EDBT 2026 Demo / reviewers in the wild / expert
Wolfgang Hommel
dblp:50/6329
· DBLP profile ↗
25ranked-venue papers
1as first author
14since 2021 · last 2025
0000-0002-1013-7284ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 7 since 2021Computer networks · 6 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | How to Get Rid of Blockchain in Distributed Information SystemsabstractDistributed information systems often use the blockchain to enable verifiable data exchange, though its full functionality, especially persistent block history, is often unnecessary. This paper investigates lightweight, event-driven communication protocols for large-scale IS networks requiring predictable update frequency and proposes an optimized approach. The use-case scenario for this is based on interconnected identity providers. Building on gossip-based and peer-to-peer techniques, we define and evaluate four variants, including neighbor-based and fallback strategies, without relying on a full blockchain infrastructure. A custom simulation framework was developed to analyze message propagation, redundancy, delay, and network load across networks of up to 10,000 nodes. Results show that targeted event-driven protocols can significantly reduce overhead while maintaining high reliability, offering a scalable alternative for decentralized or distributed information system communication. Michael Hofmeier, Michael Grabatin, Wolfgang Hommel |
IPCCC | 3 |
| 2025 | Designing a security incident response process for self-sovereign identitiesabstractAbstract While self-sovereign identities (SSI) have been gaining more traction, the topic of SSI security has yet to be addressed. Especially regarding response procedures to security incidents, no prior work is available. However, incident response processes are essential to systematically respond to a security incident in a timely manner. We first evaluate the current state-of-the-art by conducting a literature survey and contacting organizations that offer SSI. The insights underpin the subject’s relevance, highlighting that incident response capabilities are just starting to be developed. Contributing to this development, we identify the challenges of building a security incident response process for SSI. Mainly, the decentralized nature inhibits the utilization of known best practices, which all focus on building a centralized incident response capability. However, even in the case of SSI, some centralized entities may exist. Therefore, we design two variants of SIR processes: one more centralized and one more decentralized. For the latter, the problem size is reduced in the first step by identifying all the stakeholders within an SSI ecosystem and then analyzing possible proactive and reactive measures each participant can access. This procedure leads to the grouping of SSI system participants into three distinct domains of incident response. For each domain, different capabilities for handling incidents are introduced depending on the involved stakeholders, their infrastructure, and their goals. To demonstrate the procedures, incident scenarios for each domain highlight the workflows during incident handling. Leonhard Ziegler, Michael Grabatin, Daniela Pöhn, Wolfgang Hommel |
EURASIP J. Inf. Secur. | 4 |
| 2024 | DistIN: Analysis and Validation of a Concept and Protocol for Distributed Identity Information NetworksabstractIdentity management enables users to access services around the globe. The user information is managed in some sort of identity management system. With the proposed shift to self-sovereign identities, self-sovereign control is shifted to the individual user. However, this also includes responsibilities, for example, in case of incidents. This is the case although they typically do not have the capability to do so. In order to provide users with more control and less responsibilities, we unite identity management systems with public key infrastructures. This consolidation allows more flexible and customized trust relationships to be created and validated. This paper explains, analyzes, and validates our novel design for a Distributed Identity Information Network (DistIN) that allows a high degree of decentralization while aiming for high security, privacy, usability, scalability, and sovereignty. The primary advantage of the system lies in its flexibility and ease of use, which also enables smaller organizations or even private individuals to participate in the network with a service. This work compiles categorized requirements from the literature and analyzes the verification and authentication data flows. On this basis, the security analysis and validation are following. This work is an essential step to reach the goal of the final web-based DistIN protocol and application. Michael Hofmeier, Daniela Pöhn, Wolfgang Hommel |
ARES | 3 |
