EDBT 2026 Demo / reviewers in the wild / expert
Leander Jehl
dblp:138/7318
· DBLP profile ↗
20ranked-venue papers
6as first author
13since 2021 · last 2026
0000-0002-4465-540XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 1 first-author · 5 since 2021Software engineering, systems software and programming languages · 6 · 1 first-author · 6 since 2021Systems, architecture and hardware · 5 · 1 first-author · 3 since 2021Computer networks · 3 · 1 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | OptiLog: Assigning Roles in Byzantine ConsensusabstractByzantine Fault-Tolerant (BFT) protocols play an important role in blockchains. As the deployment of such systems extends to wide-area networks, the scalability of BFT protocols becomes a critical concern. Optimizations that assign specific roles to individual replicas can significantly improve the performance of BFT systems. However, such role assignment is highly sensitive to faults, potentially undermining the optimizations' effectiveness. Hanish Gogada, Christian Berger 0006, Leander Jehl, Hans P. Reiser, Hein Meling |
EuroSys | 3 |
| 2026 | Formal Modeling of Beefy, a Protocol for Supporting Light Clients
Daniel O. Dirdal, Leander Jehl, Bhargav Nagaraj Bhatt, Hein Meling, Nejm Saadallah |
FORTE | 2 |
| 2026 | zkRevoke: Configurable Untraceability for Verifiable Credentials using ZKPsabstractSystems managing Verifiable Credentials are becoming increasingly popular. Unfortunately, their support for revoking previously issued credentials allows verifiers to effectively monitor the validity of the credentials, which is sensitive information. While the issue started to gain recognition, no adequate solution has been proposed so far. In this work, we propose a novel framework for time-limited continuous verification. The holder is able to individually configure the verification period when sharing information with the verifier, and the system guarantees proven untraceability of the revocation status after the verification period expires. Differently from existing systems, the implementation adopts a more scalable blacklist approach where tokens corresponding to revoked credentials are stored in the registry. The approach employs ZK proofs that allow holders to prove non-membership in the blacklist. In addition to theoretically proving security, we evaluate the approach analytically and experimentally and show that it significantly improves bandwidth consumption on the holder while being on par with state-of-the-art solutions with respect to the other performance metrics. Praveensankar Manimaran, Mayank Raikwar, Thiago Garrett, Arlindo Flávio da Conceição, Leander Jehl, Roman Vitenberg |
Proc. Priv. Enhancing Technol. | 5 |
| 2024 | Iniva: Inclusive and Incentive-Compatible Vote AggregationabstractMany blockchain platforms use committee-based consensus for scalability, finality, and security. In this consensus scheme, a committee decides which blocks get appended to the chain, typically through several voting phases. Platforms typically leverage the committee members' recorded votes to reward, punish, or detect failures. A common approach is to let the block proposer decide which votes to include, opening the door to possible attacks. For example, a malicious proposer can omit votes from targeted committee members, resulting in lost profits and, ultimately, their departure from the system. This paper presents Iniva, an inclusive and incentive-compatible vote aggregation scheme that prevents such vote omission attacks. Iniva relies on a tree overlay with carefully selected fallback paths, making it robust against process failures without needing reconfiguration or additional redundancy. Our analysis shows that Iniva significantly reduces the chance to omit individual votes while ensuring that omitting many votes incurs a significant cost. In addition, our experimental results show that Iniva enjoys robustness, scalability, and reasonable throughput. Arian Balouchestani, Hanish Gogada, Leander Jehl, Hein Meling |
DSN | 3 |
