VLDB 2026 Research / reviewers in the wild / expert
Michael Waidner
dblp:90/308
· DBLP profile ↗
106ranked-venue papers
2as first author
36since 2021 · last 2026
0000-0001-7919-9961ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 71 · 1 first-author · 28 since 2021Computer networks · 20 · 6 since 2021Systems, architecture and hardware · 14 · 1 first-author · 3 since 2021Theory of computation · 6Software engineering, systems software and programming languages · 3 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | The Fault in Our Drafts: Vulnerabilities in RPKI Specification and Softwareabstract2815 Oliver Jacobsen, Tobias Kirsch, Haya Schulmann, Niklas Vogel, Michael Waidner |
SP | 5 |
| 2026 | All That Glitters is Not Gold: RPKI's Stumbling Speedrun to the TopabstractThe democratization of access has transformed the Internet into the primary platform for social interaction and economic activity. The COVID-19 pandemic significantly accelerated the digitalization of services, finance and communication. As critical infrastructure increasingly moves online, routing security is becoming a national security concern. U.S. regulatory bodies were the first to sound the alarm by formally recognizing the urgency of Internet routing security and calling for nationwide adoption of security protocols. The Resource Public Key Infrastructure (RPKI) protocol is already the leading standard for protecting Internet routing from hijacking attacks and route leaks. However, RPKI is not secure by design. Research on its security guarantees has shown that despite the minimal public facing interfaces, the software implementations are not only rife with issues, but the nature of these issues is such that they can be easily triggered and disconnect the RPKI security framework from Internet routing, thus severely downgrading RPKI protection benefits. In this work, we evaluate the security properties of RPKI, analyze its attack surface, the required attacker capabilities to launch them, and their consequences on global routing security. We propose that RPKI requires fundamental changes and improvements to mitigate its vulnerabilities, and become robust enough to withstand the eye of the storm. Donika Mirdita, Haya Schulmann, Michael Waidner |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | Poster: Exploring the Landscape of RPKI Relying PartiesabstractThe Resource Public Key Infrastructure (RPKI) is the most successful routing defense mechanism currently deployed throughout critical Internet infrastructures around the world. According to recent works, RPKI deployment boasts over 55% global prefix resource coverage, and at least 27% global protocol enforcement; all this success over a short period of time. In this work, we investigate for the first time deployment trends of the Relying Party (RP), the RPKI component responsible for collecting and enforcing RPKI on routers. We map RP locations, deployment parameters, vulnerability distributions, and describe the evolution of deployment trends over two measurement periods three years apart. Through this exploratory analysis, we map global patterns and the preferred deployment configurations by network operators. We observe how within three years, RP traffic increased by 45%, while 89% of traffic stems from one software type. Our measurements show a strong preference by operators to self-host, coupled with inadequate rates of RP vulnerability mitigation. Donika Mirdita, Haya Schulmann, Michael Waidner |
CCS | 3 |
| 2025 | ValidaTor: Domain Validation over Tor
Jens Frieß, Haya Schulmann, Michael Waidner |
NSDI | 3 |
| 2025 | SoK: An Introspective Analysis of RPKI Security
Donika Mirdita, Haya Schulmann, Michael Waidner |
USENIX Security Symposium | 3 |
| 2024 | External Attack-Surface of Modern OrganizationsabstractNavigating the maze of contemporary organizational attack surfaces is paramount in fortifying our defenses against the relentless tide of cyber incidents. However, existing network reconnaissance and security measurements, which enumerate IP addresses or scan popular domains searching for vulnerabilities, capture only a fragmented view of the risk landscape, neglecting the nuanced reality of modern organizational assets. We experimentally show that such scans miss out on most assets of large organizations since they do not consider the increasingly complex IT architectures. Nethanel Gelernter, Haya Schulmann, Michael Waidner |
AsiaCCS | 3 |
| 2024 | Poster: Kill Krill or Proxy RPKIabstractResource Public Key Infrastructure (RPKI), designed to protect Internet routing from hijacks, is gaining traction: over 50% of prefixes have digital certificates, at least 27% of Autonomous Systems actively validate certificates against BGP announcements, and filter invalid routing announcements. In this study, we present the first security analysis of Krill, the only public and open-source RPKI publication point software. Publication points are hosted by the five Regional Internet Registries across the globe, or by independent Internet operators that wish to manage their own RPKI repositories. Louis Cattepoel, Donika Mirdita, Haya Schulmann, Michael Waidner |
CCS | 4 |
| 2024 | Byzantine-Secure Relying Party for Resilient RPKIabstractBGP is a gaping hole in Internet security, as evidenced by numerous hijacks and outages. The significance of BGP for stability and security of the Internet has made it a top priority on the cyber security agenda of the US government, with CISA, FCC, and other federal agencies leading the efforts. Jens Frieß, Donika Mirdita, Haya Schulmann, Michael Waidner |
CCS | 4 |
| 2024 | The Harder You Try, The Harder You Fail: The KeyTrap Denial-of-Service Algorithmic Complexity Attacks on DNSSECabstractAvailability is a major concern in the design of DNSSEC. To ensure availability, DNSSEC follows Postel's Law [RFC1123]: "Be liberal in what you accept, and conservative in what you send." Hence, nameservers should send not just one matching key for a record set, but all the relevant cryptographic material, e.g., all the keys for all the ciphers that they support and all the corresponding signatures. This ensures that validation succeeds, and hence availability, even if some of the DNSSEC keys are misconfigured, incorrect or correspond to unsupported ciphers. Elias Heftrig, Haya Schulmann, Niklas Vogel, Michael Waidner |
CCS | 4 |
| 2024 | Poster: From Fort to Foe: The Threat of RCE in RPKIabstractIn this work, we present a novel severe buffer-overflow vulnerability in the RPKI validator Fort, that allows an attacker to achieve Remote Code Execution (RCE) on the machine running the software. We discuss the unique impact of this RCE on networks that use RPKI, illustrating that RCE vulnerabilities are especially severe in the context of RPKI. The design of RPKI makes RCE easy to exploit on a large scale, allows compromise of RPKI validation integrity, and enables a powerful vector for additional attacks on other critical components of the network, like the border routers. We analyze the vulnerability exposing to this RCE and identify indications that the discovered vulnerability could constitute an intentional backdoor to compromise systems running the software over a benign coding mistake. We disclosed the vulnerability, which has been assigned a CVE rated 9.8 critical (CVE-2024-45237). Oliver Jacobsen, Haya Schulmann, Niklas Vogel, Michael Waidner |
CCS | 4 |
| 2024 | Poster: Security of Login Interfaces in Modern OrganizationsabstractLogin pages, including those for processes like sign-up, registration, and password recovery are interfaces that implement access control to company services or functionalities. Insufficient security on these pages could allow malicious individuals to gain access to services and network of an organization and launch attacks. In this work, we perform a comprehensive study of the security of 73.4k login interfaces of the 100-top European companies from the Fortune report, which we call EU100. We find over 9 million vulnerabilities, which we analyze from a technical perspective, and categorize them according to the hosting model. Our work provides details on the most commonly observed vulnerabilities on login pages across different sectors and according to the hosting strategy adopted by each company. Kevin Nsieyanji Tchokodeu, Haya Schulmann, Gil Sobol, Michael Waidner |
CCS | 4 |
| 2024 | Crowdsourced Distributed Domain ValidationabstractDomain validation is the primary method used by Certificate Authorities for affirming administrative control over a domain for issuing TLS certificates. Prior work has repeatedly shown its vulnerability to hijacking, prompting the use of multiple vantage points for validation. However, the use of static vantage points, as in Let's Encrypt's MultiVA system, is still subject to targeted attacks. Validators should therefore be both distributed and selected in an unpredictable fashion, which is expensive to achieve with dedicated infrastructure. Jens Frieß, Haya Schulmann, Michael Waidner |