| 2024 | Lowcaf: A Low-Code Protocol Analysis FrameworkabstractEvaluating a communication protocol’s design in terms of compliance and security is a very complex and time-consuming task. It requires the configuration of suitable test environments and test scenarios as well as the evaluation of procedures and handling of network traffic. A plethora of tools and frameworks exist that tackle individual problems of low-level networking but they usually presume robust programming skills and lack visualization. In contrast we propose an approach, derived from node-based processing systems, that conveys a clear logical picture that is still flexible and extensible enough to be adaptable to real-time processing or simulation of arbitrary networking components. In this paper, we present the concept for a visually programmable low-code communication protocol analysis framework (Lowcaf) that can be used either stand-alone to simulate network components or be used together with arbitrary backends. We also showcase our prototypical implementation of this framework and how it can be combined with the popular deterministic network simulator ns-3. Alexander Frank, Michael Steinke, Wolfgang Hommel |
CNSM | 3 |
| 2024 | Protecting Digital Identity Wallet: A Threat Model in the Age of eIDAS 2.0
Amir Sharif, Zahra Ebadi Ansaroudi, Giada Sciarretta, Daniela Pöhn, Majid Mollaeefar, Wolfgang Hommel, Silvio Ranise |
CRiSIS | 6 |
| 2024 | Web-Based Protocol Enabling Distributed Identity Information Networks for Greater Sovereignty
Michael Hofmeier, Karl Seidenfad, Manfred Hofmeier, Wolfgang Hommel |
I4CS | 4 |
| 2023 | TASEP: A Collaborative Social Engineering Tabletop Role-Playing Game to Prevent Successful Social Engineering AttacksabstractData breaches resulting from targeted attacks against organizations, e. g., by advanced persistent threat groups, often involve social engineering (SE) as the initial attack vector before malicious software is used, e. g., for persistence, lateral movement, and data exfiltration. While technical security controls, such as the automated detection of phishing emails, can contribute to mitigating SE risks, raising awareness for SE attacks through education and motivation of personnel is an important building block to increasing an organization’s resilience. To facilitate hands-on SE awareness training as one component of broader SE awareness campaigns, we created a SE tabletop game called Tabletop As Social Engineering Prevention (TASEP) in two editions for (a) small and medium enterprises and (b) large corporations, respectively. Its game design is inspired by Dungeons & Dragons role-playing games and facilitates LEGO models of the in-game target organizations. Participants switch roles by playing a group of SE penetration testers and conducting a security audit guided by the game master. We evaluated the created game with different student groups, achieving highly immersive and flexible training, resulting in an entertaining way of learning about SE and raising awareness. Lukas Hafner, Florian Wutz, Daniela Pöhn, Wolfgang Hommel |
ARES | 4 |
| 2023 | Needle in the Haystack: Analyzing the Right of Access According to GDPR Article 15 Five Years after the ImplementationabstractThe General Data Protection Regulation (GDPR) was implemented in 2018 to strengthen and harmonize the data protection of individuals within the European Union. One key aspect is Article 15, which gives individuals the right to access their personal data in an understandable format. Organizations offering services to Europeans had five years’ time to optimize their processes and functions to comply with Article 15. This study aims to explore the process of submitting and receiving the responses of organizations to GDPR Article 15 requests. A quantitative analysis obtains data from various websites to understand the level of conformity, the data received, and the challenges faced by individuals who request their data. The study differentiates organizations operating worldwide and in Germany, browser website- and app-based usage, and different types of websites. Thereby, we conclude that some websites still compile the data manually, resulting in longer waiting times. A few exceptions did not respond with any data or deliver machine-readable data (GDRP Article 20). The findings of the study additionally reveal ten patterns individuals face when requesting and accessing their data. Daniela Pöhn, Niklas Mörsdorf, Wolfgang Hommel |
ARES | 3 |
| 2023 | Enabling the JSON Web Signature Format to Support Complex and Identity-Oriented Non-web Processes
Michael Hofmeier, Wolfgang Hommel |
I4CS | 2 |
| 2023 | An Intermediary Protocol Representation to Aid in Avionics Network DevelopmentabstractComplex networked systems like aircraft or unmanned aerial vehicles (UAVs) often employ purpose-built network protocols. To eliminate design or implementation errors, general-purpose and domain-specific simulation/analysis tools are used. For newly developed protocols, these require dedicated configuration posing another source of errors and being cumbersome due to tool-specific protocol representations.As a first step towards alleviating this problem, we propose an Intermediary Protocol Representation (InPR) that can be generated programmatically, i.e., from existing machine-readable protocol specifications. An InPR can serve as the single basis for generating protocol specifications for other analysis tools, reducing the recurring implementation overhead.For demonstration purposes, we design and implement an InPR for protocols appearing in the aerospace industry and showcase how it can drive certain analysis tasks by itself or by generating configurations for other analysis tools. Alexander Frank, Wolfgang Hommel, Benedikt Hopfner |
