Jakob Heher

dblp:324/8174 · DBLP profile ↗
← Back
5ranked-venue papers
1as first author
5since 2021 · last 2025
0009-0007-7351-8117ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 1 first-author · 5 since 2021
YearPublicationVenuePosition
2025 BISON: Blind Identification with Stateless scOped pseudoNyms
Jakob Heher, Stefan More, Lena Heimberger
AsiaCCS1
2025 Future-Proof Asynchronous IoT Backups: An Evaluation of Secure IoT Data Recovery Considering Post-Quantum Threats
Dmytro Shvets, Edona Fasllija, Jakob Heher, Stefan More
SEC (2)3
2024 Service Provider Accreditation: Enabling and Enforcing Privacy-by-Design in Credential-based Authentication Systems
abstract
In credential-based authentication systems (wallets), users transmit personally identifiable and potentially sensitive data to Service Providers (SPs). Here, users must often trust that they are communicating with a legitimate SP and that the SP has a lawful reason for requesting the information that it does. In the event of data misuse, identifying and holding the SP accountable can be difficult.
Stefan More, Jakob Heher, Edona Fasllija, Maximilian Mathie
ARES2
2024 Credential Issuance Transparency: A Privacy-Preserving Audit Log of Credential Issuance
Edona Fasllija, Jakob Heher, Stefan More
NSS2
2022 Offline-verifiable Data from Distributed Ledger-based Registries
abstract
Trust management systems often use registries to authenticate data, or form trust decisions. Examples are revocation registries and trust status lists. By introducing distributed ledgers (DLs), it is also possible to create decentralized registries. A verifier then queries a node of the respective ledger, e.g., to retrieve trust status information during the verification of a credential. While this ensures trustworthy information, the process requires the verifier to be online and the ledger node available. Additionally, the connection from the verifier to the registry poses a privacy issue, as it leaks information about the user's behavior. In this paper, we resolve these issues by extending existing ledger APIs to support results that are trustworthy even in an offline setting. We do this by introducing attestations of the ledger's state, issued by ledger nodes, aggregatable into a collective attestation by all nodes. This attestation enables a user to prove the provenance of DL-based data to an offline verifier. Our approach is generic. So once deployed it serves as a basis for any use case with an offline verifier. We also provide an implementation for the Ethereum stack and evaluate it, demonstrating the practicability of our approach.
Stefan More, Jakob Heher, Clemens Walluschek
SECRYPT2