HotNets | 3 |
| 2024 | The CURE to Vulnerabilities in RPKI Validation
Donika Mirdita, Haya Schulmann, Niklas Vogel, Michael Waidner |
NDSS | 4 |
| 2024 | Cloudy with a Chance of Cyberattacks: Dangling Resources Abuse on Cloud Platforms
Jens Frieß, Tobias Gattermayer, Nethanel Gelernter, Haya Schulmann, Michael Waidner |
NSDI | 5 |
| 2023 | Poster: Longitudinal Analysis of DoS AttacksabstractDenial-of-Service (DoS) attacks have become a regular occurrence in the digital world of today. Easy-to-use attack software via download and botnet services that can be rented cheaply in the darknet enable adversaries to conduct such attacks without requiring a comprehensive knowledge of the techniques. Fabian Kaiser, Haya Schulmann, Michael Waidner |
CCS | 3 |
| 2023 | Poster: Off-Path DNSSEC Downgrade AttacksabstractRecent works found that signing zones with new cryptographic ciphers may disable DNSSEC validation in DNS resolvers. Adversaries could exploit this to manipulate algorithm numbers of ciphers in DNS responses, to make them appear as unknown, hence maliciously downgrading DNSSEC validation. In this work we show that these manipulation of DNSSEC records can also be launched remotely by off-path adversaries. We develop a DNSSEC downgrade attack using IP fragmentation. The idea is to create large DNS responses, that exceed the Maximum Transmission Unit on that path. The off-path adversary injects a malicious IP fragment, which when reassembled with the genuine IP fragment, overwrites the algorithm number of the ciphers in DNSSEC records. Elias Heftrig, Haya Schulmann, Michael Waidner |
SIGCOMM | 3 |
| 2023 | Beyond Limits: How to Disable Validators in Secure NetworksabstractRelying party validator is a critical component of RPKI: it fetches and validates signed authorizations mapping prefixes to their owners. Routers use this information to block bogus BGP routes. Tomas Hlavacek, Philipp Jeitner, Donika Mirdita, Haya Schulmann, Michael Waidner |
SIGCOMM | 5 |
| 2023 | Downgrading DNSSEC: How to Exploit Crypto Agility for Hijacking Signed Zones
Elias Heftrig, Haya Schulmann, Michael Waidner |
USENIX Security Symposium | 3 |
| 2023 | Keep Your Friends Close, but Your Routeservers Closer: Insights into RPKI Validation in the Internet
Tomas Hlavacek, Haya Schulmann, Niklas Vogel, Michael Waidner |
USENIX Security Symposium | 4 |
| 2022 | Poster: The Unintended Consequences of Algorithm Agility in DNSSECabstractCryptographic algorithm agility is an important property for DNSSEC: it allows easy deployment of new algorithms if the existing ones are no longer secure. In this work we show that the cryptographic agility in DNSSEC, although critical for provisioning DNS with strong cryptography, also introduces a vulnerability. We find that under certain conditions, when new algorithms are listed in signed DNS responses, the resolvers do not validate DNSSEC. As a result, domains that deploy new ciphers may in fact cause the resolvers not to validate DNSSEC. We exploit this to develop DNSSEC-downgrade attacks and experimentally and ethically evaluate them against popular DNS resolver implementations, public DNS providers, and DNS services used by web clients worldwide. We find that major DNS providers as well as 45% of DNS resolvers used by web clients are vulnerable to our attacks. Elias Heftrig, Haya Schulmann, Michael Waidner |
CCS | 3 |
| 2022 | Behind the Scenes of RPKIabstractBest practices for making RPKI resilient to failures and attacks recommend using multiple URLs and certificates for publication points as well as multiple relying parties. We find that these recommendations are already supported by 63% of the ASes with RPKI. Tomas Hlavacek, Philipp Jeitner, Donika Mirdita, Haya Schulmann, Michael Waidner |
CCS | 5 |
| 2022 | Poster: RPKI Kill SwitchabstractRelying party implementations are an important component of RPKI: they fetch and validate the signed authorizations mapping prefixes to their owners. Border routers use this information to check which Autonomous Systems (ASes) are authorized to originate given prefixes and to enforce Route Origin Validation (ROV) in order to block bogus BGP announcements, preventing accidental and malicious prefix hijacks. In 2021 the RPKI relying party implementations were patched against attacks by malicious publication points. In such attacks the relying parties are stalled processing malformed RPKI objects. In this work we perform a black-box analysis of the patched relying party implementations and find that out of five popular relying parties, two major implementations (Routinator and OctoRPKI) have vulnerabilities that can be exploited to cause large scale blackouts in the RPKI ecosystem. We show that the vulnerabilities we found apply to 84.9% of the networks supporting RPKI. We analyze the code to understand the factors causing the bugs. We show that these vulnerabilities can be exploited to crash the deployed relying parties, disabling RPKI validation and exposing the networks to prefix hijack attacks. Donika Mirdita, Haya Schulmann, Michael Waidner |
CCS | 3 |
| 2022 | Poster: Insights into Global Deployment of RPKI ValidationabstractIP prefix hijacks, due to malicious attacks or benign misconfigurations, pose a threat to the Internet's stability and security. RPKI was designed to enable networks to block prefix hijacks by enforcing Route Origin Validation (ROV). In this work we evaluate the effectiveness of the global ROV deployment in blocking prefix hijacks. We perform control-plane and data-plane experiments and provide an in-depth analysis of the collected results. Our analysis is based on new methodologies we developed that allow more accurate identification of ROV enforcing ASes. Our analysis shows that the current ROV enforcement rate is significantly higher than found in previous studies: in contrast to 0.6% in a study from 2021, in our work we find that 37.8% enforce ROV. Our results indicate that ROV has finally gained traction and offers substantial protection against prefix hijacks. Haya Schulmann, Niklas Vogel, Michael Waidner |
CCS | 3 |
| 2022 | Poster: DNS in Routers Considered HarmfulabstractTo save costs residential routers often do not implement most of the functionalities and security features of DNS, yet they still contain DNS forwarders which merely proxy the clients' requests to another address. These forwarders separate the network configuration of the internal client network from the network of the ISP. This provides connectivity without the need for synchronization. History of cache poisoning attacks shows however that such simplified implementations expose a wide range of vulnerabilities. We propose to remove DNS from routers. We show that the performance impact is negligible, while security gain is substantial. We discuss a number of ways for implementing our approach Haya Schulmann, Michael Waidner |
CCS | 2 |
| 2022 | Smart RPKI Validation: Avoiding Errors and Preventing Hijacks
Tomas Hlavacek, Haya Schulmann, Michael Waidner |
ESORICS (1) | 3 |
| 2022 | Stalloris: RPKI Downgrade Attack
Tomas Hlavacek, Philipp Jeitner, Donika Mirdita, Haya Schulmann, Michael Waidner |
USENIX Security Symposium | 5 |
| 2022 | XDRI Attacks - and - How to Enhance Resilience of Residential Routers
Philipp Jeitner, Haya Schulmann, Lucas Teichmann, Michael Waidner |
USENIX Security Symposium | 4 |
| 2022 | Special issue ESORICS 2021abstractFollowing the tradition of the European Symposium European Symposium on Research in Computer Security (ESORICS), this special issue includes selected papers from the 2021 edition of ESORICS.This edition was held (virtually) in Darmstadt (Germany) on October 4-8, 2021.ESORICS 2021 introduced for the first time in the ESORICS series two review cycles: a winter cycle and a spring cycle.Multiple submission cycles are today common in top conferences; they are not only more convenient for the authors but also allow revision and resubmission of papers.In response to the call for papers, 351 papers were submitted to ESORICS 2021.The papers were peer reviewed and discussed based on their novelty, quality, and contribution by the members of the Program Committee.Based on the reviews and discussions 71 high quality papers were selected for presentation at the conference.As a result, ESORICS had an interesting program covering timely and interesting security and privacy topics in theory, systems, networks, and applications.Because of the high quality of the papers accepted for presentation at ESORICS 2021, selecting the papers to invite for the special issue was challenging.To select the papers, we analyzed the top ranked papers and also asked for inputs by the PC members, and finally identified and invited six papers.Out of those six papers, one was not submitted owning to some resource issues by the authors.The remaining five papers went through the customary review cycles and were all accepted.These papers cover a broad set of topics, ranging from zero-knowledge proof protocols and privacy-preserving neural network inferences to privacy-preserving searching techniques, malware sandbox evasion and password strength estimation.Overall the selected papers address timely and crucial topics and provide novel solutions.We now briefly describe the main contributions of these papers. Elisa Bertino, Haya Schulmann, Michael Waidner |
