VLDB 2026 Research / reviewers in the wild / expert
Thomas Groß 0001
dblp:g/ThomasGross · also Thomas Gross 0001
· DBLP profile ↗
22ranked-venue papers
7as first author
4since 2021 · last 2025
0000-0002-7766-2454ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 18 · 7 first-author · 4 since 2021Artificial intelligence and machine learning · 1Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | MoniPoly - An Expressive $q$q-SDH-Based Anonymous Attribute-Based Credential System With Constant-Size ProofsabstractModern anonymous attribute-based credential (ABC) systems benefit from expressive and efficient show proofs on logical statements. Camenisch and Groß pioneered such statements with an Strong RSA-based ABC system on a restricted message space that offers efficient$\mathsf{AND}$,$\mathsf{OR}$and$\mathsf{NOT}$proofs. While other ABC frameworks have adopted constructions in the same vein, the Camenisch-Groß ABC has been the most expressive and asymptotically most efficient proof system to date. Due to its use of prime numbers as message space, however, it is constrained by the requirement of a trusted message-space setup and an inherent restriction to pre-defined finite-set attributes. In this paper, we present a provably secure ABC system that supports show proofs for complex logical statements on an unrestricted message space. Our construction is founded on the commit-and-sign paradigm and offers a novel commitment scheme. This construction is not only more expressive than existing approaches, but also highly efficient. Its ECC protocols only require a constant number of bilinear pairings by the verifier; none by the prover. As the security models for the existing approaches do not capture the expressiveness of this scheme, we introduce strong security models for impersonation resilience and unlinkability under adaptive active and concurrent attacks. Based on the$q$-(co-)SDH assumption, we prove the scheme's security with respect to both properties with tight reductions. Syh-Yuan Tan, Thomas Groß 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | Special issue on socio-technical aspects in security - editorialabstractSuccessful attacks on information systems often exploit not only IT systems and networks, but also the human element in the system.It is vital to understand technical vulnerabilities and how user behavior contributes to their exploitation, but also poorly designed user interfaces, and unclear or unrealistic security policies.To improve the security of systems, technology and policies must consider the characteristics of the users, where research in social sciences and usable security has demonstrated that user behavior involved in security exploits can be understood from cognitive, emotional, and social perspectives.When there is a good "fit" of technology to users, workable security policies and targeted behavioral support can augment technical security.Finding the right balance between technical and social security measures remains, however, largely unexplored, and different security communities (theoretical security, systems security, usable security, and security management) rarely work together.There remains a need for focused, holistic research in socio-technical security, and the respective communities tend to offload on each other parts of problems that they consider to be out of scope.This is an attitude that results in deficient or unsuitable security solutions.The research domain of socio-technical security was born after many realized that practical attacks against information services often succeed because of a combination of social engineering practices and technical skills.Often, such attacks were possible because of vulnerable security mechanisms, ill-designed system interfaces, unusable security policies, or carelessly conceived human computer ceremonies -and not because humans just "don't get security right", as it was wrongly put not a long time ago.In 2011, Giampaolo Bella and Gabriele Lenzini created the international Workshop on "Socio-Technical Aspects in Security and Trust" (STAST) to gather experts in security and experts in social science with an interest in security, and thus foster an interdisciplinary discussion on how to model and analyze the socio-technical aspects of modern security systems and on how to protect such systems from socio-technical threats and attacks.Since then, the workshop has taken place annually, shortening its name to "Socio-Technical Aspects in Security", but continuing to stimulate an active exchange of ideas and experiences from different communities of researchers in order to identify weaknesses potentially emerging from poor usability designs and policies, from social engineering, and from deficiencies hidden in flawed interfaces and implementations.STAST has been bringing together experts in computer security and in cognitive, social, and behavioral sciences; it has been collecting the state of the art, identifying open and emerging problems, and proposing future research directions. Thomas Groß 0001, Luca Viganò 0001 |