| 2024 | Altruism, reciprocity, and tokens to reward forwarding data: Is that fair?abstractDecentralized storage networks offer services with intriguing possibilities to reduce inequalities in an extremely centralized market. Fair distribution of rewards, however, is still a persistent problem in the current generation of decentralized applications using token-based incentives. They are often disproportionally concentrated with small number of early adopters and high-resourced participants. Incentive mechanisms capable of addressing this problem are still poorly understood. This paper aims to help fill this gap by developing our Tit-forToken (Tit4Tok) model. Tit4Tok realizes incentives based on the triad of altruism (selfless behavior), reciprocity (Tit-for-Tat), and monetary rewards compatible with a free market. Tit4Tok analyzes the effects of storage-, and network-parameters fine-tuning to achieve fair distribution of rewards for participants. We present a comprehensive exploration of different factors when incentivized peers share bandwidth in a libp2p-based network, including uneven distributions emerging when gateways provide data to users outside the network. We quantified the Income-Fairness with the Gini coefficient, using multiple model instantiations and diverse approaches for debt cancellation. We propose regular changes to the gateway neighborhood and show that our shuffling method improves the Income-Fairness from 0.66 to 0.16. We quantified the non-negligible cost of tolerating free-riding (altruism). The performance is evaluated by extensive computer simulations and using an IPFS workload to study the effects of caching. Vahid Heidaripour Lakhani, Arman Babaei, Leander Jehl, Georgy Ishmaev, Vero Estrada-Galiñanes |
ICBC | 3 |
| 2023 | SoK: Scalability Techniques for BFT ConsensusabstractWith the advancement of blockchain systems, many recent research works have proposed distributed ledger technology (DLT) that employs Byzantine fault-tolerant (BFT) consensus protocols to decide which block to append next to the ledger. Notably, BFT consensus can offer high performance, energy efficiency, and provable correctness properties, and it is thus considered a promising building block for creating highly resilient and performant blockchain infrastructures. Yet, a major ongoing challenge is to make BFT consensus applicable to large-scale environments. A large body of recent work addresses this challenge by developing novel ideas to improve the scalability of BFT consensus, thus opening the path for a new generation of BFT protocols tailored to the needs of blockchain. In this survey, we create a systematization of knowledge about the novel scalability-enhancing techniques that state-of-the-art BFT consensus protocols use. For our comparison, we closely analyze the efforts, assumptions, and trade-offs these protocols make. Christian Berger 0006, Signe Rüsch, Arne Vogel, Kai Bleeke, Leander Jehl, Hans P. Reiser, Rüdiger Kapitza |
ICBC | 5 |
| 2023 | ContractBox: Realizing accountable data sharing on the edge using a small scale blockchainabstractThe utilization of IoT devices is becoming omnipresent in industrial settings. However, adoption in more rural areas still poses challenges. Especially when processing data on the edge, privacy, data integrity, accountability and data ownership pose challenges since the devices may be easily accessed and manipulated. We present ContractBox, a system that provides accountable and trusted data sharing based on a publisher–subscriber system, as well as trusted computing on the edge. ContractBox uses a Trusted Execution Environment to guarantee the confidentiality and integrity of clients’ data and code. Furthermore, it provides security by using WebAssembly to execute the smart contracts in their own sandboxed environment. This design protects the host as well as co-located smart contracts from misbehaving executions. Lastly, it ensures the immutability and accountability of the published data by storing it in a blockchain. We show that ContractBox can process several thousand publications per second with various payloads and host multiple smart contract runtimes on a single edge device. ContractBox also achieves up to 35 times higher throughput than a comparable deployment of Hyperledger Fabric. Lennart Almstedt, Kai Bleeke, Mohammad Mahhouk, Leander Jehl, Rüdiger Kapitza, Lars C. Wolf |
Comput. Networks | 4 |
| 2022 | Rebop: Reputation-Based Incentives in Committee-Based Blockchains
Arian Balouchestani, Leander Jehl, Hein Meling |
DAIS | 2 |
| 2022 | ZugChain: Blockchain-Based Juridical Data Recording in Railway SystemsabstractIn modern trains, a juridical recording unit logs events that occur during operation. This data is used to reconstruct the exact chain of events in case of failures and crashes. To ensure data recovery after an accident, the recorder is hardened against physical damage and secured against tampering; however, it is a single proprietary device and by no means indestructible.This paper presents ZugChain, a distributed, blockchain-based juridical recording unit that opportunistically utilizes on-train hardware. ZugChain offers high reliability via replication and tamper-resistance due to the nature of blockchains. It implements a permissioned blockchain based on a Byzantine fault-tolerant agreement protocol suitable for diverse communication systems. To utilize the logged data for advanced services, e. g., predictive maintenance, ZugChain securely and continuously exports traces to private data centers. We demonstrate ZugChain's feasibility with an implementation running on real train hardware, where we show that ZugChain orders data within 14 ms using at maximum 15 % of the total available shared CPU resources, thus fulfilling requirements of juridical recorders. Signe Rüsch, Kai Bleeke, Ines Messadi, Andreas Krampf, Katharina Olze, Susanne Stahnke, Robert Schmid, Lukas Pirl, Roland Kittel, Andreas Polze, Marquart Franz, Leander Jehl, Rüdiger Kapitza |