J. Comput. Secur. | 3 |
| 2021 | Evaluating Resilience of Domains in PKIabstractDomain Validation of PKI, allows to verify ownership over domains and poses the basis for cryptography. A number of recent attacks led to efforts to enhance the security of domain validation by improving the resilience of the vantage points used by the certificate authorities. Markus Brandt, Haya Schulmann, Michael Waidner |
CCS | 3 |
| 2021 | Let's Downgrade Let's EncryptabstractFollowing the recent off-path attacks against PKI, Let's Encrypt deployed in 2020 domain validation from multiple vantage points to ensure security even against the stronger on-path MitM adversaries. The idea behind such distributed domain validation is that even if the adversary can hijack traffic of some vantage points, it will not be able to intercept traffic of all the vantage points to all the nameservers in a domain. Tianxiang Dai, Haya Schulmann, Michael Waidner |
CCS | 3 |
| 2021 | Predictive Cipher-Suite Negotiation for Boosting Deployment of New CiphersabstractDeployment of strong cryptographic ciphers for DNSSEC is essential for long term security of DNS. Unfortunately, due to the hurdles involved in adoption of new ciphers coupled with the limping deployment of DNSSEC, most domains use the weak RSA-1024 cipher. Elias Heftrig, Jean-Pierre Seifert, Haya Schulmann, Michael Waidner, Nils Wisiol |
CCS | 4 |
| 2021 | The Master and Parasite AttackabstractWe explore a new type of malicious script attacks: the persistent parasite attack. Persistent parasites are stealthy scripts, which persist for a long time in the browser's cache. We show to infect the caches of victims with parasite scripts via TCP injection. Once the cache is infected, we implement methodologies for propagation of the parasites to other popular domains on the victim client as well as to other caches on the network. We show how to design the parasites so that they stay long time in the victim's cache not restricted to the duration of the user's visit to the web site. We develop covert channels for communication between the attacker and the parasites, which allows the attacker to control which scripts are executed and when, and to exfiltrate private information to the attacker, such as cookies and passwords. We then demonstrate how to leverage the parasites to perform sophisticated attacks, and evaluate the attacks against a range of applications and security mechanisms on popular browsers. Finally we provide recommendations for countermeasures. Lukas Baumann, Elias Heftrig, Haya Schulmann, Michael Waidner |
DSN | 4 |
| 2021 | Poster: Off-path VoIP Interception AttacksabstractThe proliferation of Voice-over-IP (VoIP) technologies make them a lucrative target of attacks. While many attack vectors have been uncovered, one critical vector has not yet received attention: hijacking telephony via DNS cache poisoning. We demonstrate practical VoIP hijack attacks by manipulating DNS responses with a weak off-path attacker. We evaluate our attacks against popular telephony VoIP systems in the Internet and provide a live demo of the attack against Extensible Messaging and Presence Protocol at https://sit4.me/M4. Tianxiang Dai, Haya Schulmann, Michael Waidner |
ICDCS | 3 |
| 2021 | Poster: Fragmentation Attacks on DNS over TCPabstractThe research and operational community believe that TCP provides protection against IP fragmentation based attacks and recommend that servers avoid sending responses over UDP and use TCP instead. In this work we show for the first time that IP fragmentation attacks may also apply to communication over TCP. We perform a study of the nameservers in the 100K-top Alexa domains and find that 454 domains are vulnerable to IP fragmentation attacks. Of these domains, we find 366 additional domains that are vulnerable only to IP fragmentation attacks on communication with TCP. We also find that the servers vulnerable to TCP fragmentation can be forced to fragment packets to much smaller sizes (of less than 292 bytes) than servers vulnerable to UDP fragmentation (not below 548 bytes). This makes the impact of the attacks against servers vulnerable to fragmentation of TCP segments much more detrimental. Our study not only shows that the recommendation to use TCP and avoid UDP is risky but it also shows that the attack surface due to fragmentation is larger than was previously believed. We evaluate known IP fragmentation-based DNS cache poisoning attacks against DNS responses over TCP. Tianxiang Dai, Haya Schulmann, Michael Waidner |
ICDCS | 3 |
| 2021 | From IP to transport and beyond: cross-layer attacks against applicationsabstractWe perform the first analysis of methodologies for launching DNS cache poisoning: manipulation at the IP layer, hijack of the inter-domain routing and probing open ports via side channels. We evaluate these methodologies against DNS resolvers in the Internet and compare them with respect to effectiveness, applicability and stealth. Our study shows that DNS cache poisoning is a practical and pervasive threat. Tianxiang Dai, Philipp Jeitner, Haya Schulmann, Michael Waidner |
SIGCOMM | 4 |
| 2021 | The Hijackers Guide To The Galaxy: Off-Path Taking Over Internet Resources
Tianxiang Dai, Philipp Jeitner, Haya Schulmann, Michael Waidner |
USENIX Security Symposium | 4 |
| 2020 | Black-box caches fingerprintingabstractWe propose the first methodologies for remotely inferring and fingerprinting the software of DNS caches in the Internet based solely on the exchange of queries/responses with the DNS platform. Our techniques are robust and cannot be altered in transit, e.g., by firewalls, which does not hold for the existing fingerprinting techniques. In particular, the only way to alter the outcome of our fingerprinting methods is by modifying the DNS software itself. Amit Klein 0001, Elias Heftrig, Haya Schulmann, Michael Waidner |
CoNEXT | 4 |
| 2020 | Performance penalties of resilient SDN infrastructuresabstractSecure software and hardware are critical to the functionality and stability of the Internet as well as to its clients and services. Unfortunately, benign vulnerabilities and maliciously infiltrated backdoors can often not be identified in advance, which eliminates the possibility to mitigate them. When security assurances are not known, robust combiners can be applied to ensure resilience of networks and systems. In this work we present resilient constructions based on robust combiners for network devices in Software Defined Networking, and perform extensive evaluations to show the impact of robust combiners on the efficiency of network devices. Our results demonstrate that combining devices and software provides a reasonable performance for practical systems and is a promising approach for ensuring resilience when using potentially faulty or malicious components. Daniel Senf, Haya Schulmann, Michael Waidner |
CoNEXT | 3 |
| 2020 | The Impact of DNS Insecurity on TimeabstractWe demonstrate the first practical off-path time shifting attacks against NTP as well as against Man-in-the-Middle (MitM) secure Chronos-enhanced NTP. Our attacks exploit the insecurity of DNS allowing us to redirect the NTP clients to attacker controlled servers. We perform large scale measurements of the attack surface in NTP clients and demonstrate the threats to NTP due to vulnerable DNS. Philipp Jeitner, Haya Schulmann, Michael Waidner |
DSN | 3 |