J. Comput. Secur. | 1 |
| 2021 | Hashing to Prime in Zero-Knowledge
Thomas Groß 0001 |
SECRYPT | 1 |
| 2021 | Validity and Reliability of the Scale Internet Users' Information Privacy Concerns (IUIPC)abstractAbstract Internet Users’ Information Privacy Concerns (IUIPC-10) is one of the most endorsed privacy concern scales. It is widely used in the evaluation of human factors of PETs and the investigation of the privacy paradox. Even though its predecessor Concern For Information Privacy (CFIP) has been evaluated independently and the instrument itself seen some scrutiny, we are still missing a dedicated confirmation of IUIPC-10, itself. We aim at closing this gap by systematically analyzing IUIPC’s construct validity and reliability. We obtained three mutually independent samples with a total of N = 1031 participants. We conducted a confirmatory factor analysis (CFA) on our main sample to assert the validity and reliability of IUIPC-10. Having found weaknesses, we proposed a respecified instrument IUIPC-8 with improved psychometric properties. Finally, we confirmed our findings on a validation sample. While we found sound foundations for content validity and could confirm the overall three-dimensionality of IUIPC-10, we observed evidence of biases in the question wording and found that IUIPC-10 consistently missed the mark in evaluations of construct validity and reliability, calling into question the unidimensionality of its sub-scales Awareness and Control. Our respecified scale IUIPC-8 offers a statistically significantly better model and outperforms IUIPC-10’s construct validity and reliability. The disconfirming evidence on IUIPC-10’s construct validity raises doubts how well it measures the latent variable Information Privacy Concern. The less than desired reliability could yield spurious and erratic results as well as attenuate relations with other latent variables, such as behavior. Thereby, the instrument could confound studies of human factors of PETs or the privacy paradox, in general. Thomas Groß 0001 |
Proc. Priv. Enhancing Technol. | 1 |
| 2020 | MoniPoly - An Expressive q-SDH-Based Anonymous Attribute-Based Credential System
Syh-Yuan Tan, Thomas Groß 0001 |
ASIACRYPT (3) | 2 |
| 2018 | UniGuard: Protecting Unikernels Using Intel SGXabstractComputations executed in lightweight virtual machines called unikernels have a minimal attack surface and improved performance. However, unikernels are still prone to leaking information to the operating system or to the hypervisor that hosts them. This is attributed to vulnerabilities in privileged software and to malicious insiders operating in cloud infrastructures. Indeed, the deployment of unikernels requires a protection mechanism to ensure that information does not leak from unikernels. In this paper, we present our initial experiments into the use of an approach to creating a Trusted Execution Environment (TEE) in unikernels. We present UniGuard: a security architecture that leverages Intel Software Guard Extensions (SGX) to protect security-sensitive computations inside unikernels. We believe that unikernels are an excellent match for Intel SGX to create a TEE. We implemented our solution on top of the KVM hypervisor and its Intel SGX support. Results show that UniGuard has a comparable 20% overhead when starting an enclave inside a unikernel and 10% when executing ocalls. Ioannis Sfyrakis, Thomas Groß 0001 |
IC2E | 2 |
| 2017 | VirtusCap: Capability-Based Access Control for UnikernelsabstractA recent direction in cloud computing is toward massive consolidation of resources by using lightweight virtual machines (VMs) called unikernels. Unikernels are specialized VMs that eliminate the operating system layer and provide a small footprint, minimal attack surface, and near-instant boot times. However, managing the privileges of thousands of unikernels hosted in Xen hypervisor and authoring complex Mandatory Access Control (MAC) policies using Xen Security Module (XSM)-Flask or sHype is often difficult and error prone for cloud administrators. XSM-Flask and sHype access control mechanisms have not reached wide adoption since their configuration and policies are complex and contain hundreds of subjects and objects for a single VM. Thus, we require an access control mechanism that is flexible, simple, integrated with unikernels and is efficient in order to regulate access to a large number of unikernels. In this paper, we present VirtusCap: a novel multi-layer access control architecture and mechanism that integrates capabilities with unikernels. Our approach employs capabilities to limit privileges of unikernels. Hence, our approach embodies the Principle of Least Privilege (POLP) to create unikernels that have only the privileges they need to accomplish their task. Performance evaluations show that up to request rate of 7000 (req/sec) our prototype's response time is identical to XSM-Flask. Ioannis Sfyrakis, Thomas Groß 0001 |
