VLDB 2026 Research / reviewers in the wild / expert
Florian Tschorsch
dblp:82/9385
· DBLP profile ↗
38ranked-venue papers
3as first author
24since 2021 · last 2026
0000-0001-6716-7225ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 20 · 3 first-author · 11 since 2021Security and privacy · 15 · 12 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 2 since 2021Software engineering, systems software and programming languages · 4 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Network-level Side-channel Attacks in the Lightning NetworkabstractThe Lightning network (LN) offers a solution to Bitcoin’s scalability limitations by providing fast and private off-chain payments. In addition to the LN’s long known application-level centralisation, recent work has highlighted its centralisation at the network level which makes it vulnerable to attacks on privacy by malicious actors. In this work, we explore the LN’s susceptibility to further attacks by a network-level actor such as a malicious autonomous system. We show that a network-level adversary can identify and interfere with all payments routed via their network by just examining the packet headers. Our results indicate that it is viable to accurately identify LN messages despite the fact that all inter-peer communication is end-to-end encrypted. While this can likely be used to achieve various adversarial objectives, we show how it can be exploited by an adversary to impose payment censorship and induce channel congestion. Additionally, we describe how a network-level observer can determine a node’s role in a payment path based on timing, direction of flow and message type, and demonstrate the approach’s feasibility using experiments in a live instance of the network. Simulations of the attack on a snapshot of the Lightning mainnet suggest that the impact of a congestion attack varies from mild to potentially dramatic depending on the adversary and type of payments that are censored. On the other hand, they show that the impact of a congestion attack, under the assumption that the adversary is not able to jam all channels, is less extreme. We analyse countermeasures the network can implement and come to the conclusion that an adequate solution involves constant message sizes as well as dummy traffic. Charmaine Ndolo, Florian Tschorsch |
ACM Trans. Internet Techn. | 2 |
| 2025 | BERMUDA: A BPSec-Compatible Key Management Scheme for DTNs
Fiona Fuchs, Felix Walter, Florian Tschorsch |
SEC (2) | 3 |
| 2025 | PrivTru: A Privacy-by-Design Data Trustee Minimizing Information Leakage
Lukas Gehring, Florian Tschorsch |
SEC (1) | 2 |
| 2025 | The Last Hop Attack: The Last Hop Attack: Why Loop Cover Traffic over Fixed Cascades Threatens AnonymityabstractAdvanced mix net designs use a combination of loop cover traffic and fixed cascades to detect when active adversaries delay or drop messages. In this paper, we propose the Last Hop Attack, a new attack algorithm that takes advantage of the fact that users send loop cover, i.e., messages sent to themselves over the same mix nodes that they also use to communicate with others. We use established privacy definitions based on indistinguishability games and prove that our algorithm can break strong anonymity notions. Our research shows that the Last Hop Attack breaks Sender Receiver Pair Unlinkability for any Anonymous Communication Network that utilizes loop cover traffic, fixed cascades, and no additional cover traffic. We furthermore conclude that the notions of Sender Message Unlinkability, Receiver Message Unlinkability~(and Unobservability), and Both Side Unlinkability~(and Unobservability) are unachievable in this setting. To the best of our knowledge, this impossibility result is the first to show that loop cover traffic can threaten anonymity. It allows us to conclude that mix nets that utilize loop cover traffic and fixed cascades must deploy additional cover traffic to achieve strong anonymity. Maximilian Weisenseel, Christoph Döpmann, Florian Tschorsch |
Proc. Priv. Enhancing Technol. | 3 |