| 2020 | Diving into Email Bomb AttackabstractWe explore Email Bomb - a particularly devastating type of Denial of Service (DOS) attack that recently gained traction. During the attack Email account of a victim is targeted with a flood of Emails. Existing anti-spam defences fail at filtering this Emails' flood, since the Emails are not sent from spoofed addresses, but originate from legitimate web services on the Internet which are exploited as reflectors. We perform a two-year study of the Email bomb attack and the affected actors - the victims and the reflectors. We show that although the attack is rented for one day, the Email flood proceeds over longer time periods often lasting months after the initial attack. We identify the properties that allow the attackers to recruit web sites as potential reflectors and demonstrate how the attackers harvest web reflectors. We show that even popular Alexa web sites, such as booking.com, are exploited to launch Email bomb attacks. The main problem is that such attacks are extremely simple to launch and can be rented for 5USD on darknet. We setup a tool which periodically collects and analyses the Emails received during the attack, the analysis as well as the data is presented online at http://emailbombresearch.xyz. We argue that email bomb attacks do not only pose inconvenience and hinder the ability of victims to function, but also we provide the first demonstration how such attacks can be leveraged for hiding other devastating attacks which take place in parallel. We show that existing countermeasures fall short of preventing email bomb attacks and provide effective mitigation recommendations that are based on our study of this attack. Markus Schneider 0002, Haya Schulmann, Adi Sidis, Ravid Sidis, Michael Waidner |
DSN | 5 |
| 2020 | Cryptanalysis of FNV-Based CookiesabstractDNS cookies is a recently standardised proposal of the IETF meant to protect DNS against off-path cache poisoning attacks. In contrast to other defences for DNS, DNS cookies is a lightweight mechanism, is easy to deploy and does not introduce overhead on the DNS servers. In this work we demonstrate off-path attacks allowing to circumvent the DNS cookies mechanism and impersonate legitimate Internet sources, exposing the DNS servers to cache poisoning and amplification reflection DoS attacks. We implement and evaluate the attacks, and provide recommendations for countermeasures. Amit Klein 0001, Haya Schulmann, Michael Waidner |
GLOBECOM | 3 |
| 2020 | Blocking Email Bombs with EmailGlassabstractWe develop a defence against email bomb attacks, we call EmailGlass. Email bomb is a targeted Denial of Service (DOS) attack during which the email account of a victim is flooded with multiple emails. The emails are sent by legitimate web services which the attackers abuse as reflectors, to reflect unwanted email traffic at victim email accounts.The lack of defences coupled with low costs of the attack and the devastating outcome, make email bomb attack particularly popular. The email bomb attacks do not only pose inconvenience and hinder the ability of victims to function, but can also be used to hide other attacks which take place concurrently.The design of EmailGlass is based on a two year study of the email bomb attack and the relevant actors - the victims and the reflectors. During the study we setup victim email accounts, and rented email bomb attacks on darknet. We analysed the attack traffic that was received on our victim accounts to derive conclusions for development of an effective defence mechanism. Markus Schneider 0002, Haya Schulmann, Michael Waidner |
GLOBECOM | 3 |
| 2018 | Domain Validation++ For MitM-Resilient PKIabstractThe security of Internet-based applications fundamentally relies on the trustworthiness of Certificate Authorities (CAs). We practically demonstrate for the first time that even a weak off-path attacker can effectively subvert the trustworthiness of popular commercially used CAs. Our attack targets CAs which use Domain Validation (DV) for authenticating domain ownership; collectively these CAs control 99% of the certificates market. The attack utilises DNS Cache poisoning and tricks the CA into issuing fraudulent certificates for domains the attacker does not legitimately own -- namely certificates binding the attacker's public key to a victim domain. We discuss short and long term defences, but argue that they fall short of securing DV. To mitigate the threats we propose Domain Validation++ (DV++). DV++ replaces the need in cryptography through assumptions in distributed systems. While retaining the benefits of DV (automation, efficiency and low costs) DV++ is secure even against Man-in-the-Middle (MitM) attackers. Deployment of DV++ is simple and does not require changing the existing infrastructure nor systems of the CAs. We demonstrate security of DV++ under realistic assumptions and provide open source access to DV++ implementation. Markus Brandt, Tianxiang Dai, Amit Klein 0001, Haya Schulmann, Michael Waidner |
CCS | 5 |
| 2018 | Off-Path Attacks Against PKIabstractThe security of Internet-based applications fundamentally relies on the trustworthiness of Certificate Authorities (CAs). We practically demonstrate for the first time that even a very weak attacker, namely, an off-path attacker, can effectively subvert the trustworthiness of popular commercially used CAs. We demonstrate an attack against one popular CA which uses Domain Validation (DV) for authenticating domain ownership. The attack exploits DNS Cache Poisoning and tricks the CA into issuing fraudulent certificates for domains the attacker does not legitimately own -- namely certificates binding the attacker's public key to a victim domain. Tianxiang Dai, Haya Schulmann, Michael Waidner |
CCS | 3 |
| 2018 | Removing the Bottleneck for Practical 2PCabstractSecure Two Party Computation (2PC) has the potential to facilitate a wide range of real life applications where privacy of the computation and participants is critical. Nevertheless, this potential has not translated to widespread industry acceptance due to performance issues. Over the years a significant research effort has focused on optimising the performance of 2PC. The computation complexity has been continually improved and recently, following circuit optimisations and hardware support for cryptographic operations, evaluations of 2PC on a single host currently produce efficient results. Unfortunately, when evaluated on remote hosts, the performance remains prohibitive for practical purposes. The bottleneck is believed to be the bandwidth. In this work we explore the networking layer of 2PC implementations and show that the performance bottleneck is inherent in the usage of TCP sockets in implementations of 2PC schemes. Through experimental evaluations, we demonstrate that other transport protocols can significantly improve the performance of 2PC, making it suitable for practical applications. Kris Shrishak, Haya Schulmann, Michael Waidner |
CCS | 3 |
| 2018 | Practical Experience: Methodologies for Measuring Route Origin ValidationabstractPerforming Route Origin Validation (ROV) to filter BGP announcements, which contradict Route Origin Authorizations (ROAs) is critical for protection against BGP prefix hijacks. Recent works quantified ROV enforcing Autonomous Systems (ASes) using control-plane experiments. In this work we show that control-plane experiments do not provide accurate information about ROV-enforcing ASes. We devise data-plane approaches for evaluating ROV in the Internet and perform both control and data-plane experiments using different data acquisition sources. We analyze and correlate the results of our study to identify the number of ASes enforcing ROV, and hence protected with RPKI. We perform simulations with the ROV-enforcing ASes that we identified, and find that their impact on the Internet security against prefix hijacks is negligible. As a countermeasure we provide recommendations how to cope with the main factor hindering wide adoption of ROV. Tomas Hlavacek, Amir Herzberg, Haya Schulmann, Michael Waidner |
DSN | 4 |
| 2018 | Internet As a Source of RandomnessabstractPseudorandom Generators (PRGs) play an important role in security of systems and cryptographic mechanisms. Yet, there is a long history of vulnerabilities in practical PRGs. Markus Brandt, Haya Schulmann, Michael Waidner |
HotNets | 3 |
| 2018 | Path MTU Discovery Considered HarmfulabstractPath MTU Discovery (PMTUD) allows to optimize the performance in the Internet by identifying the maximal packet size that can be transmitted through a network. Despite the central role that PMTUD plays in the Internet communication, it has a long history of software bugs, failures and misconfigurations. In this work we explore the benefits versus drawbacks of PMTUD in the Internet from the clients and servers perspective. First, we examine the fraction of clients that use PMTUD. To that end we analyse ICMP PTB messages in CAIDA Internet Traces and show that the fraction of networks using PMTUD is negligible and that this number is further decreasing over the period of 2008 - 2016. Second, we evaluate the fraction of popular web servers that support the PMTUD mechanism and show that a large number of the servers block "ICMP packet too big" messages. On the other hand, we show easy and efficient - even though well-known - degradation of service attacks that exploit the availability of PMTUD. Since the benefit of PMTUD is questionable, and in contrast it exposes to degradation of service attacks, we advocate to stop using it. As with any new change in the Internet, the implications of our recommendation should be carefully evaluated and gradually implemented. In the meanwhile, we provide recommendations for mitigations against the degradation of service attacks. Matthias Gohring, Haya Schulmann, Michael Waidner |