IC2E | 2 |
| 2017 | Why Privacy Is All But ForgottenabstractAbstract Privacy and sharing are believed to share a dynamic and dialectical tension, where individuals have competing needs to be both open and closed in contact with others [8]. Online, technology can impact this dynamic process [68]. Indeed, a number of researchers observed that users’ stated privacy attitude do not match their behavior [2, 3, 23, 30, 64, 81]. In these studies privacy attitude is compared with behavior via a number of concepts related to privacy. While it is known in psychology that attitudes are multidimensional constructs [10, 15, 76], the question arises whether the user ambivalence with regards to privacy is due to different or contradictory cognitive and affective components of privacy and sharing attitude. We conducted an empirical study to investigate the difference between privacy attitude and sharing attitude. A US sample ofN= 60 MTurk workers was assigned to two groups and asked to describe in a 250-word free-form response what [privacy/sharing] online means for them. Responses were coded in quantitative content analysis. The presence and frequency of codes were compared across conditions. Emotions and relationships to other parties were evaluated as predictors for a discriminative logistic regression classifying both attitudes. We found that privacy and sharing attitude differ significantly across a number of the extracted codes. Participants in privacy attitude were significantly more likely to express fear and significantly less likely to express happiness. For sharing attitude the reverse is true. We found that a discriminant logistic regression on a tone analysis of the participants’ responses offers excellent discrimination between privacy and sharing attitude. We cross-validated this classifier with another sample ofN′ = 54. The observed differences contribute an understanding of user states in privacy (and sharing) situations online and has implications for both privacy research and practice. Kovila P. L. Coopamootoo, Thomas Groß 0001 |
Proc. Priv. Enhancing Technol. | 2 |
| 2015 | Proactive Security Analysis of Changes in Virtualized InfrastructuresabstractThe pervasiveness of cloud computing can be attributed to its scale and elasticity. However, the operational complexity of the underlying cloud infrastructure is high, due to its dynamics, multi-tenancy, and size. Misconfigurations and insider attacks carry significant operational and security risks, such as breaches in tenant isolation put both the infrastructure provider and the consumers at risk. Sören Bleikertz, Carsten Vogel, Thomas Groß 0001, Sebastian Mödersheim |
ACSAC | 3 |
| 2014 | Cloud radar: near real-time detection of security failures in dynamic virtualized infrastructuresabstractCloud infrastructures are designed to share physical resources among many different tenants while ensuring overall security and tenant isolation. The complexity of dynamically changing and growing cloud environments, as well as insider attacks, can lead to misconfigurations that ultimately result in security failures. The detection of these misconfigurations and subsequent failures is a crucial challenge for cloud providers---an insurmountable challenge without tools. Sören Bleikertz, Carsten Vogel, Thomas Groß 0001 |
ACSAC | 3 |
| 2013 | Eighth ACM workshop on digital identity management (DIM 2013): identity at the crossroadsabstractThe Workshop Digital Identity Management has evolved during the last decade as one of the most interesting events on identity management issues. Starting from a community with a background mainly in computer science, it has developed towards an interdisciplinary workshop where a lively interactive community discusses identity topics from technical, sociological, economical, legal, psychological and many more angles. The goal of this workshop is to share the latest findings, identify key challenges, inspire debates, and foster collaboration between industries and academia towards interoperable identity service infrastructures. Thomas Groß 0001, Marit Hansen |
CCS | 1 |