| 2024 | Payment Censorship in the Lightning Network Despite Encrypted CommunicationabstractPayment Channel Networks (PCNs) have been a promising approach to scale blockchains. However, PCNs have limited liquidity: large-amount or multi-hop payments may fail. The major threat of PCNs liquidity is payment griefing, where the adversary who acts as the payee keeps withholding the payment, so that coins involved in the payment cannot be used for routing other payments before the payment expires. Payment griefing gives adversaries a chance to launch the congestion attack, where the adversary griefs a large number of payments and paralyses the entire PCN. Understanding congestion attacks, including their strategies and impact, is crucial for designing PCNs with better liquidity guarantees. However, existing research has only focused on the specific attacking strategies and specific aspects of their impact on PCNs. We fill this gap by studying the general congestion attack. Compared to existing attack strategies, in our framework each step serves an orthogonal purpose and is customisable, allowing the adversary to focus on different aspects of the liquidity. To evaluate the attack’s impact, we propose a generic method of quantifying PCNs' liquidity and effectiveness of the congestion attacks. We evaluate our general congestion attacks on Bitcoin’s Lightning Network, and show that with direct channels to 1.5% richest nodes, and ∼ 0.0096 BTC of cost, the adversary can launch a congestion attack that locks 47% (∼280 BTC) coins in the network; reduces success rate of payments by 16.0%∼60.0%; increases fee of payments by 4.5%∼16.0%; increases average attempts of payments by 42.0%∼115.3%; and increase the number of bankruptcy nodes (i.e., nodes with insufficient balance for making normal-size payments) by 26.6%∼109.4%, where the amounts of payments range from 0.001 to 0.019 BTC. Charmaine Ndolo, Florian Tschorsch |
AFT | 2 |
| 2024 | From Theory to Comprehension: A Comparative Study of Differential Privacy and k-AnonymityabstractThe notion of \varepsilon-differential privacy is a widely used concept of providing quantifiable privacy to individuals. However, it is unclear how to explain the level of privacy protection provided by a differential privacy mechanism with a set \varepsilon. In this study, we focus on users' comprehension of the privacy protection provided by a differential privacy mechanism. To do so, we study three variants of explaining the privacy protection provided by differential privacy: (1) the original mathematical definition; (2) \varepsilon translated into a specific privacy risk; and (3) an explanation using the randomized response technique. We compare users' comprehension of privacy protection employing these explanatory models with their comprehension of privacy protection of k-anonymity as baseline comprehensibility. Our findings suggest that participants' comprehension of differential privacy protection is enhanced by the privacy risk model and the randomized response-based model. Moreover, our results confirm our intuition that privacy protection provided by k-anonymity is more comprehensible. Saskia Nuñez von Voigt, Luise Mehner, Florian Tschorsch |
CODASPY | 3 |
| 2024 | Poster: On Integrating Sphinx in IPFSabstractThe Interplanetary File System (IPFS) [1] is a popular Peer-to-Peer (P2P) overlay network with a focus on content-addressed data exchange. While IPFS offers decentralized file storage, improving resilience, it suffers from privacy challenges [3]. In particular Bitswap, the data exchange protocol suffers under these challenges. That is, Bitswap contacts all neighbors for content discovery revealing interest to many participants. Erik Daniel, Florian Tschorsch |
IMC | 2 |
| 2024 | StarReact: Detecting Important Network Changes in BFT Protocols with Star-Based CommunicationabstractThreshold signatures have improved the scalability of BFT protocols by replacing all-to-all broadcast with star-based communication. On the flip side, this approach renders network re-organization and performance optimization more costly, because information can only be exchanged between the leader and all other nodes.We present StarReact,an extension for BFT protocols that relies on star-based communication to collect and disseminate quorum certificates. This extension allows all nodes of the system to measure and evaluate the network state by monitoring the messages disseminated by the leader. Each node decides independently if performance degradation justifies a leader change. By deploying a median filter, the measured commit latency of the system is evaluated by each node to determine if a network change has a lasting effect that warrants a change in leadership or should be ignored. We showcase how StarReact is able to identify important network changes for different deployment scenarios and explain how view change executions should be adapted to different environments to improve commit latency and potentially throughput for such systems. Martin Nischwitz, Marko Esche, Florian Tschorsch |
