EDBT 2026 Demo / reviewers in the wild / expert
Niklas Vogel
dblp:332/3113
· DBLP profile ↗
11ranked-venue papers
0as first author
11since 2021 · last 2026
0009-0004-1461-2419ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 11 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Pruning the Tree: Rethinking RPKI Architecture from the Ground up
Haya Schulmann, Niklas Vogel |
NDSS | 2 |
| 2026 | The Fault in Our Drafts: Vulnerabilities in RPKI Specification and Softwareabstract2815 Oliver Jacobsen, Tobias Kirsch, Haya Schulmann, Niklas Vogel, Michael Waidner |
SP | 4 |
| 2026 | Batch Me If You Can: Coverage-Guided RPKI Fuzzing at Scale
Haya Schulmann, Niklas Vogel |
SP | 2 |
| 2025 | Demo: Stopping Production Testing: A Graphical RPKI Test-SuiteabstractThe Resource Public Key Infrastructure (RPKI) is increasingly protecting global BGP routing and major players are pushing for wide-scale adoption. RPKI protection relies on correct publication and validity of RPKI objects: If a prefix has no valid covering RPKI object, e.g., because the object is invalid or expired, the prefix is not protected from hijacks. At the same time, ASes that issue RPKI objects lack any feedback whether their objects are considered valid by all RPKI validation software. This lack of feedback has repeatedly led to operational issues, and problems with object validity are persistent to this day. Oftentimes, issues with objects are only detected in production, after they have caused damage to routing. A prominent example of this is an issue with Amazon objects in 2023 that left 6000 of its prefixes open to hijack in any AS using a specific RPKI validator software implementation. In this work, we present a novel RPKI toolsuite that allows for comprehensive testing of RPKI objects, enabling operators to detect issues in their object configurations before production use. For this, our tool allows parsing arbitrary DER/base64 encoded objects, editing their content and structure, and live-testing them against all current RPKI validator implementations to probe for inconsistent validation results, errors, and even vulnerabilities. Our work provides an important foundation to ensure RPKI resilience against misconfigurations and facilitates future research into RPKI security. We make our tool open-source and provide a hosted web application to enable usage by the community. Tobias Kirsch, Haya Schulmann, Niklas Vogel |
CCS | 3 |
| 2025 | Poster: The Rocky Road Towards RPKI Algorithm AgilityabstractThe Resource Public Key Infrastructure (RPKI) already protects around 50% of announced BGP prefixes, and around 28% of systems enforce RPKI validity in routing. RPKI binds ownership of prefixes to public keys inside certificates, which are signed by the respective issuer. For signatures and keys, RPKI currently exclusively supports RSA-2048, forbidding other algorithms and key sizes. In this work, we practically show that RPKI efficiency could significantly benefit from algorithm agility, allowing for smaller more efficient algorithms like Elliptic Curve Cryptography (ECC). We further illustrate that current plans for shifting algorithms, which will eventually become necessary to shift towards quantum-secure algorithms, are infeasible due to bandwidth limitations, validation overhead, and issues with patch management. From our observations, we derive a new agility procedure that uses separate repository versions additional to two separate trees (a mixed tree and a legacy tree) to enable incremental deployment of a new algorithm. In contrast to existing approaches, our procedure provides benefits also for early adopters, facilitating deployment. Katharina Miesch, Haya Schulmann, Niklas Vogel |
CCS | 3 |
| 2025 | Poster: We must talk about RPKI RepositoriesabstractThe Resource Public Key Infrastructure (RPKI) increasingly protects global routing against attacks. RPKI protection builds on the security and availability of RPKI objects, which are stored in public RPKI repositories. Despite their critical role, not much is known about the technical specifics of these repositories. Which implementations do they use? Is the software maintained and secure? Which vulnerabilities persist? Answering these questions is essential to evaluate security and resilience of current RPKI architecture. Haya Schulmann, Niklas Vogel |
CCS | 2 |
| 2024 | The Harder You Try, The Harder You Fail: The KeyTrap Denial-of-Service Algorithmic Complexity Attacks on DNSSECabstractAvailability is a major concern in the design of DNSSEC. To ensure availability, DNSSEC follows Postel's Law [RFC1123]: "Be liberal in what you accept, and conservative in what you send." Hence, nameservers should send not just one matching key for a record set, but all the relevant cryptographic material, e.g., all the keys for all the ciphers that they support and all the corresponding signatures. This ensures that validation succeeds, and hence availability, even if some of the DNSSEC keys are misconfigured, incorrect or correspond to unsupported ciphers. Elias Heftrig, Haya Schulmann, Niklas Vogel, Michael Waidner |
CCS | 3 |
| 2024 | Poster: From Fort to Foe: The Threat of RCE in RPKIabstractIn this work, we present a novel severe buffer-overflow vulnerability in the RPKI validator Fort, that allows an attacker to achieve Remote Code Execution (RCE) on the machine running the software. We discuss the unique impact of this RCE on networks that use RPKI, illustrating that RCE vulnerabilities are especially severe in the context of RPKI. The design of RPKI makes RCE easy to exploit on a large scale, allows compromise of RPKI validation integrity, and enables a powerful vector for additional attacks on other critical components of the network, like the border routers. We analyze the vulnerability exposing to this RCE and identify indications that the discovered vulnerability could constitute an intentional backdoor to compromise systems running the software over a benign coding mistake. We disclosed the vulnerability, which has been assigned a CVE rated 9.8 critical (CVE-2024-45237). Oliver Jacobsen, Haya Schulmann, Niklas Vogel, Michael Waidner |
CCS | 3 |
| 2024 | The CURE to Vulnerabilities in RPKI Validation
Donika Mirdita, Haya Schulmann, Niklas Vogel, Michael Waidner |
NDSS | 3 |
| 2023 | Keep Your Friends Close, but Your Routeservers Closer: Insights into RPKI Validation in the Internet
Tomas Hlavacek, Haya Schulmann, Niklas Vogel, Michael Waidner |
USENIX Security Symposium | 3 |
| 2022 | Poster: Insights into Global Deployment of RPKI ValidationabstractIP prefix hijacks, due to malicious attacks or benign misconfigurations, pose a threat to the Internet's stability and security. RPKI was designed to enable networks to block prefix hijacks by enforcing Route Origin Validation (ROV). In this work we evaluate the effectiveness of the global ROV deployment in blocking prefix hijacks. We perform control-plane and data-plane experiments and provide an in-depth analysis of the collected results. Our analysis is based on new methodologies we developed that allow more accurate identification of ROV enforcing ASes. Our analysis shows that the current ROV enforcement rate is significantly higher than found in previous studies: in contrast to 0.6% in a study from 2021, in our work we find that 37.8% enforce ROV. Our results indicate that ROV has finally gained traction and offers substantial protection against prefix hijacks. Haya Schulmann, Niklas Vogel, Michael Waidner |
CCS | 2 |