ICDCS | 3 |
| 2017 | POSTER: X-Ray Your DNSabstractWe design and develop DNS X-Ray which performs analyses of DNS platforms on the networks where it is invoked. The analysis identifies the caches and the IP addresses used by the DNS platform, fingerprints the DNS software on the caches, and evaluates vulnerabilities allowing injection of spoofed records into the caches. DNS X-Ray is the first tool to perform an extensive analysis of the caching component on the DNS platforms. In addition, DNS X-Ray also provides statistics from previous invocations, enabling networks to check which for popular DNS software on the caches, the number of caches typically used on DNS platforms and more. We set up DNS X-Ray online, it can be accessed via a website http://www.dns.xray.sit.fraunhofer.de. Amit Klein 0001, Vladimir Kravtsov, Alon Perlmuter, Haya Schulmann, Michael Waidner |
CCS | 5 |
| 2017 | Counting in the Dark: DNS Caches Discovery and Enumeration in the InternetabstractDomain Name System (DNS) is a fundamental element of the Internet providing lookup services for end users as well as for a multitude of applications, systems and security mechanisms that depend on DNS, such as antispam defences, routing security, firewalls, certificates and more. Caches constitute a critical component of DNS, allowing to improve efficiency and reduce latency and traffic in the Internet. Understanding the behaviour, configurations and topologies of caches in the DNS platforms in the Internet is important for efficiency and security of Internet users and services. In this work we present methodologies for efficiently discovering and enumerating the caches of the DNS resolution platforms in the Internet. We apply our techniques and methodologies for studying caches in popular DNS resolution platforms in the Internet. Our study includes networks of major ISPs, enterprises and professionally managed open DNS resolvers. The results of our Internet measurements shed light on architectures and configurations of the caches in DNS resolution platforms. Amit Klein 0001, Haya Schulmann, Michael Waidner |
DSN | 3 |
| 2017 | Internet-wide study of DNS cache injectionsabstractDNS caches are an extremely important tool, providing services for DNS as well as for a multitude of applications, systems and security mechanisms, such as anti-spam defences, routing security (e.g., RPKI), firewalls. Subverting the security of DNS is detrimental to the stability and security of the clients and services, and can facilitate attacks, circumventing even cryptographic mechanisms. We study the caching component of DNS resolution platforms in diverse networks in the Internet, and evaluate injection vulnerabilities allowing cache poisoning attacks. Our evaluation includes networks of leading Internet Service Providers and enterprises, and professionally managed open DNS resolvers. We test injection vulnerabilities against known payloads as well as a new class of indirect attacks that we define in this work. Our Internet evaluation indicates that more than 92% of the Internet's DNS resolution platforms are vulnerable to records injection and can be persistently poisoned. Amit Klein 0001, Haya Schulmann, Michael Waidner |
INFOCOM | 3 |
| 2017 | One Key to Sign Them All Considered Vulnerable: Evaluation of DNSSEC in the Internet
Haya Schulmann, Michael Waidner |
NSDI | 2 |
| 2016 | DNSSEC Misconfigurations in Popular Domains
Tianxiang Dai, Haya Schulmann, Michael Waidner |
CANS | 3 |
| 2016 | Security in industrie 4.0 - challenges and solutions for the fourth industrial revolution
Michael Waidner, Michael Kasper |
DATE | 1 |
| 2015 | Security and privacy challenges in industrial internet of thingsabstractToday, embedded, mobile, and cyberphysical systems are ubiquitous and used in many applications, from industrial control systems, modern vehicles, to critical infrastructure. Current trends and initiatives, such as "Industrie 4.0" and Internet of Things (IoT), promise innovative business models and novel user experiences through strong connectivity and effective use of next generation of embedded devices. These systems generate, process, and exchange vast amounts of security-critical and privacy-sensitive data, which makes them attractive targets of attacks. Cyberattacks on IoT systems are very critical since they may cause physical damage and even threaten human lives. The complexity of these systems and the potential impact of cyberattacks bring upon new threats. Ahmad-Reza Sadeghi, Christian Wachsmann, Michael Waidner |
DAC | 3 |
| 2015 | Towards Security of Internet Naming InfrastructureabstractWe study the operational characteristics of the server-side of the Internet’s naming infrastructure. Our findings discover common architectures whereby name servers are ‘hidden’ behind server-side caching DNS resolvers. We explore the extent and the scope of the name servers that use server-side caching resolvers, and find such configurations in at least $$38\,\%$$ of the domains in a forward DNS tree, and higher percents of the domains in a reverse DNS tree. We characterise the operators of the server-side caching resolvers and provide motivations, explaining their prevalence. Our experimental evaluation indicates that the caching infrastructures are typically run by third parties, and that the services, provided by the third parties, often do not deploy best practices, resulting in misconfigurations, vulnerabilities and degraded performance of the DNS servers in popular domains. Haya Schulmann, Michael Waidner |
ESORICS (1) | 2 |
| 2015 | Detection and Forensics of Domains HijackingabstractThe naming service provided by Domain Name System (DNS) is essential for locating resources on the Internet, for distributing security mechanisms in an authenticated manner, and for facilitating future applications. Unfortunately, despite the critical function that the naming service of the DNS infrastructure fulfills, it is extremely vulnerable to domain hijacking attacks. While most of the attacks go undetected, they are detrimental for the availability of the Internet services, and the security and privacy of clients and networks. We designed and developed a system, we call LUDIC (LookUp DIstributed Cache), for detection of domain hijacking attacks. Our system also enables forensic analysis and provides victims with signed evidences allowing them to prove breaches to third parties, such as a court of law or a resolution authority. LUDIC uses distributed vantage points to validate DNS records, and does not require establishing a chain of trust to a centralised trust anchor, hence sidestepping the adoption challenges inherent in DNSSEC. Our system does not introduce any changes to the existing infrastructure and can be easily integrated into an Intrusion Detection System (IDS) or a firewall, while providing an immediate benefit to adopters. Andreas Borgwart, Spyros Boukoros, Haya Schulmann, Carel van Rooyen, Michael Waidner |
GLOBECOM | 5 |
| 2014 | Fragmentation Considered Leaking: Port Inference for DNS Poisoning
Haya Schulmann, Michael Waidner |
ACNS | 2 |
| 2014 | DNSSEC for cyber forensicsabstractDomain Name System (DNS) cache poisoning is a stepping stone towards advanced (cyber) attacks. DNS cache poisoning can be used to monitor users’ activities for censorship, to distribute malware and spam and to subvert correctness and availability of Internet clients and services. Currently, the DNS infrastructure relies on challenge-response defences against attacks by (the common) off-path adversaries. Such defences do not suffice against stronger, man-in-the-middle (MitM), adversaries. However, MitM is not believed to be common; hence, there seems to be little motivation to adopt systematic, cryptographic mechanisms. We show that challenge-response do not protect against cache poisoning. In particular, we review common situations where (1) attackers can frequently obtain MitM capabilities and (2) even weaker attackers can subvert DNS security. We also experimentally study dependencies in the DNS infrastructure, in particular, dependencies within domain registrars and within domains, and show that multiple dependencies result in more vulnerable DNS. We review domain name system security extensions (DNSSEC), the defence against DNS cache poisoning, and argue that not only it is the most suitable mechanism for preventing cache poisoning but it is also the only proposed defence that enables a posteriori forensic analysis of attacks. Haya Schulmann, Michael Waidner |