LCN | 3 |
| 2024 | Plausibly Deniable Content Discovery for Bitswap Using Random WalksabstractBitswap is the data exchange protocol for the content-addressed peer-to-peer overlay network IPFS. During content discovery, Bitswap reveals the interest of a peer in content to all neighbors, enabling the tracking of user interests. In our paper, we propose a modification of the Bitswap protocol, which enables source obfuscation using proxies for content discovery. The proxies are selected via a random-walk. Enabling content discovery through proxies introduces plausible deniability. We evaluate the protocol modification with a simulation. The protocol modification demonstrates enhanced privacy, while maintaining acceptable performance levels. Manuel Wedler, Erik Daniel, Florian Tschorsch |
LCN | 3 |
| 2024 | Exploring the design space of privacy-enhanced content discovery for bitswapabstractIPFS is a content-addressed peer-to-peer data network, which follows the paradigm of information centric networking. In IPFS, data is exchanged with the Bitswap protocol. For content discovery, Bitswap queries all neighbors for the content, leaking the interest to all neighbors. In our paper, we develop three privacy-enhanced protocols for content discovery, which reduce the interest leak from all neighbors to ideally one content provider. Our protocols use probabilistic data structures like Bloom filter and cryptographic approaches like Private Set Intersection. We implement our protocols as proof of concept and show how they can be integrated into the go implementation of Bitswap. Furthermore, we provide a measurement supported performance, load, and privacy evaluation of the three protocols, showing their feasibility trade-offs. Erik Daniel, Florian Tschorsch |
Comput. Commun. | 2 |
| 2023 | Modeling Tor Network Growth by Extrapolating Consensus DataabstractSince the Tor network is evolving into an infrastructure for anonymous communication, analyzing the consequences of network growth is becoming more relevant than ever. In particular, adding large amounts of resources may have unintentional consequences for the system performance as well as security. To this end, we contribute a methodology for the analysis of scaled Tor networks that enables researchers to leverage real-world network data. Based on historical network snapshots (consensuses), we derive and implement a model for methodically scaling Tor consensuses. This allows researchers to apply established research methods to scaled networks. We validate our model based on historical data, showing its applicability. Furthermore, we demonstrate the merits of our data-driven approach by conducting a simulation study to identify performance impacts of scaling Tor. Christoph Döpmann, Florian Tschorsch |
ARES | 2 |
| 2023 | Tornado Vote: Anonymous Blockchain-Based VotingabstractDecentralized apps (DApps) often hold significant cryptocurrency assets. In order to manage these assets and coordinate joint investments, shareholders leverage the underlying smart contract functionality to realize a transparent, verifiable, and secure decision-making process. That is, DApps implement proposal-based voting. Permissionless blockchains, however, lead to a conflict between transparency and anonymity; potentially preventing free decision-making if individual votes and intermediate results become public. In this paper, we therefore present Tornado Vote, a voting DApp for anonymous, fair, and practical voting on the Ethereum blockchain. We propose to use a cryptocurrency mixer such as Tornado Cash to reconcile transparency and anonymity. To this end, we adapt Tornado Cash and develop a voting protocol that implements a fair voting process. While Tornado Vote can technically process 10 k votes on Ethereum in approximately two hours, this is not feasible under realistic conditions: Third-party transactions on the Ethereum Mainnet reduce the possible throughput, and transaction fees make it infeasible to use all available block capacities. We therefore present various Gas cost models that yield lower bounds and economic estimations with respect to the required number of blocks and voting costs to assess and adjust Tornado Vote's feasibility trade-off. Robert Muth, Florian Tschorsch |
ICBC | 2 |