NOMS | 2 |
| 2022 | TaxIdMA: Towards a Taxonomy for Attacks related to IdentitiesabstractIdentity management refers to the technology and policies for the identification, authentication, and authorization of users in computer networks. Identity management is therefore fundamental to today’s IT ecosystem. At the same time, identity management systems, where digital identities are managed, pose an attractive target for attacks. With the heterogeneity of identity management systems, every type (i. e., models, protocols, implementations) has different requirements, typical problems, and hence attack vectors. In order to provide a systematic and categorized overview, the framework Taxonomy for Identity Management Attacks (TaxIdMA) for attacks related to identities is proposed. The purpose of this framework is to classify existing attacks associated with system identities, identity management systems, and end-user identities as well as the background using an extensible structure from a scientific perspective. The taxonomy is then evaluated with eight real-world attacks resp. vulnerabilities. This analysis shows the capability of the proposed taxonomy framework TaxIdMA in describing and categorizing these attacks. Daniela Pöhn, Wolfgang Hommel |
ARES | 2 |
| 2021 | Field Studies on the Impact of Cryptographic Signatures and Encryption on Phishing Emails
Stefanie Pham, Matthias Schopp, Lars Stiemert, Sebastian Seeber, Daniela Pöhn, Wolfgang Hommel |
ICISSP | 6 |
| 2021 | Self-sovereign Identity Management in Wireless Ad Hoc Mesh Networks
Michael Grabatin, Wolfgang Hommel |
IM | 2 |
| 2021 | FEDCON: An embeddable Framework for Managing MOC Functions and Interfaces in Federated Software Networks
Michael Steinke, Wolfgang Hommel |
IM | 2 |
| 2020 | An overview of limitations and approaches in identity managementabstractIdentity and access management (I&AM) is the umbrella term for managing users and their permissions. It is required for users to access different services. These services can either be provided from their home organization, like a company or university, or from external service providers, e. g., cooperation partners. I&AM provides the management of identifiers with the attributes, credentials, roles, and permissions the user has. Today, the requirements have evolved from simply accessing individual web services in the internet or at a company to the majority of all IT services from different service providers with various accounts. Several identity management models have been created with different approaches within. Daniela Pöhn, Wolfgang Hommel |
ARES | 2 |
| 2018 | A Process Framework for Stakeholder-specific Visualization of Security MetricsabstractAwareness and knowledge management are key components to achieve a high level of information security in organizations. However, practical evidence suggests that there are significant discrepancies between the typical elements of security awareness campaigns, the decisions made and goals set by top-level management, and routine operations carried out by systems administration personnel. This paper presents Vis4Sec, a process framework for the generation and distribution of stakeholder-specific visualizations of security metrics, which assists in closing the gap between theoretical and practical information security by respecting the different points of view of the involved security report audiences. An implementation for patch management on Linux servers, deployed at a large data center, is used as a running example. Tanja Hanauer, Wolfgang Hommel, Stefan Metzger, Daniela Pöhn |
ARES | 2 |
| 2018 | Overcoming Network and Security Management Platform Gaps in Federated Software Networks
Michael Steinke, Wolfgang Hommel |
CNSM | 2 |
| 2018 | Reliability and scalability improvements to identity federations by managing SAML metadata with distributed ledger technologyabstractIn identity federations, users assigned to identity providers (IDPs) can access applications operated by service providers (SPs) without SP-specific credentials for authentication and authorization. While OpenID Connect and SAML are the two most widely adopted federation standards, using them inherently results in a trade-off between data quality guarantees and scalability, given how they handle the Metadata about the involved IDPs and SPs. This paper presents a novel approach for federation membership and federation Metadata management based on Distributed Ledger Technology. It applies the core idea of Certificate Transparency, as known from Global-PKI certificate authorities for X.509v3 server certificates, to SAML federation Metadata; therefore, it achieves OpenID Connect's federation building flexibility without losing the significant advantages of traditional SAML federations. An implementation based on Hyperledger Fabric is used to evaluate typical use cases by measuring impacts on Metadata distribution latency and Metadata size, and to discuss the feasibility of the presented approach. Michael Grabatin, Wolfgang Hommel |
