EDBT 2026 Demo / reviewers in the wild / expert
Dominik Merli
dblp:67/9049
· DBLP profile ↗
10ranked-venue papers
0as first author
7since 2021 · last 2025
0000-0003-2310-5895ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 4 since 2021Systems, architecture and hardware · 4 · 3 since 2021Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Testbed and Software Architecture for Enhancing Security in Industrial Private 5G NetworksabstractIn the era of Industry 4.0, the growing need for secure and efficient communication systems has driven the development of fifth-generation (5G) networks characterized by extremely low latency, massive device connectivity and high data transfer speeds. However, the deployment of 5G networks presents significant security challenges, requiring advanced and robust solutions to counter increasingly sophisticated cyber threats. This paper proposes a testbed and software architecture to strengthen the security of Private 5G Networks, particularly in industrial communication environments. Song Son Ha, Florian Foerster, Thomas Robert Doebbert, Tim Kittel, Dominik Merli, Gerd Scholl |
ETFA | 5 |
| 2024 | Accuracy Evaluation of SBOM Tools for Web Applications and System-Level SoftwareabstractRecent vulnerabilities in software like Log4j raise the question whether the software supply chain is secured sufficiently. Governmental initiatives in the United States (US) and the European Union (EU) demand a Software Bill of Materials (SBOM) for solving this issue. An SBOM has to be produced by using creation tools and it has to be accurate and complete. In the past, there had been investigations in this field of research. However, no detailed investigation of several tools producing SBOMs has been conducted regarding accuracy and reliability. For this reason, we present a selection of four popular programming languages: Python, C, Rust and Typescript. For web application software we consider Python and Typescript while for system-level software C and Rust are investigated. They build the base for four sample software projects and their package manager. For manual checking, the software projects are kept small with a small amount of packages and a single dependency. The open-source analysis tools are categorized as programming language dependent and general tools, and run in the standard execution mode on the software projects. The results were checked against completeness and the National Telecommunications and Information Administration (NTIA) minimum and recommended elements. There is no recommendation for a specific tool as no tool fulfills every requirement, only two tools can be recommended in a limited way. Many tools do not provide a complete SBOM, as they do not depict every test package and dependency. Governmental initiatives should define further specifications on SBOM for example regarding their accuracy and depth. Further research in this field, for example for proprietary tools or other programming languages is desirable. Andreas Halbritter, Dominik Merli |
ARES | 2 |
| 2024 | Automating Side-Channel Testing for Embedded Systems: A Continuous Integration ApproachabstractSoftware testing is vital for strengthening the security of embedded systems by identifying and rectifying code errors, flaws and vulnerabilities. This is particularly significant when addressing vulnerabilities associated with side-channel attacks, given that they introduce a distinctive class of vulnerabilities, primarily subject to manual testing procedures. Manual testing remains prevalent despite advances in automation, posing challenges, particularly for complex environments. This research aims to automate embedded software testing on hardware in a modular and scalable manner, addressing the limitations of manual testing. We present a system designed to automate testing, including Side-Channel Analysis (SCA), in Continuous Integration (CI) environments, emphasizing accessibility and collaboration through open-source tools. Our evaluation setup based on GitLab, Jenkins and the ChipWhisperer framework shows that automating and integrating Side-Channel Analysis (SCA) in Continuous Integration (CI) environments is possible in an efficient way. Philipp Schloyer, Peter Knauer, Bernhard Bauer 0001, Dominik Merli |
ARES | 4 |
| 2024 | Safe and Secure? On the Timing Analysability of Cryptographic ImplementationsabstractHard real-time systems are increasingly vulnerable to cyberattacks. Since real-time systems represent a significant proportion of safety-critical systems not only established safety standards but also security standards have to be considered. In particular, standard cryptographic libraries are required to reach an adequate level of protection. In this study, we investigate whether it is possible to en-sure security and hard real-time without compromising either side. Thus, we examine relevant state-of-the-art cryptographic primitives provided by one of the de-facto standard libraries Mbed TLS, which is widely-used in embedded systems. We investigate the possibility to derive a Worst-Case Execution Time (WCET) for these primitives and review the code base with regard to compliance on safety-related coding guidelines. In addition, we assess the relevant aspects when security concerns must be considered in the safety-related context. Our research reveals several obstacles to fully apply Mbed TLS in hard real- time systems. Alexander Stegmeier, Peter Knauer, Philipp Schubaur, Christian Piatka, Dominik Merli, Sebastian Altmeyer |
