EDBT 2026 Demo / reviewers in the wild / expert
Steffen Lindner
dblp:257/4950
· DBLP profile ↗
12ranked-venue papers
4as first author
10since 2021 · last 2026
0000-0002-5274-4621ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 9 · 3 first-author · 7 since 2021Systems, architecture and hardware · 3 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Extensions to BIER Tree Engineering (BIER-TE) for large multicast domains and 1:1 protectionabstractBit Index Explicit Replication (BIER) was developed by the IETF as a new forwarding paradigm for stateless multicast packet forwarding. IP multicast (IPMC) creates a per-hop forwarding state for each IP multicast group. In contrast, ingress nodes of a BIER domain equip packets with a bitstring indicating egress nodes, and BIER nodes forward the packets according to that bitstring. As the bitstring size is limited, e.g., 256 bits, only that number of egress nodes can be addressed. To scale BIER to larger networks, the egress nodes can be assigned to subsets and addressed with with a subset-specific bitstrings including a subset ID. This approach is even compliant with fast reroute (FRR) mechanisms for BIER. BIER-TE extends BIER with tree engineering capabilities, i.e., the bitstring is repurposed to indicate both egress nodes and links, so that explicit paths can be encoded over which packets are transmitted. However, BIER’s scaling mechanism cannot be adopted out of the box for BIER-TE because the encoding of explicit paths requires that all contained links belong to the same subset. Obviously, chosen subsets for BIER-TE scaling must represent connected sub-topologies. In this work, we extend BIER-TE for scaling. When an ingress node sends a packet to an egress node in another subset, it tunnels the packet to the ingress node of that subset. We further protect the communication against link and node failures, which is particularly challenging when the ingress node of a subset fails, and which is a major contribution of this paper. The suggested protocol solution combines existing concepts like tunneling, egress protection, and BIER-TE-FRR. We identify various behaviors of BIER-TE nodes, and implement them on the P4-programmable Tofino switching ASIC to demonstrate the feasibility of the proposed approach. Finally, we evaluate and discuss the forwarding performance of the prototype. Moritz Flüchter, Steffen Lindner, Fabian Ihle, Toerless Eckert, Michael Menth |
J. Netw. Comput. Appl. | 2 |
| 2025 | How Low Can You Go? Revisiting (S)NTP Time Synchronization for Industrial NetworksabstractTime synchronization is a fundamental requirement for various industrial automation scenarios. Its use cases range from precise distributed control to deterministic Sequence of Events (SoEs) in case of plant faults. With the advent of Time-Sensitive Networking (TSN), the Generalized Precision Time Protocol (gPTP) has been the protocol of choice to enable sub- $\mu$ s time synchronization between network devices and has superseded the Network Time Protocol (NTP) in most mission-critical systems. However, gPTP requires hardware support in all devices and thus is not compatible with many existing system installations. In this paper, we revisit time synchronization for industrial networks and tackle the question of NTP’s synchronization accuracy in the light of network convergence. We examine the impact of recent capabilities of network devices such as strict priority scheduling and frame preemption on (S)NTP and show that accuracies below 1 ms can be achieved in large networks. Steffen Lindner, Amin Shahraki, Dirk Schulz 0002 |
WFCS | 1 |
| 2024 | Secure Resource Allocation Protocol (SecRAP) for Time-Sensitive NetworkingabstractThe convergence of operational technology (OT) and information technology (IT) networks through Time-Sensitive Networking (TSN) promises enhanced efficiency and new use cases in industrial settings. However, ensuring security in this shared infrastructure is crucial to prevent potential attacks that could compromise Quality of Service (QoS) of real-time streams and pose risks to operations and safety. This paper focuses on auditing the security of the Resource Allocation Protocol (RAP), a distributed QoS signaling protocol for TSN. We analyze the vulnerability of RAP to attacks during admission control, where end stations request network resources for data transmission. We leverage the Dolev-Yao attacker model to assess the security properties of RAP in both distributed hop-by-hop admission control and hybrid admission control with a central controller. We introduce novel security extensions to RAP, called Secure Resource Allocation Protocol (SecRAP), to mitigate the identified attack vectors. Finally, we present a prototype and discuss the security properties of SecRAP. Lukas Osswald, Steffen Lindner, Lukas Bechtel, Tobias Heer, Michael Menth |
ETFA | 2 |