NOMS | 2 |
| 2018 | A data model for federated network and security management information exchange in inter-organizational IT service infrastructuresabstractOperating large-scale IT infrastructures and IT services necessitates the management of the involved devices (e. g., network components and servers) and applications. Recent advances and trends in technology, such as software-defined networking, network function virtualization, and distributed data centers render many established organization-wide management processes and tools almost useless: We argue that they must be significantly re-designed to profoundly address the specifics of the new technologies and operational procedures. In this paper, we present a common data model and inter-domain information exchange procedures for integrated network and security management; it is designed for dynamically instantiated IT services in federated, i. e., inter-organizational scenarios. First, we extend STIX and TAXII to generically support network and security event exchange; then we propose a complementary lightweight data model in favor of efficient data processing and correlation. We discuss our data model's application to four layers of abstraction - from single assets to federated services - along with their management activities and the information required to support them with management tools. An evaluation discusses the feasibility of our concept. Michael Steinke, Wolfgang Hommel |
NOMS | 2 |
| 2016 | POSTER: VUDEC: A Framework for Vulnerability Management in Decentralized Communication NetworksabstractVulnerability management, often used as a generic term for any organizational and technical security controls in the context of identifying, assessing, and mitigating security-relevant software and network weaknesses, has specific challenges in decentralized communication networks such as research and education networks operated by higher education institutions. While many large organizations perform professional vulnerability management and related activities, especially risk management, which are supported by commercial and open source software products, universities and other academic environments still often struggle with ad-hoc and scope-limited approaches due to often unclear responsibilities and a lack of suitable tool support. This poster presents VUDEC, an integrated vulnerability management framework tailored for the requirements of decentrally operated networks; besides organizational aspects of the vulnerability management process, its implementation supports, among other functionality, a highly distributed vulnerability scan architecture and full multi-tenancy capability. Michael Steinke, Stefan Metzger, Wolfgang Hommel |
CCS | 3 |
| 2014 | Géant-TrustBroker: Dynamic, Scalable Management of SAML-Based Inter-federation Authentication and Authorization Infrastructures
Daniela Pöhn, Stefan Metzger, Wolfgang Hommel |
SEC | 3 |
| 2013 | ICEMAN: An architecture for secure federated inter-cloud identity management
Gabi Dreo Rodosek, Mario Golling, Wolfgang Hommel, Frank Tietze |
IM | 3 |
| 2013 | MuSIC: An IT security architecture for inter-community clouds
Gabi Dreo Rodosek, Mario Golling, Wolfgang Hommel |
IM | 3 |
| 2008 | Using Policy-Based Management for Privacy-Enhancing Data Access and Usage Control in Grid EnvironmentsabstractPreventing the misuse of personally identifiable information and preserving user privacy are key issues in the management of IT services, especially when organizational borders are crossed. In this paper, we first present an analysis of the differences between grid environments and previous models of inter-organizational collaboration. Based on requirements derived thereof, we demonstrate how existing policy-based privacy management architectures can be extended to provide grid-specific functionality and can be integrated into existing infrastructures. Special emphasis is put on privacy policies which can be configured by users themselves, and distinguishing between the initial data access and the later data usage control phases. We also discuss the application of this approach to a XACML-based privacy management system. Wolfgang Hommel |
CCGRID | 1 |
| 2006 | Policy-based Service Provisioning and Dynamic Trust Management in Identity FederationsabstractIn Federated Identity Management (FIM), user administration is decentralized: Service Providers (SPs) can request information about the users from their respective Identity Providers (IDPs). The subsequent processing of this data with respect to service provisioning and various privacy aspects are open research issues. We first specify how SPs can use provider-wide and service-specific XACML policies to enforce the required quality for the data delivered by the IDPs. Then, we demonstrate how aspects of trust and reputation management can improve the dynamics of Identity Federations and enhance the end users' privacy. We also extend the identity-centric request-response model of today's FIM protocols by group queries and demonstrate their application. Finally, we introduce our prototype and its integration into the Shibboleth FIM software. Latifa Boursas, Wolfgang Hommel |
ICC | 2 |