EDBT 2026 Demo / reviewers in the wild / expert
Stefan Schiffner
dblp:03/567
· DBLP profile ↗
12ranked-venue papers
2as first author
3since 2021 · last 2024
0000-0003-2461-1482ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 1 first-author · 2 since 2021Computer networks · 2Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Why Privacy-Preserving Protocols Are Sometimes Not Enough: A Case Study of the Brisbane Toll Collection InfrastructureabstractThe use of Electronic Toll Collection (ETC) systems is on the rise, as these systems have a significant impact on reducing operational costs. Toll service providers (TSPs) access various information, including drivers' IDs and monthly toll fees, to bill drivers. While this is legitimate, such information could be misused for other purposes violating drivers' privacy, most prominent, to infer drivers' movement patterns. To this end, privacy-preserving ETC (PPETC) schemes have been designed to minimize the amount of information leaked while still allowing drivers to be charged. We demonstrate that merely applying such PPETC schemes to current ETC infrastructures may not ensure privacy. This is due to the (inevitable) minimal information leakage, such as monthly toll fees, which can potentially result in a privacy breach when combined with additional background information, such as road maps and statistical data. To show this, we provide a counterexample using the case study of Brisbane's ETC system. We present two attacks: the first, being a variant of the presence disclosure attack, tries to disclose the toll stations visited by a driver during a billing period as well as the frequency of visits. The second, being a stronger attack, aims to discover cycles of toll stations (e.g., the ones passed during a commute from home to work and back) and their frequencies. We evaluate the success rates of our attacks using real parameters and statistics from Brisbane's ETC system. In one scenario, the success rate of our toll station disclosure attack can be as high as 94%. This scenario affects about 61% of drivers. In the same scenario, our cycle disclosure attack can achieve a success rate of 51%. It is remarkable that these high success rates can be achieved by only using minimal information as input, which is, e.g., available to a driver's payment service provider or bank, and by following very simple attack strategies without exploiting optimizations. As a further contribution, we analyze how the choice of various parameters, such as the set of toll rates, the number of toll stations, and the billing period length, impact a driver's privacy level regarding our attacks. Amirhossein Adavoudi Jolfaei, Andy Rupp, Stefan Schiffner, Thomas Engel 0001 |
Proc. Priv. Enhancing Technol. | 3 |
| 2023 | Smartphones in a Microwave: Formal and Experimental Feasibility Study on Fingerprinting the Corona-Warn-AppabstractContact Tracing Apps (CTAs) have been developed to contain the coronavirus disease 19 (COVID-19) spread. By design, such apps invade their users’ privacy by recording data about their health, contacts, and—partially—location. Many CTAs frequently broadcast pseudorandom numbers via Bluetooth to detect encounters. These numbers are changed regularly to prevent individual smartphones from being trivially trackable. However, the effectiveness of this procedure has been little studied. Henrik Graßhoff, Florian Adamsky, Stefan Schiffner |
ARES | 3 |
| 2023 | A Survey on Privacy-Preserving Electronic Toll Collection Schemes for Intelligent Transportation SystemsabstractAs part of Intelligent Transportation Systems (ITS), Electronic toll collection (ETC) is a type of toll collection system (TCS) which is getting more and more popular as it can not only help to finance the government’s road infrastructure but also it can play a crucial role in pollution reduction and congestion management. As most of the traditional ETC schemes (ETCS) require identifying their users, they enable location tracking. This violates user privacy and poses challenges regarding the compliance of such systems with privacy regulations such as the EU General Data Protection Regulation (GDPR). So far, several privacy-preserving ETC schemes have been proposed. To the best of our knowledge, this is the first survey that systematically reviews and compares various characteristics of these schemes, including components, technologies, security