| 2024 | Autonomous integration of TSN-unaware applications with QoS requirements in TSN networksabstractModern industrial networks transport both best-effort and real-time traffic. Time-Sensitive Networking (TSN) was introduced by the IEEE TSN Task Group as an enhancement to Ethernet to provide high quality of service (QoS) for real-time traffic. In a TSN network, applications signal their QoS requirements to the network before transmitting data. The network then allocates resources to meet these requirements. However, TSN-unaware applications can neither perform this registration process nor profit from TSN’s QoS benefits. The contributions of this paper are twofold. First, we introduce a novel network architecture in which an additional device acts as a central user configuration (CUC) for TSN-unaware applications and autonomously signals their QoS requirements to the network. Second, we propose a processing method to detect real-time streams in a network and extract the necessary information for the TSN stream signaling. It leverages a Deep Recurrent Neural Network (DRNN) to detect periodic traffic, extracts an accurate traffic description, and uses traffic classification to determine the source application. As a result, our proposal allows TSN-unaware applications to benefit from TSNs QoS guarantees. Our evaluations underline the effectiveness of the proposed architecture and processing method. Moritz Flüchter, Steffen Lindner, Lukas Osswald, Jérôme Arnaud, Michael Menth |
Comput. Commun. | 2 |
| 2024 | P4-PSFP: P4-Based Per-Stream Filtering and Policing for Time-Sensitive NetworkingabstractTime-Sensitive Networking (TSN) extends Ethernet to enable real-time communication. In TSN, bounded latency and zero congestion-based packet loss are achieved through mechanisms such as the Credit-Based Shaper (CBS) for bandwidth shaping and the Time-Aware Shaper (TAS) for traffic scheduling. Generally, TSN requires streams to be explicitly admitted before being transmitted. To ensure that admitted traffic conforms with the traffic descriptors indicated for admission control, Per-Stream Filtering and Policing (PSFP) has been defined. For credit-based metering, well-known token bucket policers are applied. However, time-based metering requires time-dependent switch behavior and time synchronization with sub-microsecond precision. While TSN-capable switches support various TSN traffic shaping mechanisms, a full implementation of PSFP is still not available. To bridge this gap, we present a P4-based implementation of PSFP on a 100 Gb/s per port hardware switch. We explain the most interesting aspects of the PSFP implementation whose code is available on GitHub. We demonstrate credit-based and time-based policing and synchronization capabilities to validate the functionality and effectiveness of P4-PSFP. The implementation scales up to 35840 streams depending on the stream identification method. P4-PSFP can be used in practice as long as appropriate TSN switches lack this function. Moreover, its implementation may be helpful for other P4-based hardware implementations that require time synchronization. Fabian Ihle, Steffen Lindner, Michael Menth |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2023 | A survey on data plane programming with P4: Fundamentals, advances, and applied research
Frederik Hauser, Marco Häberle, Daniel Merling, Steffen Lindner, Vladimir Gurevich, Florian Zeiger, Reinhard Frank, Michael Menth |
J. Netw. Comput. Appl. | 4 |
| 2023 | Learning Multicast Patterns for Efficient BIER Forwarding With P4abstractBit Index Explicit Replication (BIER) is an efficient domain-based transport mechanism for IP multicast (IPMC) that indicates receivers of a packet through a bitstring in the packet header. Recently, BIER forwarding has been implemented on 100 Gbit/s per port hardware using the P4 programming language. However, the implementation requires packet recirculation to iteratively serve one next-hop after another. The objective of this paper is to reduce this inefficiency. Static multicast groups can be configured on P4 switches so that traffic can be sent to all next-hops without recirculation. We leverage that feature to make BIER forwarding more efficient. However, only a limited number of static multicast groups can be configured on a switch, which is not sufficient to cover all potential port patterns. In a first step, we develop efficient BIER forwarding that utilizes static multicast groups derived from so-called configured port clusters. Then, we design port clustering algorithms that observe multicast patterns and compute configured port clusters which are more efficient than randomly selected port clusters. These methods are based on Spectral Clustering, an unsupervised machine learning technique. We perform simulations that underline the effectiveness of this approach to reduce inefficient packet recirculations. We further implement the new forwarding behaviour on programmable hardware and provide a controller that samples BIER packets on the switch, runs the port clustering algorithms, and updates the configured static multicast groups. We validate this open source implementation in a testbed and show that the