EURASIP J. Inf. Secur. | 2 |
| 2007 | Simplified Privacy Controls for Aggregated Services - Suspend and Resume of Personal Data
Matthias Schunter, Michael Waidner |
Privacy Enhancing Technologies | 2 |
| 2007 | The reactive simulatability (RSIM) framework for asynchronous systems
Michael Backes 0001, Birgit Pfitzmann, Michael Waidner |
Inf. Comput. | 3 |
| 2007 | PrefaceabstractThis special issue collects extended versions of selected papers presented at the second ACM Workshop on Formal Methods in Security Engineering (FMSE) 2004, held in Washington DC, October 29th, in conjunction with the 11th ACM Conference on Computer and Communications Security.The purpose of FMSE is to bring together researchers and practitioners from both the security and the software engineering communities, from academia and industry, who are working on applying formal methods to designing and validating large-scale security-critical systems.The scope of the workshop covers security and formalmethods related aspects of: security specification techniques, formal trust models, combination of formal techniques with semi-formal techniques like UML, formal analyses of specific security properties relevant to software development, securitypreserving composition and refinement of processes, faithful abstractions of cryptographic primitives and protocols in process abstractions, integration of formal security specifications, as well as refinement and validation techniques in development methods and tools. Michael Backes 0001, David A. Basin, Michael Waidner |
J. Comput. Secur. | 3 |
| 2006 | Cryptographically Sound Theorem ProvingabstractWe describe a faithful embedding of the Dolev-Yao model of Backes, Pfitzmann, and Waidner (CCS 2003) in the theorem prover Isabelle/HOL. This model is cryptographically sound in the strong sense of blackbox reactive simulatability/UC, which essentially entails the preservation of arbitrary security properties under active attacks and in arbitrary protocol environments. The main challenge in designing a practical formalization of this model is to cope with the complexity of providing such strong soundness guarantees. We reduce this complexity by abstracting the model into a sound, light-weight formalization that enables both concise property specifications and efficient application of our proof strategies and their supporting proof tools. This yields the first tool-supported framework for symbolically verifying security protocols that enjoys the strong cryptographic soundness guarantees provided by reactive simulatability/UC As a proof of concept, we have proved the security of the Needham-Schroeder-Lowe protocol using our framework Christoph Sprenger 0001, Michael Backes 0001, David A. Basin, Birgit Pfitzmann, Michael Waidner |
CSFW | 5 |
| 2006 | Limits of the BRSIM/UC Soundness of Dolev-Yao Models with Hashes
Michael Backes 0001, Birgit Pfitzmann, Michael Waidner |
ESORICS | 3 |
| 2006 | Formal Methods and Cryptography
Michael Backes 0001, Birgit Pfitzmann, Michael Waidner |
FM | 3 |
| 2005 | Guest Editor's Introduction: 2005 IEEE Symposium on Security and PrivacyabstractSINCE 1980, the IEEE Symposium on Security and Privacy has been the premier annual forum for the presentation of scientific developments in information security and privacy technology, and for bringing together researchers and practitioners in the field. It is sponsored by the IEEE Computer Society Technical Committee on Security and Privacy, in co-operation with The International Association for Cryptologic Research (IACR). The program committee of the 2005 conference received 192 submissions, and selected 17 papers to be presented, on the basis of excellence of scientific contribution. Out of these 17 high quality papers, the program committee selected three as the most highly rated papers for this special issue. In no particular order, they are: “Hardware-Assisted Circumvention of Self-Hashing Software Tamper Resistance” by P.C. van Oorschot, Anil Somayaji, and Glenn Wurster; “Remote Physical Device Fingerprinting” by Tadayoshi Kohno, Andre Broido, and K.C. Claffy; “Relating Symbolic and Cryptographic Secrecy” by Michael Backes and Birgit Pfitzmann. Like all scientific conferences, the IEEE Symposium on Security and Privacy lives from the voluntary and hard work of many people. We wish to thank all of them-authors, reviewers, participants and organizers-but in particular the members of the program committee: William Arbaugh, Michael Backes, Josh Benaloh, Marc Dacier, Herve Debar, George Dinolt, Riccardo Focardi, Virgil Gligor, Peter Gutmann, Dogan Kesdogan, Helmut Kurth, Wenke Lee, Roy Maxion, John McHugh, Catherine Meadows, Radia Perlman, Birgit Pfitzmann, Joachim Posegga, Niels Provos, Josyula R. Rao, Michael Reiter Eric Rescorla, Rei SafaviNaini, Pierangela Samarati, Andrei Serjantov, Giovanni Vigna, Dan S. Wallach, Andreas Wespi, and Marianne Winslett. We also thank the anonymous journal reviewers of the three papers published in this special issue for their work. Vern Paxson received the MS and PhD degrees from the University of California, Berkeley, and has been (and continues to be) a staff scientist with the Lawrence Berkeley National Laboratory’s Network Research Group for many years. He began at the ICIR group of the International Computer Science Institute (ICSI) in 1999. His main active research projects are Bro, worms (including the network telescope project), DETER, and PREDICT. He has been the vice chair of ACM SIGCOMM; program cochair for IEEE Security and Privacy 2005 (Program); and program committee member for SRUTI 2005, RAID 2005, ACSAC 2005, and USENIX/ACM NSDI ’05. He was on the editorial board of IEEE/ACM Transactions on Networking from 2000-2004. Vern Paxson, Michael Waidner |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2004 | Low-Level Ideal Signatures and General Integrity Idealization
Michael Backes 0001, Birgit Pfitzmann, Michael Waidner |
ISC | 3 |
| 2004 | A General Composition Theorem for Secure Reactive Systems
Michael Backes 0001, Birgit Pfitzmann, Michael Waidner |
TCC | 3 |
| 2004 | Privacy-enhancing identity management
Marit Hansen, Peter Berlich, Jan Camenisch, Sebastian Clauß 0001, Andreas Pfitzmann, Michael Waidner |
Inf. Secur. Tech. Rep. | 6 |
| 2004 | Polynomial livenessabstractImportant properties of many protocols are liveness or availability, i.e., that something good happens now and then. In asynchronous scenarios, these properties depend on the scheduler, which is usually considered to be fair in this case. The standard definitions of fairness and liveness are based on infinite sequences. Unfortunately, this cannot be applied to most cryptographic protocols since one must restrict the adversary and the runs as a whole to length polynomial in the security parameter. We present the first general definition of polynomial fairness and liveness in asynchronous scenarios which can cope with cryptographic protocols. Furthermore, our definitions provide a link to the common approach of simulatability which is used throughout modern cryptography: We show that polynomial liveness is maintained under simulatability. As an example, we present an abstract specification and a secure implementation of secure message transmission with reliable channels, and prove them to fulfill the desired liveness property, i.e., reliability of messages. Michael Backes 0001, Birgit Pfitzmann, Michael Waidner |
J. Comput. Secur. | 3 |
| 2003 | Security in Business Process Engineering
Michael Backes 0001, Birgit Pfitzmann, Michael Waidner |
Business Process Management | 3 |
| 2003 | A composable cryptographic library with nested operationsabstractWe present the first idealized cryptographic library that can be used like the Dolev-Yao model for automated proofs of cryptographic protocols that use nested cryptographic operations, while coming with a cryptographic implementation that is provably secure under active attacks. Michael Backes 0001, Birgit Pfitzmann, Michael Waidner |
CCS | 3 |
| 2003 | Symmetric Authentication within a Simulatable Cryptographic Library
Michael Backes 0001, Birgit Pfitzmann, Michael Waidner |
ESORICS | 3 |
| 2003 | Reactively Secure Signature Schemes
Michael Backes 0001, Birgit Pfitzmann, Michael Waidner |
ISC | 3 |
