EDBT 2026 Demo / reviewers in the wild / expert
Michael Eckel
dblp:271/4790
· DBLP profile ↗
13ranked-venue papers
10as first author
11since 2021 · last 2025
0000-0002-5138-1769ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 10 first-author · 11 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | LENI: Lightweight and Efficient Network-Optimized Remote Attestation for IoT DevicesabstractWe present LENI, a standards-aligned transport for remote attestation logs that replaces known IMA/CEL entries with compact indices—using a a context-aware, lossless transport scheme—into shared Reference Values (RVs) derived from CoRIM/CoMID, while inlining unknowns. We formalize the method and invariants, define a CBOR + COSE wire format, and integrate a C99 + SQLite prototype with TAP/CHARRA. Across stable, managed systems (IIoT, energy, network gear, automotive, avionics), our executed evaluation shows 60–94% byte reduction depending on RV coverage (60/80/95%), e. g., a 40k-entry log shrinks from ~10.68 MiB (full CEL) to ~0.61 MiB at 95% coverage. Codec overhead is modest (sub-ms per 1k events on x86 64/A72; sub-second end-to-end on Cortex-M for 40k events) and leaves cryptographic checks (AK/COSE, freshness, TPM PCR re-compute) unchanged. Beyond the baseline client– verifier flow, we demonstrate a handheld verifier using QR/JAB Code for offline appraisal and show that LENI’s packed-index mode enables compliant runtime reporting over LoRaWAN under regional payload and duty-cycle limits. Michael Eckel |
TrustCom | 1 |
| 2025 | Towards Stateless Post-Quantum Remote Attestation for IoT Using TPM and DICEabstractRemote attestation is a cornerstone of Trusted Computing, ensuring the integrity and trustworthiness of devices in diverse environments, ranging from resource-constrained IoT nodes to cloud-based virtual machines (VMs). The two predominant attestation technologies, the Trusted Platform Module (TPM) and the Device Identifier Composition Engine (DICE), provide strong security guarantees but often rely on stateful challenge-response models. These models introduce scalability challenges, particularly in large-scale Internet of Things (IoT) and smart metering deployments.This paper presents a powerful stateless post-quantum remote attestation approach for IoT devices, leveraging authenticated and encrypted (AEAD) challenges within TPM and DICE-based attestation. The stateless approach effectively limits replay attacks to a short validity window, even in environments where IoT devices lack real-time clocks, and enables robust integrity and trust verification across dynamic network topologies, by avoiding the downsides of other freshness concepts for remote attestation.Furthermore, this paper presents a performance evaluation of suitable post-quantum cryptography (PQC) algorithms across five heterogeneous hardware platforms, ranging from high-end laptops to constrained IoT devices, to present a recommendation to the reader, thereby illustrating the continued utility of remote attestation on IoT devices in the future.Our findings suggest that stateless post-quantum remote attestation can enhance security and scalability in IoT environments, by reducing overhead from storage of nonces making it a compelling alternative to traditional challenge-response models. Michael Eckel, Janik Gorbracht, Georgios Gkoktsis, Tobias Kaupat |
TrustCom | 1 |
| 2025 | Who Appraises the Appraiser? Decentralized Attestation with Partial Appraisal and Aggregated ResultsabstractWe present a decentralized approach to remote attestation that moves evidence appraisal from a central verifier to Trusted Execution Environments (TEEs) at the edge, emitting compact attestation results instead of raw evidence. Our design supports partial appraisal—explicitly encoding unknown or missing evidence—and aggregation of (partial) attestation results across composite systems, anchored in provisioned keys and reference values (RVs). To answer "Who appraises the appraiser?", each edge verifier is itself attested (e. g., Intel SGX/TDX, AMD SEV-SNP, Arm Trust Zone-A/M, RISC-V Keystone and MultiZone®, NVIDIA H100) and its TEE quote is cryptographically bound to the attestation result, enabling relying parties to appraise both the device and the verifier. The approach instantiates cleanly across domains—constrained IoT/smart metering (SMGWs), automotive zonal architectures, cloud/edge multi-tenant stacks, Network Functions Virtualization (NFV) chassis, and power substations—with identical semantics for partial appraisal and aggregation. A prototype using CHAllenge-Response based Remote Attestation with TPM 2.0 (CHARRA) with the verifier inside Intel Software Guard Extensions (SGX) using the Gramine library OS demonstrates reduced network volume and central CPU load with acceptable overheads while preserving conservative security semantics under partially appraised evidence. Michael Eckel, Georgios Gkoktsis, Markus Horn |