| 2023 | Improving Bitswap Privacy with Forwarding and Source ObfuscationabstractIPFS is a content-addressed decentralized peer-to-peer data network, using the Bitswap protocol for exchanging data. The data exchange leaks the information to all neighbors, compromising a user’s privacy. This paper investigates the suitability of forwarding with source obfuscation techniques for improving the privacy of the Bitswap protocol. The usage of forwarding can add plausible deniability and the source obfuscation provides additional protection against passive observers. First results showed that through trickle-spreading the source prediction could decrease to 40%, at the cost of an increased content fetching time. However, assuming short distances between content provider and consumer the content fetching time can be faster even with the additional source obfuscation. Erik Daniel, Marcel Ebert, Florian Tschorsch |
LCN | 3 |
| 2023 | QUICforge: Client-side Request Forgery in QUIC
Konrad Yuri Gbur, Florian Tschorsch |
NDSS | 2 |
| 2023 | Kadcast-NG: A Structured Broadcast Protocol for Blockchain NetworksabstractIn order to propagate transactions and blocks, today’s blockchain systems rely on unstructured peer-to-peer overlay networks. In such networks, broadcast is known to be an inefficient operation in terms of message complexity and overhead. In addition to the impact on the system performance, inefficient or delayed block propagation may have severe consequences regarding security and fairness of the consensus layer. In contrast, the Kadcast protocol is a structured peer-to-peer protocol for block and transaction propagation in blockchain networks. Kadcast utilizes the well-known overlay topology of Kademlia to realize an efficient broadcast operation with tunable overhead. We study the security and privacy of the Kadcast protocol based on probabilistic models and analyze its resilience to packet losses and node failures. Moreover, we evaluate Kadcast’s block delivery performance, broadcast reliability, efficiency, and security based on advanced network simulations. Lastly, we introduce a QUIC-based prototype implementation of the Kadcast protocol and show its merits through deployment in a global-scale cloud-based testbed. Elias Rohrer, Florian Tschorsch |
IEEE/ACM Trans. Netw. | 2 |
| 2022 | Am I Private and If So, how Many?: Communicating Privacy Guarantees of Differential Privacy with Risk Communication FormatsabstractEvery day, we have to decide multiple times, whether and how much personal data we allow to be collected. This decision is not trivial, since there are many legitimate and important purposes for data collection, for examples, the analysis of mobility data to improve urban traffic and transportation. However, often the collected data can reveal sensitive information about individuals. Recently visited locations can, for example, reveal information about political or religious views or even about an individual's health. Privacy-preserving technologies, such as differential privacy (DP), can be employed to protect the privacy of individuals and, furthermore, provide mathematically sound guarantees on the maximum privacy risk. However, they can only support informed privacy decisions, if individuals understand the provided privacy guarantees. This article proposes a novel approach for communicating privacy guarantees to support individuals in their privacy decisions when sharing data. For this, we adopt risk communication formats from the medical domain in conjunction with a model for privacy guarantees of DP to create quantitative privacy risk notifications. Daniel Franzen, Saskia Nuñez von Voigt, Peter Sörries, Florian Tschorsch, Claudia Müller-Birn |
CCS | 4 |
| 2022 | Raising the AWAREness of BFT Protocols for Soaring Network DelaysabstractClassic BFT protocols are often deployed in the LAN setting, with low delays and reliable links. Recent publications of BFT protocols have decreased drastically in their communication complexity and the application to previously unsuited areas such as mobile or sensor networks is getting more traction. To facilitate that development and showcase suitability under harsher network conditions, we take one of the most recent BFT protocols, HotStuff, and analyze the impact of increased and varying network delays on its performance. We apply the delay prediction scheme AWARE and make some simple modifications to the prediction algorithm in order to increase its performance even further. Martin Nischwitz, Marko Esche, Florian Tschorsch |
LCN | 3 |
