EDBT 2026 Demo / reviewers in the wild / expert
Signe Rüsch
dblp:214/8329 · also Signe Schwarz-Rüsch
· DBLP profile ↗
7ranked-venue papers
3as first author
4since 2021 · last 2023
0000-0002-6305-1943ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 2 first-author · 3 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | SoK: Scalability Techniques for BFT ConsensusabstractWith the advancement of blockchain systems, many recent research works have proposed distributed ledger technology (DLT) that employs Byzantine fault-tolerant (BFT) consensus protocols to decide which block to append next to the ledger. Notably, BFT consensus can offer high performance, energy efficiency, and provable correctness properties, and it is thus considered a promising building block for creating highly resilient and performant blockchain infrastructures. Yet, a major ongoing challenge is to make BFT consensus applicable to large-scale environments. A large body of recent work addresses this challenge by developing novel ideas to improve the scalability of BFT consensus, thus opening the path for a new generation of BFT protocols tailored to the needs of blockchain. In this survey, we create a systematization of knowledge about the novel scalability-enhancing techniques that state-of-the-art BFT consensus protocols use. For our comparison, we closely analyze the efforts, assumptions, and trade-offs these protocols make. Christian Berger 0006, Signe Rüsch, Arne Vogel, Kai Bleeke, Leander Jehl, Hans P. Reiser, Rüdiger Kapitza |
ICBC | 2 |
| 2022 | ZugChain: Blockchain-Based Juridical Data Recording in Railway SystemsabstractIn modern trains, a juridical recording unit logs events that occur during operation. This data is used to reconstruct the exact chain of events in case of failures and crashes. To ensure data recovery after an accident, the recorder is hardened against physical damage and secured against tampering; however, it is a single proprietary device and by no means indestructible.This paper presents ZugChain, a distributed, blockchain-based juridical recording unit that opportunistically utilizes on-train hardware. ZugChain offers high reliability via replication and tamper-resistance due to the nature of blockchains. It implements a permissioned blockchain based on a Byzantine fault-tolerant agreement protocol suitable for diverse communication systems. To utilize the logged data for advanced services, e. g., predictive maintenance, ZugChain securely and continuously exports traces to private data centers. We demonstrate ZugChain's feasibility with an implementation running on real train hardware, where we show that ZugChain orders data within 14 ms using at maximum 15 % of the total available shared CPU resources, thus fulfilling requirements of juridical recorders. Signe Rüsch, Kai Bleeke, Ines Messadi, Andreas Krampf, Katharina Olze, Susanne Stahnke, Robert Schmid, Lukas Pirl, Roland Kittel, Andreas Polze, Marquart Franz, Leander Jehl, Rüdiger Kapitza |
DSN | 1 |
| 2022 | EventChain: a blockchain framework for secure, privacy-preserving event verificationabstractThe number of fake news written by bots or malicious actors on social media is rising. One cause is the ability of users to post anything, at any place, at any time. This offers great flexibility, but it also poses the risk that users share misinformation. One type includes events that allegedly have occurred in a location, without the reporting user necessarily having been present. A user may add her location to posts to appear as an eyewitness and thus more trustworthy; however, basing that trust on commonly used and easily faked GPS locations is not reasonable. Signe Rüsch, Michael Behlendorf, Markus Horst Becker, René Kudlek, Hesham Hosney Elsayed Mohamed, Felix Schoenitz, Leander Jehl, Rüdiger Kapitza |
Middleware | 1 |
| 2021 | Adding Fairness to Order: Preventing Front-Running Attacks in BFT Protocols using TEEsabstractThis paper presents Fairy: a modular system that augments any Total Order Broadcast (TOB) protocol with fairness properties, namely input (request) causality and sender obfuscation. With these properties, Fairy helps to prevent front-running attacks where an adversary can interfere with the order of requests depending on request payload and sender identity, allowing for substantial application-level consequences. Fairy leverages Trusted Execution Environments (TEEs) to implement fairness on top of a TOB-based ordering service. Fairy collocates TEEs with ordering service nodes effectively making them run as trusted proxies of actual TOB clients. TEEs help Fairy to achieve both input causality and sender obfuscation - previous related systems addressing only input causality. We evaluate Fairy on top of a recent, efficient Byzantine Fault-Tolerant (BFT) TOB protocol and compare it to state-of-the-art BFT TOB with input causality. We show that Fairy improves state-of-the-art throughput by 66% and reduces latency by 50%. Chrysoula Stathakopoulou, Signe Rüsch, Marcus Brandenburger, Marko Vukolic |
SRDS | 2 |
