Robert Krahn

dblp:42/7656 · DBLP profile ↗
← Back
12ranked-venue papers
2as first author
3since 2021 · last 2025
0000-0003-0768-6351ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 4 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 4 · 1 first-author · 1 since 2021Security and privacy · 2 · 1 since 2021Computer networks · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Computer architecture, parallel and distributed computing, and storage systems
3 papers
Cloud and datacenter computing · 47% Distributed systems · 38% Storage systems · 14%
Network and information security
4 papers
Hardware security and side channels · 55% Cryptographic protocols and secure computation · 20% Authentication and access control · 20%

Topics — the 7 heaviest of 9, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Hardware security and side channels
trusted execution environments
0.932025
Varys: Protecting SGX Enclaves from Practical Side-Channel Attacks · USENIX ATC 2018
LibSEAL: revealing service integrity violations using trusted execution · EuroSys 2018
Understanding the Latency-Security Tradeoff: TEE-based Confidential Computing for Streaming Workloads · ICNP 2025
Cloud and datacenter computing › cloud security
confidential computing
0.912025
Understanding the Latency-Security Tradeoff: TEE-based Confidential Computing for Streaming Workloads · ICNP 2025
Distributed systems
stream processing
0.912025
Understanding the Latency-Security Tradeoff: TEE-based Confidential Computing for Streaming Workloads · ICNP 2025
Authentication and access control
access control
0.312018
Pesos: policy enhanced secure object store · EuroSys 2018
Storage systems
secure storage
0.312018
Pesos: policy enhanced secure object store · EuroSys 2018
Systems and software security › trusted computing
enclave security
0.112018
Varys: Protecting SGX Enclaves from Practical Side-Channel Attacks · USENIX ATC 2018
Cloud and datacenter computing › datacenter services
online service systems
0.112018
LibSEAL: revealing service integrity violations using trusted execution · EuroSys 2018

Methods — techniques the papers use, named apart from their topics

measurement · 1.7i/o mediation · 0.7declarative policy language · 0.7
YearPublicationVenuePosition
2025 Understanding the Latency-Security Tradeoff: TEE-based Confidential Computing for Streaming Workloads
abstract
Distributed streaming platforms such as Pravega, Kafka, and Pulsar are widely used for high-throughput, low-latency data processing. As these platforms increasingly handle sensitive data, ensuring data confidentiality and integrity becomes critical. Trusted Execution Environments (TEEs) offer secure computations that can be used on client-side processing, but their impact on performance must be carefully assessed. This study evaluates the write latency of Pravega clients running in TEEs compared to those in standard (non-secured) environments. We found that under typical workloads, TEE-based clients experience approximately 50% higher latency due to the overhead of secure executions. However, when data rates exceed 976 MB/s, the Pravega broker reaches its throughput limit, causing latency to spike for standard clients. In contrast, TEE-based clients exhibit more stable latency under these high-throughput conditions. These findings can be helpful for data architects, as systems highlight a trade-off: while latency may increase, the impact could be acceptable in certain scenarios given the enhanced security benefits.
Alan Cueva Mora, K. P. N. Jayasena, Robert Krahn, Enrique Chirivella-Perez, Christof Fetzer
ICNP3
2023 SinClave: Hardware-assisted Singletons for TEEs
abstract
For trusted execution environments (TEEs), remote attestation permits establishing trust in software executed on a remote host. It requires that the measurement of a remote TEE is both complete and fresh: We need to measure all aspects that might determine the behavior of an application, and this measurement has to be reasonably fresh. Performing measurements only at the start of a TEE simplifies the attestation but enables "reuse" attacks of enclaves. We demonstrate how to perform such reuse attacks for different TEE frameworks. We also show how to address this issue by enforcing freshness -- through the concept of a singleton enclave -- and completeness of the measurements. Completeness of measurements is not trivial since the secrets provisioned to an enclave and the content of the filesystem can both affect the behavior of the software, i.e., can be used to mount reuse attacks. We present mechanisms to include measurements of these two components in the remote attestation. Our evaluation based on real-world applications shows that our approach incurs only negligible overhead ranging from 1.03% to 13.2%.