properties, privacy properties, and attacks on ETCS. This survey first categorizes the ETCS based on two technologies, GNSS and DSRC. Then under these categories, the schemes are classified based on whether they provide formal proof of security and support security analysis. We also demonstrate which schemes specifically are/are not resistant to collusion and physical attacks. Then, based on these classifications, several limitations and shortcomings in privacy-preserving ETCS are revealed. Finally, we identify several directions for future research. Amirhossein Adavoudi Jolfaei, Abdelwahab Boualouache, Andy Rupp, Stefan Schiffner, Thomas Engel 0001 |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2019 | On Privacy Notions in Anonymous CommunicationabstractAbstract Many anonymous communication networks (ACNs) with different privacy goals have been developed. Still, there are no accepted formal definitions of privacy goals, and ACNs often define their goals ad hoc. However, the formal definition of privacy goals benefits the understanding and comparison of different flavors of privacy and, as a result, the improvement of ACNs. In this paper, we work towards defining and comparing privacy goals by formalizing them as privacy notions and identifying their building blocks. For any pair of notions we prove whether one is strictly stronger, and, if so, which. Hence, we are able to present a complete hierarchy. Using this rigorous comparison between notions, we revise inconsistencies between the existing works and improve the understanding of privacy goals. Christiane Weis, Martin Beck, Stefan Schiffner, Eduard A. Jorswieck, Thorsten Strufe |
Proc. Priv. Enhancing Technol. | 3 |
| 2018 | WLAN Device Fingerprinting using Channel State Information (CSI)abstractpeer reviewed Florian Adamsky, Tatiana Retunskaia, Stefan Schiffner, Christian Köbel, Thomas Engel 0001 |
WISEC | 3 |
| 2016 | AnonPubSub: Anonymous publish-subscribe overlays
Jörg Daubert, Mathias Fischer 0001, Tim Grube, Stefan Schiffner, Panayotis Kikiras, Max Mühlhäuser |
Comput. Commun. | 4 |
| 2013 | k-anonymous reputationabstractWhile performing pure e-business transactions such as purchasing software or music, customers can act anonymously supported by, e.g., anonymous communication protocols and anonymous payment protocols. However, it is hard to establish trust relations among anonymously acting business partners. Anonymous reputation systems have been proposed to mitigate this problem. Schiffner et al. recently proved that there is a conflict between anonymity and reputation and they established the non-existence of certain privacy-preserving reputation functions. In this paper we argue that this relationship is even more intricate. First, we present a reputation function that deanonymizes the user, yet provides strong anonymity (SA) according to their definitions. However, this reputation function has no utility, i.e., the submitted ratings have no influence on the resulting reputation values. Second, we show that a reputation function having utility requires the system to choose new independently at random selected pseudonyms (for all users it has utility for) on every new rating as a necessary condition to provide strong anonymity according to the aforementioned definition. Since some persistence of pseudonyms is favorable, we present a more secure, but also more usable definition for anonymous reputation systems that allows persistency yet guaranties k-anonymity. We further present a definition for rating secrecy based on a threshold. Finally, we propose a practical reputation function, for which we prove that it satisfies these definitions. Sebastian Clauß 0001, Stefan Schiffner, Florian Kerschbaum |
AsiaCCS | 2 |
| 2013 | Distributed and Anonymous Publish-Subscribe
Jörg Daubert, Mathias Fischer 0001, Stefan Schiffner, Max Mühlhäuser |
NSS | 3 |
| 2011 | Privacy, Liveliness and Fairness for Reputation
Stefan Schiffner, Sebastian Clauß 0001, Sandra Steinbrecher |
SOFSEM | 1 |
| 2011 | On the difficulty of achieving anonymity for Vehicle-2-X communication
Carmela Troncoso, Enrique Costa-Montenegro, Claudia Díaz, Stefan Schiffner |
Comput. Networks | 4 |
| 2010 | Evaluating Adversarial Partitions
Andreas Pashalidis, Stefan Schiffner |
ESORICS | 2 |
| 2009 | Using Linkability Information to Attack Mix-Based Anonymity Services
Stefan Schiffner, Sebastian Clauß 0001 |
Privacy Enhancing Technologies | 1 |