| 2002 | Polynomial Fairness and LivenessabstractImportant properties of many protocols are liveness or availability, i.e. that something good happens now and then. In asynchronous scenarios, these properties obviously depend on the scheduler, which is usually considered to be fair in this case. Unfortunately, the standard definitions of fairness and liveness based on infinite sequences cannot be applied for most cryptographic protocols since one must restrict the adversary and the runs as a whole to polynomial length. We present the first general definition of polynomial fairness and liveness in asynchronous scenarios which is suited to cope with arbitrary cryptographic protocols. Furthermore, our definitions provide a link to the common approach of simulatability which is used throughout modern cryptography, and we show that polynomial liveness is maintained under simulatability. As an example, we present an abstract specification and a secure implementation of secure message transmission with reliable channels, and prove them to fulfill the desired liveness property, i.e., reliability of messages. Michael Backes 0001, Birgit Pfitzmann, Michael Steiner 0001, Michael Waidner |
CSFW | 4 |
| 2001 | Relating Cryptography and Cryptographic Protocols
Andre Scedrov, Ran Canetti, Joshua D. Guttman, David A. Wagner 0001, Michael Waidner |
CSFW | 5 |
| 2001 | A Model for Asynchronous Reactive Systems and its Application to Secure Message TransmissionabstractWe present a rigorous model for secure reactive systems in asynchronous networks with a sound cryptographic semantics, supporting abstract specifications and the composition of secure systems. This enables modular proofs of security, which is essential in bridging the gap between the rigorous proof techniques of cryptography and tool-supported formal proof techniques. The model follows the general simulatability approach of modern cryptography. A variety of network structures and trust models can be described such as static and adaptive adversaries, some examples of this are given. As an example of our specification methodology we provide an abstract and complete specification for Secure Message Transmission, improving on recent results by Lynch (1999), and verify one concrete implementation. Our proof is based on a general theorem on the security of encryption in a reactive multi-user setting, generalizing a recent result by Bellare et. al (2000). Birgit Pfitzmann, Michael Waidner |
S&P | 2 |
| 2001 | Secure password-based cipher suite for TLSabstractSSL is the de facto standard today for securing end-to-end transport on the Internet. While the protocol itself seems rather secure, there are a number of risks that lurk in its use, for example, in web banking. However, the adoption of password-based key-exchange protocols can overcome some of these problems. We propose the integration of such a protocol (DH-EKE) in the TLS protocol, the standardization of SSL by IETF. The resulting protocol provides secure mutual authentication and key establishment over an insecure channel. It does not have to resort to a PKI or keys and certificates stored on the users computer. Additionally, its integration in TLS is as minimal and non-intrusive as possible. Michael Steiner 0001, Peter Buhler, Thomas Eirich, Michael Waidner |
ACM Trans. Inf. Syst. Secur. | 4 |
| 2000 | Composition and integrity preservation of secure reactive systemsabstractWe consider compositional properties of reactive systems that are secure in a cryptographic sense. We follow the well-known simulatability approach, i.e., the specification is an ideal system and a real system should in some sense simulate it. We recently presented the first detailed general definition of this concept for reactive systems that allows abstraction and enables proofs of efficient real-life systems like secure channels or certified mail. We prove two important properties of this definition, preservation of integrity and secure composition: First, a secure real system satis es all integrity requirements (e.g., safety requirements expressed in temporal logic) that are satisfied by the ideal system. Secondly, if a composed system is designed using an ideal subsystem, it will remain secure if a secure real subsystem is used instead. Such a property was so far only known for non-reactive simulatability. Both properties are important for putting formal verification methods for systems u... Birgit Pfitzmann, Michael Waidner |
CCS | 2 |
| 2000 | Round-Optimal and Abuse Free Optimistic Multi-party Contract Signing
Birgit Baum-Waidner, Michael Waidner |
ICALP | 2 |
| 2000 | Secure Password-Based Cipher Suite for TLS
Peter Buhler, Thomas Eirich, Michael Waidner, Michael Steiner 0001 |
NDSS | 3 |
| 2000 | Electronic Commerce
Simon Field, Michael Waidner |
Comput. Networks | 2 |
| 2000 | Optimistic fair exchange of digital signaturesabstractWe present a new protocol that allows two players to exchange digital signatures over the Internet in a fair way, so that either each player gets the other's signature, or neither player does. The obvious application is where the signatures represent items of value, for example, an electronic check or airline ticket. The protocol can also be adapted to exchange encrypted data. It relies on a trusted third party, but is "optimistic," in that the third party is only needed in cases where one player crashes or attempts to cheat. A key feature of our protocol is that a player can always force a timely and fair termination, without the cooperation of the other player, even in a completely asynchronous network. A specialization of our protocol can be used for contract signing; this specialization is not only more efficient, but also has the important property that the third party can be held accountable for its actions: if it ever cheats, this can be detected and proven. N. Asokan, Victor Shoup, Michael Waidner |
IEEE J. Sel. Areas Commun. | 3 |
| 2000 | Design, implementation, and deployment of the iKP secure electronic payment systemabstractThis paper discusses the design, implementation, and deployment of a secure and practical payment system for electronic commerce on the Internet. The system is based on the iKP family of protocols-(i=1,2,3)-developed at IBM Research. The protocols implement credit card-based transactions between buyers and merchants while the existing financial network is used for payment clearing and authorization. The protocols are extensible and can be readily applied to other account-based payment models, such as debit cards. They are based on careful and minimal use of public-key cryptography, and can be implemented in either software or hardware. Individual protocols differ in both complexity and degree of security. In addition to being both a precursor and a direct ancestor of the well-known SET standard, iKP-based payment systems have been in continuous operation on the Internet since mid-1996. This longevity-as well as the security and relative simplicity of the underlying mechanisms-makes the iKP experience unique. For this reason, this paper also reports on, and addresses, a number of practical issues arising in the course of implementation and real-world deployment of a secure payment system. Mihir Bellare, Juan A. Garay 0001, Ralf C. Hauser, Amir Herzberg, Hugo Krawczyk, Michael Steiner 0001, Gene Tsudik, Els Van Herreweghen, Michael Waidner |
IEEE J. Sel. Areas Commun. | 9 |
| 2000 | Key Agreement in Dynamic Peer GroupsabstractAs a result of the increased popularity of group-oriented applications and protocols, group communication occurs in many different settings: from network multicasting to application layer tele- and videoconferencing. Regardless of the application environment, security services are necessary to provide communication privacy and integrity. This paper considers the problem of key agreement in dynamic peer groups. (Key agreement, especially in a group setting, is the stepping stone for all other security services.) Dynamic peer groups require not only initial key agreement (IKA) but also auxiliary key agreement (AKA) operations, such as member addition, member deletion, and group fusion. We discuss all group key agreement operations and present a concrete protocol suite, CLIQUES, which offers complete key agreement services. CLIQUES is based on multiparty extensions of the well-known Diffie-Hellman key exchange method. The protocols are efficient and provably secure against passive adversaries. Michael Steiner 0001, Gene Tsudik, Michael Waidner |
IEEE Trans. Parallel Distributed Syst. | 3 |
| 1999 | Authenticating public terminals
N. Asokan, Hervé Debar, Michael Steiner 0001, Michael Waidner |
Comput. Networks | 4 |
| 1998 | Optimistic Fair Exchange of Digital Signatures (Extended Abstract)
N. Asokan, Victor Shoup, Michael Waidner |
EUROCRYPT | 3 |
| 1998 | CLIQUES: A New Approach to Group Key AgreementabstractThe paper considers the problem of key agreement in a group setting with highly dynamic group member population. A protocol suite, called CLIQUES, is developed by extending the well known Diffie-Hellman key agreement method to support dynamic group operations. Constituent protocols are provably secure and efficient. Michael Steiner 0001, Gene Tsudik, Michael Waidner |