| 2022 | Optimization-Based Predictive Congestion Control for the Tor Network: Opportunities and ChallengesabstractBased on the principle of onion routing, the Tor network achieves anonymity for its users by relaying user data over a series of intermediate relays. This approach makes congestion control in the network a challenging task. As of this writing, this results in higher latencies due to considerable backlog as well as unfair data rate allocation. In this article, we present a concept study of PredicTor, a novel approach to congestion control that tackles clogged overlay networks. Unlike traditional approaches, it is built upon the idea of distributed model predictive control, a recent advancement from the area of control theory. PredicTor is tailored to minimizing latency in the network and achieving max-min fairness. We contribute a thorough evaluation of its behavior in both toy scenarios to assess the optimizer and complex networks to assess its potential. For this, we conduct large-scale simulation studies and compare PredicTor to existing congestion control mechanisms in Tor. We show that PredicTor is highly effective in reducing latency and realizing fair rate allocations. In addition, we strive to bring the ideas of modern control theory to the networking community, enabling the development of improved, future congestion control. Thus, we demonstrate benefits and issues alike with this novel research direction. Christoph Döpmann, Felix Fiedler, Sergio Lucia, Florian Tschorsch |
ACM Trans. Internet Techn. | 4 |
| 2021 | Strong Anonymity is not Enough: Introducing Fault Tolerance to Planet-Scale Anonymous Communication SystemsabstractCurrent Anonymous Communication Systems (ACS) lack fault tolerance and thus risk becoming unavailable when failures occur, forcing users offline or to less private messengers. In this work, we evaluate end-to-end message transmission latencies and resource demands of state-of-the-art mixnet Vuvuzela and CPIR system Pung under different network failure scenarios on an ACS test bed across four continents. We compare Vuvuzela and Pung to proof-of-concept mixnet FTMix that we equip with simple fault tolerance measures. Our analysis shows that FTMix maintains the smallest divergence of end-to-end latencies under failures from their respective baseline among all three ACS, while also achieving a balanced resource consumption trade-off. Thus, we consider fault tolerance effective in ensuring service availability and a crucial design principle for future ACS proposals. Lennart Oldenburg, Florian Tschorsch |
ARES | 2 |
| 2021 | Self-Determined Reciprocal Recommender Systemwith Strong Privacy GuaranteesabstractRecommender systems are widely used. Usually, recommender systems are based on a centralized client-server architecture. However, this approach implies drawbacks regarding the privacy of users. In this paper, we propose a distributed reciprocal recommender system with strong, self-determined privacy guarantees, i.e., local differential privacy. More precisely, users randomize their profiles locally and exchange them via a peer-to-peer network. Recommendations are then computed and ranked locally by estimating similarities between profiles. We evaluate recommendation accuracy of a job recommender system and demonstrate that our method provides acceptable utility under strong privacy requirements. Saskia Nuñez von Voigt, Erik Daniel, Florian Tschorsch |
ARES | 3 |
| 2021 | Poster: Towards Verifiable Mutability for BlockchainsabstractDue to their immutable log of information, blockchains can be considered as a transparency-enhancing technology. The immutability, however, also introduces threats and challenges with respect to privacy laws and illegal content. Introducing a certain degree of mutability, which enables the possibility to store and remove information, can therefore increase the opportunities for blockchains. In this paper, we present a concept for a mutable blockchain structure. Our approach enables the removal of certain blocks, while maintaining the blockchain's verifiability property. Since our concept is agnostic to any consensus algorithms, it can be implemented with permissioned and permissionless blockchains. Erik Daniel, Florian Tschorsch |
EuroS&P | 2 |
| 2021 | Bernoulli Meets PBFT: Modeling BFT Protocols in the Presence of Dynamic FailuresabstractThe publication of the pivotal state machine replication protocol PBFT laid the foundation for a body of BFT protocols.We introduce a probabilistic model for evaluating BFT protocols in the presence of dynamic link and crash failures.The model is derived from the communication pattern, facilitating an adaptation to other protocols.The state of replicas is captured and used to derive the success probability of the protocol execution.To this end, we examine the influence of link and crash failure rates as well as the number of replicas.A comparison in protocol behavior of PBFT, Zyzzyva and SBFT is performed. Martin Nischwitz, Marko Esche, Florian Tschorsch |
