EDBT 2026 Demo / reviewers in the wild / expert
Robert Krahn
dblp:42/7656
· DBLP profile ↗
12ranked-venue papers
2as first author
3since 2021 · last 2025
0000-0003-0768-6351ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 4 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 4 · 1 first-author · 1 since 2021Security and privacy · 2 · 1 since 2021Computer networks · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Computer architecture, parallel and distributed computing, and storage systems
3 papers |
Cloud and datacenter computing · 47% Distributed systems · 38% Storage systems · 14% | |
| Network and information security
4 papers |
Hardware security and side channels · 55% Cryptographic protocols and secure computation · 20% Authentication and access control · 20% |
Topics — the 7 heaviest of 9, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Hardware security and side channels
trusted execution environments |
0.9 | 3 | 2025 | Varys: Protecting SGX Enclaves from Practical Side-Channel Attacks · USENIX ATC 2018 LibSEAL: revealing service integrity violations using trusted execution · EuroSys 2018 Understanding the Latency-Security Tradeoff: TEE-based Confidential Computing for Streaming Workloads · ICNP 2025 |
Cloud and datacenter computing › cloud security
confidential computing |
0.9 | 1 | 2025 | Understanding the Latency-Security Tradeoff: TEE-based Confidential Computing for Streaming Workloads · ICNP 2025 |
Distributed systems
stream processing |
0.9 | 1 | 2025 | Understanding the Latency-Security Tradeoff: TEE-based Confidential Computing for Streaming Workloads · ICNP 2025 |
Authentication and access control
access control |
0.3 | 1 | 2018 | Pesos: policy enhanced secure object store · EuroSys 2018 |
Storage systems
secure storage |
0.3 | 1 | 2018 | Pesos: policy enhanced secure object store · EuroSys 2018 |
Systems and software security › trusted computing
enclave security |
0.1 | 1 | 2018 | Varys: Protecting SGX Enclaves from Practical Side-Channel Attacks · USENIX ATC 2018 |
Cloud and datacenter computing › datacenter services
online service systems |
0.1 | 1 | 2018 | LibSEAL: revealing service integrity violations using trusted execution · EuroSys 2018 |
Methods — techniques the papers use, named apart from their topics
measurement · 1.7i/o mediation · 0.7declarative policy language · 0.7
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Understanding the Latency-Security Tradeoff: TEE-based Confidential Computing for Streaming WorkloadsabstractDistributed streaming platforms such as Pravega, Kafka, and Pulsar are widely used for high-throughput, low-latency data processing. As these platforms increasingly handle sensitive data, ensuring data confidentiality and integrity becomes critical. Trusted Execution Environments (TEEs) offer secure computations that can be used on client-side processing, but their impact on performance must be carefully assessed. This study evaluates the write latency of Pravega clients running in TEEs compared to those in standard (non-secured) environments. We found that under typical workloads, TEE-based clients experience approximately 50% higher latency due to the overhead of secure executions. However, when data rates exceed 976 MB/s, the Pravega broker reaches its throughput limit, causing latency to spike for standard clients. In contrast, TEE-based clients exhibit more stable latency under these high-throughput conditions. These findings can be helpful for data architects, as systems highlight a trade-off: while latency may increase, the impact could be acceptable in certain scenarios given the enhanced security benefits. Alan Cueva Mora, K. P. N. Jayasena, Robert Krahn, Enrique Chirivella-Perez, Christof Fetzer |
ICNP | 3 |
| 2023 | SinClave: Hardware-assisted Singletons for TEEsabstractFor trusted execution environments (TEEs), remote attestation permits establishing trust in software executed on a remote host. It requires that the measurement of a remote TEE is both complete and fresh: We need to measure all aspects that might determine the behavior of an application, and this measurement has to be reasonably fresh. Performing measurements only at the start of a TEE simplifies the attestation but enables "reuse" attacks of enclaves. We demonstrate how to perform such reuse attacks for different TEE frameworks. We also show how to address this issue by enforcing freshness -- through the concept of a singleton enclave -- and completeness of the measurements. Completeness of measurements is not trivial since the secrets provisioned to an enclave and the content of the filesystem can both affect the behavior of the software, i.e., can be used to mount reuse attacks. We present mechanisms to include measurements of these two components in the remote attestation. Our evaluation based on real-world applications shows that our approach incurs only negligible overhead ranging from 1.03% to 13.2%. Franz Gregor, Robert Krahn, Do Le Quoc, Christof Fetzer |
