EDBT 2026 Demo / reviewers in the wild / expert
Michael P. Heinl
dblp:252/4801
· DBLP profile ↗
6ranked-venue papers
2as first author
5since 2021 · last 2026
0000-0002-1094-4828ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-author · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SoK: The Engineer's Guide to Post-Quantum Cryptography for Embedded Devices
Nikolai Puch, Maximilian Pursche, Sebastian N. Peters, Michael P. Heinl |
EuroS&P | 4 |
| 2024 | EmuFlex: A Flexible OT Testbed for Security Experiments with OPC UAabstractModern communication standards for the Industrial Internet of Things (IIoT) like the Open Platform Communications Unified Architecture (OPC UA) were developed with security in mind. However, their correct implementation in operational technology (OT) environments is often neglected due to a lack of appropriate monetary and human resources, especially among small and medium-sized enterprises. We present a flexible, inexpensive, and easy to use testbed enabling OT operators to experiment with different security scenarios. Our testbed is purely virtual so that procurement and construction of physical or hybrid test environments is not required. It can be operated as a web-hosted service and leverages Docker as well as OPC UA. The testbed therefore combines usability and support for modern technologies enabling future-oriented security studies as well as flexible usage across verticals and company boundaries. Alexander Giehl, Michael P. Heinl, Victor Embacher |
ARES | 2 |
| 2024 | Gateway to the Danger Zone: Secure and Authentic Remote Reset in Machine SafetyabstractThe increasing digitization of modern flexible manufacturing systems has opened up new possibilities for higher levels of automation, paving the way for innovative concepts such as Equipment-as-a-Service. Concurrently, remote access has gained traction, notably accelerated by the COVID-19 pandemic. While some areas of manufacturing have embraced these advancements, safety applications remain localized. This work aims to enable the remote reset of local safety events. To identify necessary requirements, we conducted expert-workshops and analyzed relevant standards and regulations. These requirements serve as the foundation for a comprehensive security and safety concept, built around a secure gateway. It uses secure elements, crypto agility, PQC, and certificates for secure and authentic communication. To show its applicability, we implemented a prototype, which utilizes a gateway, cameras, and light barriers to monitor the danger zone of a robot and thus enable remote reset via public Internet. The real-world limitations we faced, were used to refine our requirements and concept iteratively. Ultimately, we present a secure and safe solution that enables the remote acknowledgment of safety-critical applications. Sebastian N. Peters, Nikolai Puch, Michael P. Heinl, Philipp Zieris, Mykolai Protsenko, Thorsten Larsen-Vefring, Marcel Ely Gomes, Aliza Maftun, Thomas Zeschg |
ARES | 3 |
| 2024 | ParsEval: Evaluation of Parsing Behavior using Real-world Out-in-the-wild X.509 CertificatesabstractX.509 certificates play a crucial role in establishing secure communication over the internet by enabling authentication and data integrity. Equipped with a rich feature set, the X.509 standard is defined by multiple, comprehensive ISO/IEC documents. Due to its internet-wide usage, there are different implementations in multiple programming languages leading to a large and fragmented ecosystem. This work addresses the research question “Are there user-visible and security-related differences between X.509 certificate parsers?”. Relevant libraries offering APIs for parsing X.509 certificates were investigated and an appropriate test suite was developed. From 34 libraries 6 were chosen for further analysis. The X.509 parsing modules of the chosen libraries were called with 186,576,846 different certificates from a real-world dataset and the observed error codes were investigated. This study reveals an anomaly in wolfSSL’s X.509 parsing module and that there are fundamental differences in the ecosystem. While related studies nowadays mostly focus on fuzzing techniques resulting in artificial certificates, this study confirms that available X.509 parsing modules differ largely and yield different results, even for real-world out-in-the-wild certificates. Stefan Tatschner, Sebastian N. Peters, Michael P. Heinl, Tobias Specht, Thomas Newe |
ARES | 3 |
| 2023 | From Standard to Practice: Towards ISA/IEC 62443-Conform Public Key Infrastructures
Michael P. Heinl, Maximilian Pursche, Nikolai Puch, Sebastian N. Peters, Alexander Giehl |
SAFECOMP | 1 |
| 2020 | AntiPatterns regarding the application of cryptographic primitives by the example of ransomwareabstractCryptographic primitives are the basic building blocks for many cryptographic schemes and protocols. Implementing them incorrectly can lead to flaws, making a system or a product vulnerable to various attacks. As shown in the present paper, this statement also applies to ransomware. The paper surveys common errors occurring during the implementation of cryptographic primitives. Based on already existing research, it establishes a categorization framework to match selected ransomware samples by their respective vulnerabilities and assign them to the corresponding error categories. Subsequently, AntiPatterns are derived from the extracted error categories. These AntiPatterns are meant to support the field of software development by helping to detect and correct errors early during the implementation phase of cryptography. Michael P. Heinl, Alexander Giehl, Lukas Graif |
ARES | 1 |