RTAS | 5 |
| 2023 | FISMOS - An FPGA Implementation of a Security Module as Open SourceabstractMany IoT devices are trusted with critical tasks and therefore require solid device security. As a result, manufacturers search for cost-efficient and easy-to-integrate trust anchors, but common IT solutions, like a Trusted Platform Modules (TPMs) are often not suitable for Internet of Things (IoT) use cases. Simultaneously, the adoption of System on Chip (SoC) devices, integrating a set of ARM® cores and Programmable Logic (PL) within one package are on the rise in several industries. While the ARM® processors facilitate networking and graphical user interfaces, a Field Programmable Gate Array (FPGA) fabric enables real-time control or acceleration of AI applications on the edge. This paper presents a solution to combine these trends for the benefit of device security: an FPGA Implementation of a Security Module as Open Source (FISMOS). The security module focuses on simplicity, providing security capabilities by little expense of logic as well as engineering resources. FISMOS is based on the PicoRV32 soft-core processor and features an AXI memory interface for data exchange with its host. It enables secure symmetric and asymmetric cryptographic functions, key enclosure, and may serve as a trust anchor for the Linux kernel. This configuration allows for customized security functionalities and a robust segmentation between the encapsulated area of the FISMOS and the Linux OS. Philipp Schubaur, Peter Knauer, Dominik Merli |
ARES | 3 |
| 2022 | On the Security of IO-Link Wireless Communication in the Safety DomainabstractSecurity is an essential requirement of Industrial Control System (ICS) environments and its underlying communication infrastructure. Especially the lowest communication level within Supervisory Control and Data Acquisition (SCADA) systems - the field level - commonly lacks security measures.Since emerging wireless technologies within field level expose the lowest communication infrastructure towards potential attackers, additional security measures above the prevalent concept of air-gapped communication must be considered.Therefore, this work analyzes security aspects for the wireless communication protocol IO-Link Wireless (IOLW), which is commonly used for sensor and actuator field level communication. A possible architecture for an IOLW safety layer has already been presented recently [1].In this paper, the overall attack surface of IOLW within its typical environment is analyzed and attack preconditions are investigated to assess the effectiveness of different security measures. Additionally, enhanced security measures are evaluated for the communication systems and the results are summarized. Also, interference of security measures and functional safety principles within the communication are investigated, which do not necessarily complement one another but may also have contradictory requirements.This work is intended to discuss and propose enhancements of the IOLW standard with additional security considerations in future implementations. Thomas Robert Doebbert, Dominik Merli, Gerd Scholl |
ETFA | 3 |
| 2021 | A Secure Network Scanner Architecture for Asset Management in Strongly Segmented ICS Networks
Matthias Niedermaier, Thomas Hanka, Dominik Merli |
ICISSP | 4 |
| 2020 | Analysis of Industrial Device Architectures for Real-Time Operations Under Denial of Service Attacks
Matthias Niedermaier, Thomas Hanka, Peter Knauer, Dominik Merli |
ICICS | 5 |
| 2013 | Comprehensive analysis of software countermeasures against fault attacksabstractFault tolerant software against fault attacks constitutes an important class of countermeasures for embedded systems. In this work, we implemented and systematically analyzed a comprehensive set of 19 different strategies for software countermeasures with respect to protection effectiveness as well as time and memory efficiency. We evaluated the performance and security of all implementations by fault injections into a microcontroller simulator based on an ARM Cortex-M3. Our results show that some rather simple countermeasures outperform other more sophisticated methods due to their low memory and/or performance overhead. Further, combinations of countermeasures show strong characteristics and can lead to a high fault coverage, while keeping additional resources at a minimum. The results obtained in this study provide developers of secure software for embedded systems with a solid basis to decide on the right type of fault attack countermeasure for their application. Nikolaus Theißing, Dominik Merli, Michael Smola, Frederic Stumpf, Georg Sigl |
DATE | 2 |
| 2012 | Strengths and Limitations of High-Resolution Electromagnetic Field Measurements for Side-Channel Analysis
Johann Heyszl, Dominik Merli, Benedikt Heinz, Fabrizio De Santis, Georg Sigl |
CARDIS | 2 |