Franz Gregor, Robert Krahn, Do Le Quoc, Christof Fetzer
Middleware2
2021 ADAM-CS: Advanced Asynchronous Monotonic Counter Service
abstract
Trusted execution environments (TEEs) offer the technological breakthrough to allow several applications to be deployed and executed over untrusted public cloud environments. Although TEEs (e. g., Intel SGX, ARM TrustZone, AMD SEV) provide several mechanisms to ensure confidentiality and integrity of data and code, they do not offer freshness out of the box, a critical aspect yet often overlooked, for instance, to protect against rollback attacks. Monotonic counters are a popular way to detect rollbacks, as their counter values cannot be decremented. However, counter increments are slow (i.e., 10thof milliseconds), making their use impractical for distributed services and applications processing thousands of transactions simultaneously, for which an order of magnitude improvement is needed. ADAM-CS is an asynchronous monotonic counter service to protect such high-traffic applications against rollback attacks. Leveraging a set of distributed monotonic counters and specific algorithms, ADAM-CS minimizes the maximum vulnerability window (MVW), i.e., the amount of transactions an adversary could successfully rollback. Thanks to its asynchronous nature, ADAM-CS supports thousands of increments per second without introducing additional latency in the transactions performed by applications. Our measurements indicate that we can keep the MVW well below 10ms while supporting a throughput of more than 21K requests/s when using eight counters.
André Martin, Cong Lian, Franz Gregor, Robert Krahn, Valerio Schiavoni, Pascal Felber, Christof Fetzer
DSN4
2020 TEEMon: A continuous performance monitoring framework for TEEs
abstract
Trusted Execution Environments (TEEs), such as Intel Software Guard eXtensions (SGX), are considered as a promising approach to resolve security challenges in clouds. TEEs protect the confidentiality and integrity of application code and data even against privileged attackers with root and physical access by providing an isolated secure memory area, i.e., enclaves. The security guarantees are provided by the CPU, thus even if system software is compromised, the attacker can never access the enclave's content. While this approach ensures strong security guarantees for applications, it also introduces a considerable runtime overhead in part by the limited availability of protected memory (enclave page cache). Currently, only a limited number of performance measurement tools for TEE-based applications exist and none offer performance monitoring and analysis during runtime.
Robert Krahn, Donald Dragoti, Franz Gregor, Do Le Quoc, Valerio Schiavoni, Pascal Felber, Clenimar Souza, Andrey Brito, Christof Fetzer
Middleware1
2018 LibSEAL: revealing service integrity violations using trusted execution
abstract
Users of online services such as messaging, code hosting and collaborative document editing expect the services to uphold the integrity of their data. Despite providers' best efforts, data corruption still occurs, but at present service integrity violations are excluded from SLAs. For providers to include such violations as part of SLAs, the competing requirements of clients and providers must be satisfied. Clients need the ability to independently identify and prove service integrity violations to claim compensation. At the same time, providers must be able to refute spurious claims.
Pierre-Louis Aublin, Florian Kelbert, Dan O'Keeffe, Divya Muthukumaran, Christian Priebe, Joshua Lind, Robert Krahn, Christof Fetzer, David M. Eyers, Peter R. Pietzuch
EuroSys7
2018 Pesos: policy enhanced secure object store
abstract
Third-party storage services pose the risk of integrity and confidentiality violations as the current storage policy enforcement mechanisms are spread across many layers in the system stack. To mitigate these security vulnerabilities, we present the design and implementation of Pesos, a Policy Enhanced Secure Object Store (Pesos) for untrusted third-party storage providers. Pesos allows clients to specify per-object security policies, concisely and separately from the storage stack, and enforces these policies by securely mediating the I/O in the persistence layer through a single unified enforcement layer. More broadly, Pesos exposes a rich set of storage policies ensuring the integrity, confidentiality, and access accounting for data storage through a declarative policy language.