experimental results are in line with the simulation results. Steffen Lindner, Daniel Merling, Michael Menth |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2023 | Alternative Best Effort (ABE) for Service Differentiation: Trading Loss Versus DelayabstractThe idea of an Alternative Best Effort (ABE) per-hop behaviour (PHB) emerged about 20 years ago. It provides a low-delay traffic class in the Internet at the expense of more packet loss than Best Effort (BE). Therefore, ABE is better suited than BE for loss-tolerant but delay-sensitive applications. Furthermore, ABE traffic should not degrade the service for BE traffic in terms of packet loss and delay. Therefore, Internet service providers may leave the choice of using BE or ABE to their customers as they achieve service differentiation without compromising other traffic. In this work, we revisit ABE and pursue the fundamental question whether an ABE service is technically feasible, how its service would look like and interact with existing transport protocols? We present a novel scheduler called Deadlines, Saved Credits, and Decay (DSCD) for combined scheduling of BE and ABE traffic. It allows to control ABE’s delay advantage over BE and copes with varying bandwidth. We provide an implementation of DSCD in the Linux network stack and demonstrate its efficiency. A side product of the implementation is an efficient approximation of the exponential function in the kernel and a bandwidth estimation method that even works at moderate link utilization. We study DSCD in a semi-virtualized testbed with real networking stacks to understand implications for transport protocols in a BE/ABE Internet. The study analyzes ABE’s impact on loss and delay under various conditions and gives recommendations for configuration. Steffen Lindner, Gabriel Paradzik, Michael Menth |
IEEE/ACM Trans. Netw. | 1 |
| 2021 | RAP Extensions for the Hybrid Configuration ModelabstractModern applications in industrial automation rely on a deterministic network service, i.e., low latency, high reliability, and network convergence. Therefore, the IEEE 802.1 TSN Task Group introduces Time-Sensitive Networking (TSN). Besides mechanisms for traffic shaping, time synchronization, and reliability, TSN introduces three different configuration models for resource reservation: the fully distributed, the fully centralized, and the centralized network/distributed (hybrid) user model. Furthermore, IEEE P802.1Qdd specifies the Resource Allocation Protocol (RAP) to enable resource reservation for TSN streams in the fully distributed model. In this paper, we give an introduction to RAP, and propose extensions to RAP for the use in the hybrid configuration model. Additionally, we implement a prototype which is published under an open-source license. Lukas Osswald, Steffen Lindner, Lukas Wüsteney, Michael Menth |
ETFA | 2 |
| 2021 | Robust LFA Protection for Software-Defined Networks (RoLPS)abstractIn software-defined networks, forwarding entries on switches are configured by a controller. In case of an unreachable next-hop, traffic is dropped until forwarding entries are updated, which takes significant time. Therefore, fast reroute (FRR) mechanisms are needed to forward affected traffic over alternate paths in the meantime. Loop-free alternates (LFAs) and remote LFAs (rLFAs) have been proposed for FRR in IP networks. However, they cannot protect traffic for all destinations and some LFAs may create loops under challenging conditions. This paper proposes robust LFA protection for software-defined networks (RoLPS). RoLPS augments the coverage of (r)LFAs with novel explicit LFAs (eLFAs). RoLPS ranks available LFAs according to protection quality and complexity for selection of the best available LFA. Furthermore, we introduce advanced loop detection (ALD) so that RoLPS stops loops caused by LFAs. We evaluate RoLPS-based protection variants on a large set of representative networks with unit and non-unit link costs. We study their protection coverage, additional forwarding entries, and path extensions for rerouted traffic, and compare them with MPLS facility backup. Results show that RoLPS can protect traffic against all single link or node failures, and against most double failures while inducing only little overhead. We implement FRR on the P4-programmable switch ASIC Tofino and provide a control plane logic based on RoLPS. Measurement results show that the prototype achieves a throughput of 100 Gb/s, reroutes traffic within less than a millisecond, and reliably detects and drops looping traffic. Daniel Merling, Steffen Lindner, Michael Menth |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2020 | P4 In-Network Source Protection for Sensor Failover
Steffen Lindner, Marco Häberle, Florian Heimgaertner, Naresh Nayak 0001, Sebastian Schildt, Dennis Grewe, Hans Löhr, Michael Menth |
Networking | 1 |
| 2020 | P4-based implementation of BIER and BIER-FRR for scalable and resilient multicast
Daniel Merling, Steffen Lindner, Michael Menth |
J. Netw. Comput. Appl. | 2 |