| 2013 | Defense-in-Depth Against Malicious Insiders in the CloudabstractA critical challenge in cloud computing is assuring confidentiality and integrity for the execution of arbitrary software in a consumer's virtual machine. The problem arises from having multiple virtual machines sharing hardware resources in the same physical host. A security critical resource is random access memory, which in the current version of the Xen hyper visor is vulnerable to attacks. Like previous work demonstrated, this vulnerability originates from Xen adopting avery permissive memory access model for its management virtual machine (Dom0). The model assumes it is safe to grant Dom0full access to the memory space allocated to consumer's virtual machines. In this paper, we first present a sophisticated attack which makes it possible to compromise security-sensitive information resident in the memory area of a particular process executing in a virtual machine. The attack demonstration consists in subverting the new inter-virtual machine communication mechanism, libvchan, which is under development for the Xen hyper visor. This attack allows us to propose and implement a proof of concept for a lightweight mandatory memory access control mechanism for Xen, which achieves a better overall memory access model forDom0. We then propose an architecture which takes advantage of our memory protection mechanism and previous work to achievedefense in depth in cloud computing. Francisco Liberal Rocha, Thomas Groß 0001, Aad P. A. van Moorsel |
IC2E | 2 |
| 2013 | Defining Privacy Is Supposed to Be Easy
Sebastian Mödersheim, Thomas Groß 0001, Luca Viganò 0001 |
LPAR | 2 |
| 2012 | Efficient Attributes for Anonymous CredentialsabstractWe extend the Camenisch-Lysyanskaya anonymous credential system such that selective disclosure of attributes becomes highly efficient. The resulting system significantly improves upon existing approaches, which suffer from a linear number of modular exponentiations in the total number of attributes. This limitation makes them unfit for many practical applications, such as electronic identity cards. Our novel approach can incorporate a large number of binary and finite-set attributes without significant performance impact. It compresses all such attributes into a single attribute base and, thus, boosts the efficiency of all proofs of possession. The core idea is to encode discrete binary and finite-set values as prime numbers. We then use the divisibility property for efficient proofs of their presence or absence. In addition, we contribute efficient methods for conjunctions and disjunctions. The system builds on the strong RSA assumption. We demonstrate the aptness of our method in realistic application scenarios, notably electronic identity cards, and show its advantages for small devices, such as smartcards and cell phones. Jan Camenisch, Thomas Groß 0001 |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2011 | Vertical Protocol CompositionabstractThe security of key exchange and secure channel protocols, such as TLS, has been studied intensively. However, only few works have considered what happens when the established keys are actuallyused -- to run some protocol securely over the established "channel". We call this a vertical protocol composition, and it is truly commonplace in today's communication with the diversity of VPNs and secure browser sessions. In fact, it is normal that we have several layers of secure channels: For instance, on top of a VPN-connection, a browser may establish another secure channel (possibly with a different end point). Even using the same protocol several times in such a stack of channels is not unusual: An application may very well establish another TLS channel over an established one. We call this self-composition. In fact, there is nothing that tells us that all these compositions are sound, i.e., that the combination cannot introduce attacks that the individual protocols in isolation do not have. In this work, we prove a composability result in the symbolic model that allows for arbitrary vertical composition (including self-composition). It holds for protocols from any suite of channel and application protocols that fulfills a number of sufficient preconditions. These preconditions are satisfied for many practically relevant protocols such as TLS. Thomas Groß 0001, Sebastian Mödersheim |
CSF | 1 |
| 2011 | Automated Information Flow Analysis of Virtualized Infrastructures
Sören Bleikertz, Thomas Groß 0001, Matthias Schunter, Konrad Eriksson |
ESORICS | 2 |
| 2010 | Credential Authenticated Identification and Key Exchange
Jan Camenisch, Nathalie Casati, Thomas Groß 0001, Victor Shoup |
CRYPTO | 3 |
| 2009 | Anonymous credentials on a standard java cardabstractSecure identity tokens such as Electronic Identity (eID) cards are emerging everywhere. At the same time user-centric identity management gains acceptance. Anonymous credential schemes are the optimal realization of user-centricity. However, on inexpensive hardware platforms, typically used for eID cards, these schemes could not be made to meet the necessary requirements such as future-proof key lengths and transaction times on the order of 10 seconds. The reasons for this is the need for the hardware platform to be standardized and certified. Therefore an implementation is only possible as a Java Card applet. This results in severe restrictions: little memory (transient and persistent), an 8-bit CPU, and access to hardware acceleration for cryptographic operations only by defined interfaces such as RSA encryption operations. Patrik Bichsel, Jan Camenisch, Thomas Groß 0001, Victor Shoup |