TrustCom | 1 |
| 2024 | SECURA: Unified Reference Architecture for Advanced Security and Trust in Safety Critical InfrastructuresabstractIn the evolving landscape of safety-critical infrastructures, ensuring the integrity and security of systems has become paramount. Building upon a previously established security architecture tailored for the railway sector, this work introduces significant enhancements that extend its applicability beyond the confines of any singular industry. Key advancements include the integration of a security heartbeat to augment safety monitoring, the implementation of a sophisticated secure update mechanism leveraging Trusted Platform Module (TPM) Enhanced Authorization (EA) policies, local Trusted Platform Module (TPM) based attestation, a cyber-resiliency watchdog in a Trusted Execution Environment (TEE) that detects compromised system components and triggers remediation actions, automated vulnerability scanning leveraging Linux Integrity Measurement Architecture (IMA) logs to check against vulnerability databases, and a formal evaluation of system integrity reporting capabilities through remote attestation. Michael Eckel, Sigrid Gürgens |
ARES | 1 |
| 2024 | Towards Practical Hardware Fingerprinting for Remote Attestation
Michael Eckel, Florian Fenzl, Lukas Jäger |
SEC | 1 |
| 2023 | A Generic IoT Quantum-Safe Watchdog Timer ProtocolabstractThis paper presents a quantum-safe watchdog timer protocol designed and implemented using various quantum-safe digital signature algorithms. The protocol is specifically tailored to be used in the context of the Internet of Things (IoT) to address the security risks posed by quantum computing to classical protocols. Our approach replaces the classical protocol with a quantum-safe watchdog timer protocol, which ensures that an IoT device’s communication channels remain secure from adversarial attacks. Michael Eckel, Tanja Gutsche, Hagen Lauer, Andre Rein |
ARES | 1 |
| 2023 | Remote Attestation with Constrained DisclosureabstractTrusted Platform Modules (TPMs) are used for remote attestation to ensure the authenticity and integrity of software running on a computer system. However, measuring software executed as containers or virtual machines can be challenging as it is measured concurrently, resulting in a jumbled measurement log that is difficult to disentangle. Moreover, disclosing the entire measurement log in traditional binary remote attestation raises privacy and intellectual property concerns. To address these issues, we propose a remote attestation method with constrained disclosure, allowing for selective disclosure of entries in the measurement log using a non-interactive zero-knowledge (NIZK) proof with Schnorr signatures. Our approach is evaluated for security and privacy and proven to be correct, sound, and satisfies the properties of a NIZK proof. Formal verification of our solution with ProVerif also supports our claims. Furthermore, the performance evaluation of our proof-of-concept implementation shows that our contribution is feasible, and the overhead introduced is negligible. Michael Eckel, Dominik Roy George, Björn Grohmann, Christoph Krauß |
ACSAC | 1 |
| 2023 | SCATMAN: A Framework for Enhancing Trustworthiness in Digital Supply ChainsabstractIn this paper, we present a framework and an architecture that aim to enable and manage trust in supply chains. Our architecture addresses the authenticity and integrity of devices and processes within heterogeneous system landscapes. We identify and discuss the current challenges in digital supply chains and lay out security, privacy, and interoperability requirements that must be met for successful implementation. We hypothesize that the overall perception of trust in a supply chain depends on the trustworthiness of all digital systems involved, including hardware, software, and information flow. Our proposed architecture helps enhance trustworthiness based on verifiable, indisputable, and believable digital evidence for devices and processes in supply chains, including the entire hardware and software lifecycles. We actively advocate for a mixed landscape of centralized and decentralized solutions for the storage of evidence and trust information. This can include traditional centralized databases and distributed ledger technologies. We discuss the auditability and accountability of digital evidence using trust-enabling technologies, and present a preliminary proof-of-concept (PoC) implementation in a real-world application scenario. Michael Eckel, Anirban Basu 0001, Satoshi Kai, Hervais Simo Fhom, Sinisa Dukanovic, Henk Birkholz, Shingo Hane, Matthias Lieske |