Middleware | 2 |
| 2021 | ADAM-CS: Advanced Asynchronous Monotonic Counter ServiceabstractTrusted execution environments (TEEs) offer the technological breakthrough to allow several applications to be deployed and executed over untrusted public cloud environments. Although TEEs (e. g., Intel SGX, ARM TrustZone, AMD SEV) provide several mechanisms to ensure confidentiality and integrity of data and code, they do not offer freshness out of the box, a critical aspect yet often overlooked, for instance, to protect against rollback attacks. Monotonic counters are a popular way to detect rollbacks, as their counter values cannot be decremented. However, counter increments are slow (i.e., 10thof milliseconds), making their use impractical for distributed services and applications processing thousands of transactions simultaneously, for which an order of magnitude improvement is needed. ADAM-CS is an asynchronous monotonic counter service to protect such high-traffic applications against rollback attacks. Leveraging a set of distributed monotonic counters and specific algorithms, ADAM-CS minimizes the maximum vulnerability window (MVW), i.e., the amount of transactions an adversary could successfully rollback. Thanks to its asynchronous nature, ADAM-CS supports thousands of increments per second without introducing additional latency in the transactions performed by applications. Our measurements indicate that we can keep the MVW well below 10ms while supporting a throughput of more than 21K requests/s when using eight counters. André Martin, Cong Lian, Franz Gregor, Robert Krahn, Valerio Schiavoni, Pascal Felber, Christof Fetzer |
DSN | 4 |
| 2020 | TEEMon: A continuous performance monitoring framework for TEEsabstractTrusted Execution Environments (TEEs), such as Intel Software Guard eXtensions (SGX), are considered as a promising approach to resolve security challenges in clouds. TEEs protect the confidentiality and integrity of application code and data even against privileged attackers with root and physical access by providing an isolated secure memory area, i.e., enclaves. The security guarantees are provided by the CPU, thus even if system software is compromised, the attacker can never access the enclave's content. While this approach ensures strong security guarantees for applications, it also introduces a considerable runtime overhead in part by the limited availability of protected memory (enclave page cache). Currently, only a limited number of performance measurement tools for TEE-based applications exist and none offer performance monitoring and analysis during runtime. Robert Krahn, Donald Dragoti, Franz Gregor, Do Le Quoc, Valerio Schiavoni, Pascal Felber, Clenimar Souza, Andrey Brito, Christof Fetzer |
Middleware | 1 |
| 2018 | LibSEAL: revealing service integrity violations using trusted executionabstractUsers of online services such as messaging, code hosting and collaborative document editing expect the services to uphold the integrity of their data. Despite providers' best efforts, data corruption still occurs, but at present service integrity violations are excluded from SLAs. For providers to include such violations as part of SLAs, the competing requirements of clients and providers must be satisfied. Clients need the ability to independently identify and prove service integrity violations to claim compensation. At the same time, providers must be able to refute spurious claims. Pierre-Louis Aublin, Florian Kelbert, Dan O'Keeffe, Divya Muthukumaran, Christian Priebe, Joshua Lind, Robert Krahn, Christof Fetzer, David M. Eyers, Peter R. Pietzuch |
EuroSys | 7 |