CCS | 3 |
| 2008 | Efficient attributes for anonymous credentialsabstractWe extend the Camenisch-Lysyanskaya anonymous credential system such that selective disclosure of attributes becomes highly efficient. The resulting system significantly improves upon existing approaches, which suffer from a linear complexity in the total number of attributes. This limitation makes them unfit for many practical applications, such as electronic identity cards. Our system can incorporate an arbitrary number of binary and finite-set attributes without significant performance impact. Our approach folds all such attributes in a single attribute base and, thus, boosts the efficiency of all proofs of possession. The core idea is to encode discrete binary and finite-set attribute values as prime numbers. We use the divisibility property for efficient proofs of their presence or absence. We additionally contribute efficient methods for conjunctions and disjunctions. The system builds on the Strong-RSA assumption alone. We demonstrate the applicability and performance improvements of our method in realistic application scenarios, such as, electronic identity cards and complex/structured credentials. Our method has crucial advantages in devices with restricted computational capabilities, such as smartcards and cell phones. Jan Camenisch, Thomas Groß 0001 |
CCS | 2 |
| 2007 | User centricity: A taxonomy and open issuesabstractUser centricity is a significant concept in federated identity management (FIM), as it provides for stronger user control and privacy. However, several notions of user-centricity in the FIM community render its semantics unclear and hamper future research in this area. Therefore, we consider user-centricity abstractly and establish a comprehensive taxonomy encompassing user-control, architecture, and usability aspects of user-centric FIM. We highlight the various mechanisms to achieve the properties identified in the taxonomy. We show how these mechanisms may differ based on the underlying technologies which in turn result in different trust assumptions. We classify the technologies into two predominant variants of user-centric FIM systems with significant feature sets. We distinguish credential-focused systems, which advocate offline identity providers and long-term credentials at a user's client, and relationship-focused systems, which rely on the relationships between users and online identity providers that create short-term credentials during transactions. Note that these two notions of credentials are quite different. The former encompasses cryptographic credentials as defined by Lysyanskaya et al., in Selected Areas in Cryptography, LNCS, vol. 1758, and the latter encompasses federation tokens as used in today's FIM protocols like Liberty. We raise the question where user-centric FIM systems may go – within the limitations of the user-centricity paradigm as well as beyond them. Firstly, we investigate the existence of a universal user-centric FIM system that can achieve a superset of security and privacy properties as well as the characteristic features of both predominant classes. Secondly, we explore the feasibility of reaching beyond user centricity, that is, allowing a user of a user-centric FIM system to again give away user control by means of an explicit act of delegation. We do neither claim a solution for universal user-centric systems nor for the extension beyond the boundaries of user centricity, however, we establish a starting point for both ventures by leveraging the properties of a credential-focused FIM system. Abhilasha Bhargav-Spantzel, Jan Camenisch, Thomas Groß 0001, Dieter Sommer |
J. Comput. Secur. | 3 |
| 2005 | Browser Model for Security Analysis of Browser-Based Protocols
Thomas Groß 0001, Birgit Pfitzmann, Ahmad-Reza Sadeghi |
ESORICS | 1 |
| 2003 | Security Analysis of the SAML Single Sign-on Browser/Artifact ProfileabstractMany influential industrial players are currently pursuing the development of new protocols for federated identity management. The security assertion markup language (SAML) is an important standardized example of this new protocol class and will be widely used in business-to-business scenarios to reduce user-management costs. SAML utilizes a constraint-based specification that is a popular design technique of this protocol class. It does not include a general security analysis, but provides an attack-by-attack list of countermeasures as security consideration. We present a security analysis of the SAML single sign-on browser/artifact profile, which is the first one for such a protocol standard. Our analysis of the protocol design reveals several flaws in the specification that can lead to vulnerable implementations. To demonstrate their impact, we exploit some of these flaws to mount attacks on the protocol. Thomas Groß 0001 |
ACSAC | 1 |