FedCSIS | 3 |
| 2021 | Blockchain Layer Zero: Characterizing the Bitcoin Network through Measurements, Models, and SimulationsabstractIn recent years, research has shown the networking layer’s significant influence on the scalability, security, and privacy of blockchain systems. Such large-scale networks however exhibit a degree of complexity that demands model-based simulations as real-world experiments are often not possible. In this work, we methodically characterize blockchain networks by reference to the paradigmatic Bitcoin peer-to-peer network, explore the state-of-the-art protocols, and emphasize this key design space. To this end, we conducted a longitudinal measurement study on the Bitcoin network, from which we extract a comprehensive network model and implement it as part of the bns network simulation framework. We validate the model in comparison to real-world measurements as well as to results from related work. Moreover, we experimentally show how network utilization and miners’ geographical location impact the block propagation characteristics. Elias Rohrer, Florian Tschorsch |
LCN | 2 |
| 2021 | Onion Pass: Token-Based Denial-of-Service Protection for Tor Onion ServicesabstractThe Tor network is widely recognized as an important tool to preserve online privacy. In addition to anonymous Internet access, it allows hosting anonymous services, i.e., Onion Services. However, connecting to an Onion Service is realized in a way that makes them vulnerable to Denial-of-Service attacks (DoS). In this work, we propose Onion Pass, an extension of the Tor protocol that utilizes anonymous cryptographic tokens to mitigate the issue. Clients can solve a challenge to acquire tokens that later can be presented to the Onion Service. The Onion Service can thus differentiate between valid and malicious requests when under attack. Please note that Onion pass is agnostic on the specific challenge-response scheme and follows a design philosophy that puts Onion Services in control of the Onion Pass protocol. We implemented a prototype of Onion Pass and present experimental results that indicate its potential to prevent DoS attacks on Onion Services by reducing their CPU usage required to identify malicious requests by a factor of 47. Christoph Döpmann, Valentin Franck, Florian Tschorsch |
Networking | 3 |
| 2020 | Counting Down Thunder: Timing Attacks on Privacy in Payment Channel NetworksabstractThe Lightning Network is a scaling solution for Bitcoin that promises to enable rapid and private payment processing. In Lightning, multi-hop payments are secured by utilizing Hashed Time-Locked Contracts (HTLCs) and encrypted on the network layer by an onion routing scheme to avoid information leakage to intermediate nodes. In this work, we however show that the privacy guarantees of the Lightning Network may be subverted by an on-path adversary conducting timing attacks on the HTLC state negotiation messages. To this end, we provide estimators that enable an adversary to reduce the anonymity set and infer the likeliest payment endpoints. We developed a proof-of-concept measurement node that shows the feasibility of attaining time differences and evaluate the adversarial success in model-based network simulations. We find that controlling a small number of malicious nodes is sufficient to observe a large share of all payments, emphasizing the relevance of the on-path adversary model. Moreover, we show that adversaries of different magnitudes could employ timing-based attacks to deanonymize payment endpoints with high precision and recall. Elias Rohrer, Florian Tschorsch |
AFT | 2 |
| 2020 | Quantifying the Re-identification Risk of Event Logs for Process Mining - Empiricial Evaluation Paper
Saskia Nuñez von Voigt, Stephan A. Fahrenkrog-Petersen, Dominik Janssen, Agnes Koschmider, Florian Tschorsch, Felix Mannhardt, Olaf Landsiedel, Matthias Weidlich 0001 |
CAiSE | 5 |