| 2018 | Pesos: policy enhanced secure object storeabstractThird-party storage services pose the risk of integrity and confidentiality violations as the current storage policy enforcement mechanisms are spread across many layers in the system stack. To mitigate these security vulnerabilities, we present the design and implementation of Pesos, a Policy Enhanced Secure Object Store (Pesos) for untrusted third-party storage providers. Pesos allows clients to specify per-object security policies, concisely and separately from the storage stack, and enforces these policies by securely mediating the I/O in the persistence layer through a single unified enforcement layer. More broadly, Pesos exposes a rich set of storage policies ensuring the integrity, confidentiality, and access accounting for data storage through a declarative policy language. Robert Krahn, Bohdan Trach, Anjo Vahldiek-Oberwagner, Thomas Knauth, Pramod Bhatotia, Christof Fetzer |
EuroSys | 1 |
| 2018 | PubSub-SGX: Exploiting Trusted Execution Environments for Privacy-Preserving Publish/Subscribe SystemsabstractThis paper presents PUBSUB-SGX, a content-based publish-subscribe system that exploits trusted execution environments (TEEs), such as Intel SGX, to guarantee confidentiality and integrity of data as well as anonymity and privacy of publishers and subscribers. We describe the technical details of our Python implementation, as well as the required system support introduced to deploy our system in a container-based runtime. Our evaluation results show that our approach is sound, while at the same time highlighting the performance and scalability trade-offs. In particular, by supporting just-in-time compilation inside of TEEs, Python programs inside of TEEs are in general faster than when executed natively using standard CPython. Sergei Arnautov, Andrey Brito, Pascal Felber, Christof Fetzer, Franz Gregor, Robert Krahn, Wojciech Ozga, André Martin, Valerio Schiavoni, Marcus Tenorio, Nikolaus Thummel |
SRDS | 6 |
| 2018 | Varys: Protecting SGX Enclaves from Practical Side-Channel Attacks
Oleksii Oleksenko, Bohdan Trach, Robert Krahn, Mark Silberstein, Christof Fetzer |
USENIX ATC | 3 |
| 2015 | The Ignite Distributed Collaborative Scientific Visualization SystemabstractWe describe the Ignite Distributed Collaborative Scientific Visualization System (IDCVS), a system which permits real-time interaction and visual collaboration around large data sets, with an initial emphasis on scientific data. The IDCVS offers such a collaborative environment, with real-time interaction on any device between users separated across the wide area. It provides seamless interaction and immediate updates even under heavy load and when users are widely separated: the design goal was to fetch a data set consisting of 30,000 points from a server and render it within 150ms, for a user anywhere in the world, and reflect changes made by a user in one location to all other users within a bound provided by network latency. The system was demonstrated successfully on a significant worldwide air pollution data set, with values on 10, 25, 50, and 100km worldwide grids, monthly over an 18-year period. It was demonstrated on a wide variety of clients, including laptop, tablet, and smartphone. Sushil Bhojwani, Matt Hemmings, Daniel H. H. Ingalls, Jens Lincke, Robert Krahn, David John Lary, Patrick C. McGeer, Glenn Ricart, Marko Röder, Yvonne Coady, Ulrike Stege |
CloudCom | 5 |
| 2014 | Babelsberg/JS - A Browser-Based Implementation of an Object Constraint Language
Tim Felgentreff, Alan Borning, Robert Hirschfeld, Jens Lincke, Yoshiki Ohshima, Bert Freudenberg, Robert Krahn |
ECOOP | 7 |
| 2010 | The SOM family: virtual machines for teaching and researchabstractThis paper introduces the SOM (Simple Object Machine) family of virtual machine (VM) implementations, a collection of VMs for the same Smalltalk dialect addressing students at different levels of expertise. Starting from a Java-based implementation, several ports of the VM to different programming languages have been developed and put to successful use in teaching at both undergraduate and graduate levels since 2006. Moreover, the VMs have been used in various research projects. The paper documents the rationale behind each of the SOM VMs and results that have been achieved in teaching and research. Michael Haupt 0003, Robert Hirschfeld, Tobias Pape, Gregor Berg, Stefan Marr, Arne Bergmann, Arvid Heise, Matthias Kleine, Robert Krahn |
ITiCSE | 9 |
| 2010 | Continuous Selective Testing
Bastian Steinert, Michael Haupt 0003, Robert Krahn, Robert Hirschfeld |
XP | 3 |