DSN | 14 |
| 2022 | SplitBFT: Improving Byzantine Fault Tolerance Safety Using Trusted CompartmentsabstractByzantine fault-tolerant agreement (BFT) in a partially synchronous system usually requires 3f + 1 nodes to tolerate f faulty replicas. Due to their high throughput and finality property, BFT algorithms build the core of recent permissioned blockchains. As a complex and resource-demanding infrastructure, multiple cloud providers have started offering Blockchain-as-a-Service. This eases the deployment of permissioned blockchains but places the cloud provider in a central controlling position, thereby questioning blockchains' fault tolerance and decentralization properties and their underlying BFT algorithm. This paper presents SplitBFT, a new way to utilize trusted execution technology (TEEs), such as Intel SGX, to harden the safety and confidentiality guarantees of BFT systems, thereby strengthening the trust in could-based deployments of permissioned blockchains. Deviating from standard assumptions, SplitBFT acknowledges that code protected by trusted execution may fail. We address this by splitting and isolating the core logic of BFT protocols into multiple compartments resulting in a more resilient architecture. We apply SplitBFT to the traditional practical byzantine fault tolerance algorithm (PBFT) and evaluate it using SGX. Our results show that SplitBFT adds only a reasonable overhead compared to the non-compartmentalized variant. Ines Messadi, Markus Horst Becker, Kai Bleeke, Leander Jehl, Sonia Ben Mokhtar, Rüdiger Kapitza |
Middleware | 4 |
| 2022 | EventChain: a blockchain framework for secure, privacy-preserving event verificationabstractThe number of fake news written by bots or malicious actors on social media is rising. One cause is the ability of users to post anything, at any place, at any time. This offers great flexibility, but it also poses the risk that users share misinformation. One type includes events that allegedly have occurred in a location, without the reporting user necessarily having been present. A user may add her location to posts to appear as an eyewitness and thus more trustworthy; however, basing that trust on commonly used and easily faked GPS locations is not reasonable. Signe Rüsch, Michael Behlendorf, Markus Horst Becker, René Kudlek, Hesham Hosney Elsayed Mohamed, Felix Schoenitz, Leander Jehl, Rüdiger Kapitza |
Middleware | 7 |
| 2022 | A Privacy-Preserving and Transparent Certification System for Digital CredentialsabstractA certification system is responsible for issuing digital credentials, which attest claims about a subject, e.g., an academic diploma. Such credentials are valuable for individuals and society, and widespread adoption requires a trusted certification system. Trust can be gained by being transparent when issuing and verifying digital credentials. However, there is a fundamental tradeoff between privacy and transparency. For instance, admitting a student to an academic program must preserve the student’s privacy, i.e., the student’s grades must not be revealed to unauthorized parties. At the same time, other applicants may demand transparency to ensure fairness in the admission process. Thus, building a certification system with the right balance between privacy and transparency is challenging. This paper proposes a novel design for a certification system that provides sufficient transparency and preserves privacy through selective disclosure of claims such that authorized parties can verify them. Moreover, unauthorized parties can also verify the correctness of the certification process without compromising privacy. We achieve this using an incremental Merkle tree of cryptographic commitments to users' credentials. The commitments are added to the tree based on verifying zero-knowledge issuance proofs. Users store credentials off-chain and can prove the ownership and authenticity of credentials without revealing their commitments. Further, our approach enables users to prove statements about the credential’s claims in zero-knowledge. Our design offers a cost-efficient solution, reducing the amount of linkable on-chain data by up to 79% per credential compared to prior work, while maintaining transparency. Rodrigo Q. Saramago, Hein Meling, Leander Jehl |