ICDCS | 3 |
| 1998 | Optimal Efficiency of Optimistic Contract SigningabstractA contract is a non-repudiable agreement on a given contract text, i.e., a contract can be used to prove agreement between its signatories to any verifier. A contract signing scheme is used to fairly compute a contract so that, even if one of the signatories misbehaves, either both or none of the signatories obtain a contract. Optimistic contract signing protocols use a third party to ensure fairness, but in such a way that the third party is not actively involved in the fault-less case. Since no satisfactory protocols without any third party exist, this seems to be the best one can hope for. We prove tight lower bounds on the message and round complexity of optimistic contract signing on synchronous and asynchronous networks, and present new and efficient protocols based on digital signatures which achieve provably optimal efficiency. 1 Introduction A contract is a non-repudiable agreement on a given text [4]. A contract signing scheme includes at least three players and two protocol... Birgit Pfitzmann, Matthias Schunter, Michael Waidner |
PODC | 3 |
| 1998 | Asynchronous Protocols for Optimistic Fair ExchangeabstractThe optimistic approach of involving a third party only in the case of exceptions is a useful technique to build secure, yet practical fair exchange protocols. Previous solutions using this approach implicitly assumed that players had reliable communication channels to the third party. We present a set of optimistic fair exchange protocols which tolerate temporary failures in the communication channels to the third party. A central feature of the protocols is that either player can asynchronously and unilaterally bring a protocol run to completion. N. Asokan, Victor Shoup, Michael Waidner |
S&P | 3 |
| 1998 | A Status Report on the SEMPER Framework for Secure Electronic Commerce
Matthias Schunter, Michael Waidner, Dale Whinnett |
Comput. Networks | 2 |
| 1998 | Real-time mixes: a bandwidth-efficient anonymity protocolabstractWe present techniques for efficient anonymous communication with real-time constraints as necessary for services like telephony, where a continuous data stream has to be transmitted. For concreteness, we present the detailed protocols for the narrow-band ISDN (integrated services digital network), although the heart of our techniques-anonymous channels-can also be applied to other networks. For ISDN, we achieve the same data rate as without anonymity, using the same subscriber lines and without any significant modifications to the long-distance network. A precise performance analysis is given. Our techniques are based on mixes, a method for anonymous communication for e-mail-like services introduced by D. Chaum (1981). Anja Jerichow, Jan Müller 0001, Andreas Pfitzmann, Birgit Pfitzmann, Michael Waidner |
IEEE J. Sel. Areas Commun. | 5 |
| 1997 | Optimistic Protocols for Fair ExchangeabstractThis report has been submitted for publication outside of IBM and will probably be copyrighted if accepted for publication. It has been issued as a Research Report for early dissemination of its contents and will be distributed outside of IBM up to one year after the date indicated at the top of this page. In view of the transfer of copyright to the outside publisher, its distribution outside of IBM prior to publication should be limited to peer communications and specific requests. After outside publication, requests should be filled only by reprints or legally obtained copies of the article (e.g., payment of royalties). N. Asokan, Matthias Schunter, Michael Waidner |
CCS | 3 |
| 1997 | Asymmetric Fingerprinting for Larger Collusionsabstract. Fingerprinting schemes deter people from illegally redistributing digital data by enabling the original merchant of the data to identify the original buyer of a redistributed copy. So-called traitor-tracing schemes have the same goal for keys used to decrypt information that is broadcast in encrypted form. Recently, asymmetric fingerprinting and traitor-tracing schemes were introduced. Here, only the buyer knows the fingerprinted copy after a sale, and if the merchant finds this copy somewhere, he obtains a proof that he found the copy of this particular buyer. This gives both parties security in disputes. First constructions showed the validity of the concept. However, these constructions did not yet achieve much security against collusions, in contrast to known symmetric schemes. This paper presents asymmetric constructions without this restriction. 1 Introduction The main roles in a fingerprinting or traitor tracing scenario are: . merchants, who sell digital data, . buyers, w... Birgit Pfitzmann, Michael Waidner |
CCS | 2 |
| 1997 | Anonymous Fingerprinting
Birgit Pfitzmann, Michael Waidner |
EUROCRYPT | 2 |
| 1997 | Server-Supported SignaturesabstractNon-repudiation is one of the most important security services. In this paper we present a novel non-repudiation technique, called server-supported signatures, S3. It is based on one-way hash functions and traditional digital signatures. One of its highlights is that for ordinary users the use of a symmetric cryptography is limited to signature verification. S3 is efficient in terms of computational, communication and storage costs. It also offers a degree of security comparable to that of existing techniques based on asymmetric cryptography. N. Asokan, Gene Tsudik, Michael Waidner |
J. Comput. Secur. | 3 |
| 1997 | Strong Loss Tolerance of Electronic Coin SystemsabstractUntraceable electronic cash means prepaid digital payment systems, usually with offline payments, that protect user privacy. Such systems have recently been given considerable attention by both theory and development projects. However, in most current schemes, loss of a user device containing electronic cash implies a loss of money, just as with real cash. In comparison with credit schemes, this is considered a serious shortcoming. This article shows how untraceable electronic cash can be made loss tolerant, i.e., how the monetary value of the lost data can be recovered. Security against fraud and preservation of privacy are ensured; strong loss tolerance means that not even denial of recovery is possible. In particular, systems based on electronic coins are treated. We present general design principles and options and their instantiation in one concrete payment system. The measures are practical. Birgit Pfitzmann, Michael Waidner |
ACM Trans. Comput. Syst. | 2 |
| 1996 | Diffie-Hellman Key Distribution Extended to Group CommunicationabstractEver since 2-party Diffie-Hellman key exchange was first proposed in 1976, there have been efforts to extend its simplicity and elegance to a group setting. Notable solutions have been proposed by Ingemarsson et al. (in 1982) and Burmester/Desmedt (in 1994). In this paper, we consider a class of protocols that we call natural extensions of DiffieHellman to the n-party case. After demonstrating the security of the entire class based on the intractability of the Diffie-Hellman problem we introduce two novel and practical protocols and compare them to the previous results. We argue that our protocols are optimal with respect to certain aspects of protocol complexity. 1 Introduction It has been almost twenty years since Diffie-Hellman (DH) 2-party key exchange was first proposed in [1]. In the meantime, there have been many attempts to extend its elegance and simplicity to the group setting. The main motivating factor is the increasing popularity of various types of groupware application... Michael Steiner 0001, Gene Tsudik, Michael Waidner |
CCS | 3 |
| 1996 | Server-Supported Signatures
N. Asokan, Gene Tsudik, Michael Waidner |
ESORICS | 3 |
| 1996 | Development of a Secure Electronic Marketplace for Europe
Michael Waidner |
ESORICS | 1 |
| 1995 | How to Break Another Provably Secure Payment System
Birgit Pfitzmann, Matthias Schunter, Michael Waidner |
EUROCRYPT | 3 |
| 1994 | The ESPRIT Project CAFE - High Security Digital Payment Systems
Jean-Paul Boly, Antoon Bosselaers, Ronald Cramer, Rolf Michelsen, Stig Fr. Mjølsnes, Frank Muller, Torben P. Pedersen, Birgit Pfitzmann, Peter de Rooij, Berry Schoenmakers, Matthias Schunter, Luc Vallée, Michael Waidner |
ESORICS | 13 |
| 1992 | Unconditional Byzantine Agreement for any Number of Faulty Processors
Birgit Pfitzmann, Michael Waidner |
STACS | 2 |
| 1991 | How To Break and Repair A "Provably Secure" Untraceable Payment System
Birgit Pfitzmann, Michael Waidner |
CRYPTO | 2 |
| 1991 | Unconditional Byzantine Agreement with Good Majority
Birgit Baum-Waidner, Birgit Pfitzmann, Michael Waidner |
STACS | 3 |
| 1987 | Networks without user observability
Andreas Pfitzmann, Michael Waidner |
Comput. Secur. | 2 |