| 2020 | Privacy-Preserving Public Key Infrastructure for Vehicular NetworksabstractCooperative intelligent transport systems promise considerable improvements on road safety and the utilization of transport infrastructures. Current approaches, however, build upon policies to protect privacy, which raise serious concerns. In this paper, we propose a privacy-preserving public key infrastructure (PKI) for vehicle-to-everything communication. We use zero-knowledge proofs to authenticate, while still being able to hide identities. In order to exclude malicious actors, we integrate an anonymous reputation-based blacklisting scheme. Our benchmarks on an on-board connectivity unit with resource-constrained hardware confirms the feasibility of the approach. Specifically, we expect approximately 67 kB payload and 35 minutes computation time per day to authenticate. Pavlo Gaiduk, Kumar Rajeev Ranjan, Thomas Basmer, Florian Tschorsch |
LCN | 4 |
| 2020 | Enabling Reference Verifiability for the World Wide Web with WebchainabstractAs online sources are becoming more prevalent in journalism and scientific literature, the ephemeral nature of the World Wide Web is becoming an increasingly serious issue for their verifiability, replicability, and reproducibility. The architecture of Webchain, a new system enabling source and reference verifiability on the Web, is combining distributed ledger technologies with secure timestamping to ensure the history of creation, ownership, and referential integrity of online resources. We present the architecture and system extensions, conduct a security analysis, and evaluate the Webchain system based on a comprehensive prototype implementation. The results confirm the feasibility and robustness of our approach. Elias Rohrer, Steffen Heidel, Florian Tschorsch |
ACM Trans. Internet Techn. | 3 |
| 2019 | Kadcast: A Structured Approach to Broadcast in Blockchain NetworksabstractIn order to propagate transactions and blocks, today's blockchain systems rely on unstructured peer-to-peer overlay networks. In such networks, broadcast is known to be an inefficient operation in terms of message complexity and overhead. In addition to the impact on the system performance, inefficient or delayed block propagation may have severe consequences regarding security and fairness of the consensus layer. Therefore, we introduce Kadcast, a novel peer-to-peer protocol for block propagation in blockchain networks. Kadcast utilizes the well-known structured overlay topology of Kademlia to realize an efficient broadcast operation with tunable overhead. As our protocol is based on UDP, we incorporate forward error correction (FEC) to increase reliability while still maintaining its lightweight protocol architecture. To this end, we build a probabilistic model to analyze Kadcast's resilience to packet losses and node failures. Moreover, we evaluate Kadcast's block delivery performance, broadcast reliability, efficiency, and security based on advanced network simulations, which confirm the merits of the Kadcast protocol. Elias Rohrer, Florian Tschorsch |
AFT | 2 |
| 2019 | BBBlockchain: Blockchain-Based Participation in Urban DevelopmentabstractUrban development processes often suffer from mistrust amongst different stakeholder groups. The lack of transparency within complex and long-term planning processes and the limited scope for co-creation and joint decision-making constitute a persistent problem for successful participation in urban planning. Civic technology has the potential to improve this predicament. With BBBlockchain, we propose a blockchain-based participation platform, which is able to address all layers of participation. In the development of the platform, we focus on two key aspects: How to increase transparency and how to introduce enhanced co-decision-making. To this end, we exploit the immutable nature of blockchains and effectively offer a platform that excludes monopolistic control over information. The decision-making process is governed by smart contracts implementing, for example, timestamping of planning documents, opinion polls, and the management of a participatory budget. Our architecture and prototypes show the operational capabilities of this approach in a series of use cases for urban development. Robert Muth, Kerstin Eisenhut, Jochen Rabe, Florian Tschorsch |
eScience | 4 |
| 2019 | Map-Z: Exposing the Zcash Network in Times of TransitionabstractZcash is a privacy-preserving cryptocurrency that provides anonymous monetary transactions. While Zcash's anonymity is part of a rigorous scientific discussion, information on the underlying peer-to-peer network are missing. In this paper, we provide the first long-term measurement study of the Zcash network to capture key metrics such as the network size and node distribution as well as deeper insights on the centralization of the network. Furthermore, we present an inference method based on a timing analysis of block arrivals that we use to determine interconnections of nodes. We evaluate and verify our method through simulations and real-world experiments, yielding a precision of 50% with a recall of 82% in the real-world scenario. By adjusting the parameters, the topology inference model is adaptable to the conditions found in other cryptocurrencies and therefore also contributes to the broader discussion of topology hiding in general. Erik Daniel, Elias Rohrer, Florian Tschorsch |