| 2019 | Bloxy: Providing Transparent and Generic BFT-Based Ordering Services for BlockchainsabstractWith the wide-spread use of blockchain technology, Byzantine fault-tolerant (BFT) protocols are explored as a means to achieve consensus on which transactions should be processed next. BFT protocols are not a one-size-fits-all solution: they should be chosen according to the blockchain's use case, which can range from supply chain management to decentralised storage, requiring specialisation e.g. regarding throughput, latency, or level of decentralisation. Previously, consensus protocols were usually hardcoded into the blockchain infrastructure and could not be exchanged, therefore inhibiting flexible use of an otherwise generic blockchain infrastructure. Hyperledger Fabric claims to provide modular consensus and support for crash-fault and Byzantine fault tolerant protocols. However, integrating a BFT protocol has shown that Fabric's architecture is currently not well-suited for this fault model as it requires substantial changes and thereby breaks Fabric's modularity. This also has to be repeated for each integrated BFT protocol. In this paper, we present Bloxy, a blockchain-aware trusted proxy running on the replica that encapsulates all BFT client functionality. Bloxy enables transparent access to generic BFT frameworks and preserves Fabric's modularity even for the Byzantine fault model. It runs inside a trusted execution environment based on Intel's Software Guard Extensions. Bloxy offers blockchain-specific communication mechanisms as well as short-term block storage to handle crashes or disconnects to ensure that all nodes receive block updates. We implemented two Bloxy-based ordering services based on PBFT and the hybrid BFT protocol Hybster. Our evaluation shows that our approach increases throughput by up to 71% compared to directly integrated BFT protocols. Signe Rüsch, Kai Bleeke, Rüdiger Kapitza |
SRDS | 1 |
| 2018 | EndBox: Scalable Middlebox Functions Using Client-Side Trusted ExecutionabstractMany organisations enhance the performance, security, and functionality of their managed networks by deploying middleboxes centrally as part of their core network. While this simplifies maintenance, it also increases cost because middlebox hardware must scale with the number of clients. A promising alternative is to outsource middlebox functions to the clients themselves, thus leveraging their CPU resources. Such an approach, however, raises security challenges for critical middlebox functions such as firewalls and intrusion detection systems. We describe EndBox, a system that securely executes middlebox functions on client machines at the network edge. Its design combines a virtual private network (VPN) with middlebox functions that are hardware-protected by a trusted execution environment (TEE), as offered by Intel's Software Guard Extensions (SGX). By maintaining VPN connection endpoints inside SGX enclaves, EndBox ensures that all client traffic, including encrypted communication, is processed by the middlebox. Despite its decentralised model, EndBox's middlebox functions remain maintainable: they are centrally controlled and can be updated efficiently. We demonstrate EndBox with two scenarios involving (i) a large company; and (ii) an Internet service provider that both need to protect their network and connected clients. We evaluate EndBox by comparing it to centralised deployments of common middlebox functions, such as load balancing, intrusion detection, firewalling, and DDoS prevention. We show that EndBox achieves up to 3.8x higher throughput and scales linearly with the number of clients. David Goltzsche, Signe Rüsch, Manuel Nieke, Sébastien Vaucher, Nico Weichbrodt, Valerio Schiavoni, Pierre-Louis Aublin, Paolo Costa, Christof Fetzer, Pascal Felber, Peter R. Pietzuch, Rüdiger Kapitza |
DSN | 2 |
| 2018 | Hybrid Fault-Tolerant Consensus in Asynchronous and Wireless Embedded SystemsabstractByzantine fault-tolerant (BFT) consensus in an asynchronous system can only tolerate up to floor[(n-1)/3] faulty processes in a group of n processes. This is quite a strict limit in certain application scenarios, for example a group consisting of only 3 processes. In order to break through this limit, we can leverage a hybrid fault model, in which a subset of the system is enhanced and cannot be arbitrarily faulty except for crashing. Based on this model, we propose a randomized binary consensus algorithm that executes in complete asynchrony, rather than in partial synchrony required by deterministic algorithms. It can tolerate up to floor[(n-1)/2] Byzantine faulty processes as long as the trusted subsystem in each process is not compromised, and terminates with a probability of one. The algorithm is resilient against a strong adversary, i. e. the adversary is able to inspect the state of the whole system, manipulate the delay of every message and process, and then adjust its faulty behaviour during execution. From a practical point of view, the algorithm is lightweight and has little dependency on lower level protocols or communication primitives. We evaluate the algorithm and the results show that it performs promisingly in a testbed consisting of up to 10 embedded devices connected via an ad hoc wireless network. Wenbo Xu 0002, Signe Rüsch, Rüdiger Kapitza |
OPODIS | 2 |