and the scheme introduced by Brzuska et al. at PKC '09 and provide a detailed performance analysis of our reference implementations. Hermann de Meer, Henrich Christopher Pöhls, Joachim Posegga, Kai Samelin |
ARES | 2 |
| 2013 | Malleable Signatures for Resource Constrained Platforms
Henrich Christopher Pöhls, Stefan Peters, Kai Samelin, Joachim Posegga, Hermann de Meer |
WISTP | 1 |
| 2012 | On Structural Signatures for Tree Data Structures
Kai Samelin, Henrich Christopher Pöhls, Arne Bilzhause, Joachim Posegga, Hermann de Meer |
ACNS | 2 |
| 2012 | Redactable Signatures for Independent Removal of Structure and Content
Kai Samelin, Henrich Christopher Pöhls, Arne Bilzhause, Joachim Posegga, Hermann de Meer |
ISPEC | 2 |
| 2012 | Flexible Redactable Signature Schemes for Trees - Extended Security Model and Construction
Henrich Christopher Pöhls, Kai Samelin, Hermann de Meer, Joachim Posegga |
SECRYPT | 1 |
| 2011 | Sanitizable Signatures in XML Signature - Performance, Mixing Properties, and Revisiting the Property of Transparency
Henrich Christopher Pöhls, Kai Samelin, Joachim Posegga |
ACNS | 1 |
| 2010 | Towards Automated Processing of the Right of Access in Inter-organizational Web Service CompositionsabstractEnforcing the right of access to personal data usually is a long-running process between a data subject and an organization that processes personal data. As of today, this task is commonly realized using a manual process based on postal communication or personal attendance and ends up conflicting with trade secret protection. In this paper, we present an automated architecture to enable exercising the right of access in the domain of inter-organizational business processes based on Web Services technology. Deriving its requirements from the legal, economical, and technical obligations, we show the architecture's overall approach solving the conflict between trade secret and exercising the right of access. Ralph Herkenhöner, Hermann de Meer, Meiko Jensen, Henrich Christopher Pöhls |
SERVICES | 4 |
| 2008 | Verifiable and Revocable Expression of Consent to Processing of Aggregated Personal Data
Henrich Christopher Pöhls |
ICICS | 1 |
| 2006 | Smartcard Firewalls Revisited
Henrich Christopher Pöhls, Joachim Posegga |
CARDIS | 1 |