Robert Krahn, Bohdan Trach, Anjo Vahldiek-Oberwagner, Thomas Knauth, Pramod Bhatotia, Christof Fetzer
EuroSys1
2018 PubSub-SGX: Exploiting Trusted Execution Environments for Privacy-Preserving Publish/Subscribe Systems
abstract
This paper presents PUBSUB-SGX, a content-based publish-subscribe system that exploits trusted execution environments (TEEs), such as Intel SGX, to guarantee confidentiality and integrity of data as well as anonymity and privacy of publishers and subscribers. We describe the technical details of our Python implementation, as well as the required system support introduced to deploy our system in a container-based runtime. Our evaluation results show that our approach is sound, while at the same time highlighting the performance and scalability trade-offs. In particular, by supporting just-in-time compilation inside of TEEs, Python programs inside of TEEs are in general faster than when executed natively using standard CPython.
Sergei Arnautov, Andrey Brito, Pascal Felber, Christof Fetzer, Franz Gregor, Robert Krahn, Wojciech Ozga, André Martin, Valerio Schiavoni, Marcus Tenorio, Nikolaus Thummel
SRDS6
2018 Varys: Protecting SGX Enclaves from Practical Side-Channel Attacks
Oleksii Oleksenko, Bohdan Trach, Robert Krahn, Mark Silberstein, Christof Fetzer
USENIX ATC3
2015 The Ignite Distributed Collaborative Scientific Visualization System
abstract
We describe the Ignite Distributed Collaborative Scientific Visualization System (IDCVS), a system which permits real-time interaction and visual collaboration around large data sets, with an initial emphasis on scientific data. The IDCVS offers such a collaborative environment, with real-time interaction on any device between users separated across the wide area. It provides seamless interaction and immediate updates even under heavy load and when users are widely separated: the design goal was to fetch a data set consisting of 30,000 points from a server and render it within 150ms, for a user anywhere in the world, and reflect changes made by a user in one location to all other users within a bound provided by network latency. The system was demonstrated successfully on a significant worldwide air pollution data set, with values on 10, 25, 50, and 100km worldwide grids, monthly over an 18-year period. It was demonstrated on a wide variety of clients, including laptop, tablet, and smartphone.
Sushil Bhojwani, Matt Hemmings, Daniel H. H. Ingalls, Jens Lincke, Robert Krahn, David John Lary, Patrick C. McGeer, Glenn Ricart, Marko Röder, Yvonne Coady, Ulrike Stege
CloudCom5
2014 Babelsberg/JS - A Browser-Based Implementation of an Object Constraint Language
Tim Felgentreff, Alan Borning, Robert Hirschfeld, Jens Lincke, Yoshiki Ohshima, Bert Freudenberg, Robert Krahn
ECOOP7
2010 The SOM family: virtual machines for teaching and research
abstract
This paper introduces the SOM (Simple Object Machine) family of virtual machine (VM) implementations, a collection of VMs for the same Smalltalk dialect addressing students at different levels of expertise. Starting from a Java-based implementation, several ports of the VM to different programming languages have been developed and put to successful use in teaching at both undergraduate and graduate levels since 2006. Moreover, the VMs have been used in various research projects. The paper documents the rationale behind each of the SOM VMs and results that have been achieved in teaching and research.
Michael Haupt 0003, Robert Hirschfeld, Tobias Pape, Gregor Berg, Stefan Marr, Arne Bergmann, Arvid Heise, Matthias Kleine, Robert Krahn
ITiCSE9
2010 Continuous Selective Testing
Bastian Steinert, Michael Haupt 0003, Robert Krahn, Robert Hirschfeld
XP3