TrustCom | 1 |
| 2023 | Evaluating the applicability of hardware trust anchors for automotive applicationsabstractThe automotive trend towards autonomous driving and advanced connected services increases both complexity of the vehicle internal network and the connections to its environment. This introduced complexity further broadens the vehicle cyberattack surface. As mitigation strategy, state-of-the-art security mechanisms utilize so-called hardware trust anchors (HTAs) to protect security-sensitive data and processes in shielded locations that are isolated utilizing hardware security mechanisms. However, there is a variety of different HTAs with different functionality and security guarantees and there is currently no work done that compares and evaluates them against current and emerging automotive requirements. In this work, we evaluate the applicability of various HTAs to secure modern as well as upcoming future automotive applications. For this, we analyze and evaluate HTAs that are already established in the automotive field as well as promising HTAs from other domains. We extend our preliminary work [1] by increasing the range of the analyzed HTAs with solutions that are feasible for the most resource constrained automotive controllers and technologies that become feasible to be utilized by the introduction of high-performance controllers in future automotive architectures. We assess the different HTAs based on the evaluation criteria and in accordance to automotive requirements. Christian Plappert, Dominik Lorych, Michael Eckel, Lukas Jäger, Andreas Fuchs 0002, Ronald Heddergott |
Comput. Secur. | 3 |
| 2022 | A Resilient Network Node for the Industrial Internet of ThingsabstractThe Industrial Internet of Things (IIoT) is a ubiquitous part of modern production processes. This introduces new challenges to classical security architectures for industrial networks like the perimeter approach. These are made obsolete by the increasing horizontal and vertical integration of industrial systems and IT systems. A promising concept to face these challenges is resilience. This term describes systems or networks that can isolate compromised parts of themselves and reset them to a trustworthy state with minimal impact to the functionality of the overall system. In order to bring this concept to IIoT networks, we present a novel embedded network node that uses Trusted Computing technology such as a Trusted Platform Module (TPM) and Remote Attestation for attack detection and reporting, virtualization for the separation of processes with different criticalities and an authenticated watchdog for guaranteed platform resets as a form of return to an uncompromised state. This combination provides secure mechanisms for resilience on a platform level and can serve as a foundation for network resilience based on Software-Defined Networking (SDN) solutions. The architecture and implementation of the proposed network node are described in detail before evaluating its resource consumption and performance in order to demonstrate its suitability for embedded and IIoT contexts. Lukas Jäger, Dominik Lorych, Michael Eckel |
ARES | 3 |
| 2021 | Userspace Software Integrity MeasurementabstractTodays computing systems are more interconnected and sophisticated than ever before. Especially in healthcare 4.0, services and infrastructures rely on cyber-physical systemss (CPSess) and Internet of Things (IoT) devices. This adds to the complexity of these highly connected systems and their manageability. Even worse, the variety of emerging cyber attacks is becoming more severe and sophisticated, making healthcare one of the most important sectors with major security risks. The development of appropriate countermeasures constitutes one of the most complex and difficult challenges in cyber security research. Research areas include, among others, anomaly detection, network security, multi-layer event detection, cyber resiliency, and integrity protection. Michael Eckel, Tim Riemann |
ARES | 1 |
| 2020 | Subverting Linux' integrity measurement architectureabstractIntegrity is a key protection objective in the context of system security. This holds for both hardware and software. Since hardware cannot be changed after its manufacturing process, the manufacturer must be trusted to build it properly. However, it is completely different with software. Users of a computer system are free to run arbitrary software on it and even modify BIOS/UEFI, bootloader, or Operating System (OS). Felix Bohling, Tobias Mueller, Michael Eckel, Jens Lindemann 0001 |
ARES | 3 |
| 2020 | Secure Attestation of Virtualized Environments
Michael Eckel, Andreas Fuchs 0002, Jürgen Repp, Markus Springer |
SEC | 1 |