OPODIS | 3 |
| 2021 | Formal Verification of HotStuff
Leander Jehl |
FORTE | 1 |
| 2019 | Quorum Selection for Byzantine Fault ToleranceabstractSystems tolerating arbitrary failures use significant resources to constantly mask omission and timing failures from faulty processes. This paper presents Quorum Selection, a mechanism that allows to select well functioning processes for active participation in a system. Different from previous work, Quorum Selection not only excludes provably faulty processes that deviated from the protocol, but also takes omission and timing failures into account, even if they only affect individual links. We present a system architecture for Quorum Selection, including a novel failure detector that uses expectations to detect omission and timing failures in a Byzantine environment. We investigate how often an adversary may cause the quorum to changes. We show a quadratic lower bound for general Quorum Selection, but we also define a special case of Quorum Selection for leader based systems that requires trying at most 6f quorums. Leander Jehl |
ICDCS | 1 |
| 2017 | Towards New Abstractions for Implementing Quorum-Based SystemsabstractThis paper introduces Gorums, a novel RPC framework for building fault tolerant distributed systems. Gorums offers a flexible and simple quorum call abstraction, used to communicate with a set of processes, and to collect and process their responses. Gorums provides separate abstractions for (a) selecting processes for a quorum call and (b) processing replies. These abstractions simplify the main control flow of protocol implementations, especially for quorum-based systems, where only a subset of the replies to a quorum call need to be processed. To show that Gorums can be used in practical systems, we implemented EPaxos' latency-efficient quorum system, and ran experiments using a key-value storage. Our results show that Gorums' abstractions can provide additional performance benefits to EPaxos. Tormod Erevik Lea, Leander Jehl, Hein Meling |
ICDCS | 2 |
| 2016 | The Case for Reconfiguration without Consensus: Comparing Algorithms for Atomic StorageabstractWe compare different algorithms for reconfigurable atomic storage in the data-centric model. We present the first experimental evaluation of two recently proposed algorithms for reconfiguration without consensus and compare them to established algorithms for reconfiguration both with and without consensus. Our evaluation reveals that the new algorithms offer a significant improvement in terms of latency and overhead for reconfiguration without consensus. Our evaluation also shows that reconfiguration without consensus, can obtain similar results to that of consensus-based reconfiguration, which relies on a stable leader. Moreover, the new algorithms also substantially reduces the overhead compared to consensus-based reconfiguration without a leader. While our analysis confirms our intuition that batching reconfiguration requests serves to reduce the overhead of reconfigurations, our evaluation also shows that it is equally important to separate reconfigurations from read and write operations. Specifically, we found that using read and write operations to assist in completing concurrent reconfigurations is in fact detrimental to the reconfiguration performance. Leander Jehl, Hein Meling |
OPODIS | 1 |
| 2015 | Replacement: Decentralized Failure Handling for Replicated State MachinesabstractWe investigate methods for handling failures in a Paxos State Machine and introduce Replacement, a novel approach to handle failures. Replacement is fully decentralized and does not rely on consensus. This allows failed replicas to be replaced quickly, avoiding the bottleneck of a single leader. Instead of handling failures in the order proposed by a leader, concurrent replacements are combined to guarantee that all failed replicas are replaced. Replacement also allows the state machine to process client requests during failure handling, even while disagreeing on the current configuration. As our evaluation shows, this enables Replacement to quickly handle failures, with minimal disruption in the processing of client requests. Leander Jehl, Tormod Erevik Lea, Hein Meling |
SRDS | 1 |
| 2015 | SmartMerge: A New Approach to Reconfiguration for Atomic Storage
Leander Jehl, Roman Vitenberg, Hein Meling |
DISC | 1 |
| 2014 | Replacement - Handling Failures in a Replicated State Machine
Leander Jehl, Tormod Erevik Lea, Hein Meling |
DISC | 1 |
| 2013 | Tutorial Summary: Paxos Explained from Scratch
Hein Meling, Leander Jehl |
OPODIS | 2 |