LCN | 3 |
| 2018 | Exploring Deployment Strategies for the Tor NetworkabstractIn response to upcoming performance and security challenges of anonymity networks like Tor, it will be of crucial importance to be able to develop and deploy performance improvements and state-of-the-art countermeasures. In this paper, we therefore explore different deployment strategies and review their applicability, impact, and risks to the Tor network. In a simulation-based evaluation, which leverages historical data of Tor, we show that the deployment strategies can practically be applied to realize significant protocol changes in Tor. Our results, however, also indicate that during the transitional phase a certain degradation of anonymity is unavoidable. Christoph Döpmann, Sebastian Rust, Florian Tschorsch |
LCN | 3 |
| 2016 | ANOTEL: Cellular Networks with Location PrivacyabstractWhile location management is a key component of cellular networks, it is also a major privacy issue: location management empowers the network operator to track users. In today's public and scientific discussion, the centralized storage of location data is mostly taken as a fact, and users are expected to trust the network operator. With ANOTEL we present a novel, clean-slate approach of location management in cellular networks that challenges this assumption. The design is able to route calls to users who move through cellular networks, without violating their location privacy. Tim Dittler, Florian Tschorsch, Stefan Dietzel, Björn Scheuermann 0001 |
LCN | 2 |
| 2016 | Mind the Gap: Towards a Backpressure-Based Transport Protocol for the Tor Network
Florian Tschorsch, Björn Scheuermann 0001 |
NSDI | 1 |
| 2014 | The Sniper Attack: Anonymously Deanonymizing and Disabling the Tor Network
Rob Jansen, Florian Tschorsch, Aaron Johnson 0001, Björn Scheuermann 0001 |
NDSS | 2 |
| 2013 | An algorithm for privacy-preserving distributed user statistics
Florian Tschorsch, Björn Scheuermann 0001 |
Comput. Networks | 1 |
| 2011 | Tor is unfair - And what to do about itabstractTor is one of the most popular network anonymization services. With increasing popularity, however, Tor is also faced with increasing load. Mechanisms for handling congestion and fairness in anonymization networks, where user privacy is of greatest significance, are not yet well understood. Thus current designs leave a lot to be desired: gross unfairness and largely suboptimal performance can be observed. In this paper, we focus on fairness aspects in the Tor network. We first show that interactions of multiple scheduling mechanisms in the current Tor design cause heavily unfair resource allocations to users. Subsequently, we develop a fairness model based on max-min fairness that takes the specifics of Tor into account. This leads us to a re-design of Tor's scheduling. We implement the new design in conjunction with a congestion feedback mechanism named N23, which has recently been proposed to be used in Tor. Our scheduling approach overcomes the unfairness problems which are exhibited by today's Tor implementation, and by Tor with N23 as well. It achieves global max-min fairness and thus a fair resource allocation despite selfish end-users. Florian Tschorsch, Björn Scheuermann 0001 |
LCN | 1 |
| 2010 | Unleashing Tor, BitTorrent & Co.: How to relieve TCP deficiencies in overlaysabstractIn TCP-based overlay applications, the TCP connections of one peer typically share one physical Internet link. Using real-world experiments, we demonstrate that this can lead to undesirable interactions, causing significant throughput loss. We argue that such effects should be taken into account in the design of overlay networks, and identify readily deployable countermeasures. In a first step, we show that with existing operating system QoS functionality some relief is possible. Yet, this alone is not fully effective if peers communicate bidirectionally, due to piggybacked ACKs. We propose to separate bidirectionally used overlay links into two independent TCP connections, and demonstrate the effectiveness of this strategy. Daniel Marks, Florian Tschorsch, Björn Scheuermann 0001 |
LCN | 2 |