EDBT 2026 Demo / reviewers in the wild / expert
Stefan Rass
dblp:79/5181 · also Stefan Raß
· DBLP profile ↗
48ranked-venue papers
21as first author
19since 2021 · last 2026
0000-0003-2821-2489ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 27 · 12 first-author · 10 since 2021Computer networks · 5 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 2 since 2021Systems, architecture and hardware · 3 · 1 since 2021Software engineering, systems software and programming languages · 3 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-authorTheory of computation · 2 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Adversarial Distance Metrics: A Threat to Fairness in Clustering-Based Decision Systems
Shahzad Ahmad 0001, Stefan Rass, Enes Sovtic |
SECRYPT (1) | 2 |
| 2026 | Statistically testing training data for unwanted error patterns using rule-oriented regressionabstract• A method to detect biases in training data and de-poison it before training. • Examples of discovering biases and patterns in existing data sets. • Explainable AI via fuzzy reasoning combined with classical regression. • Using Boolean formulae to explain data, with statistical significance testing. • An open-source prototype implementation. Artificial intelligence (AI) models are only as good as the data they are trained on. Biases in training data can lead to biased outputs in machine learning models, a well-documented issue. However, methods to prevent these biases are less developed. Ensuring clean data during collection, such as using bias-aware sampling, is most effective when the entity collecting the data also trains the artificial intelligence (AI). When using pre-existing data, detecting if it has been manipulated or “poisoned” to induce undesired behavior in a model is challenging. We propose a method to test training data for flaws, establishing a trustworthy ground-truth for subsequent model training. Unlike methods that generate fuzzy rules from data, our approach defines rules before examining the data, allowing the discovery of hidden error patterns. Our method adds to statistical tests by inserting a flexible rule-checking phase that evaluates arbitrary user-defined, including fuzzy, data-pattern conditions beforehand. Those are then used as building blocks for regression models, using fuzzy inference inside. This enables explainability from fuzzy logic and statistical diagnostics from regression. Additionally, it is applicable to “small data,” not requiring large datasets like deep learning methods. We validate our method with an experimental open-source implementation, using real-life and synthetic datasets to ensure practical relevance and procedure validation. Stefan Rass, Martin Dallinger |
Expert Syst. Appl. | 1 |
| 2026 | PRIDE: Privacy Through Deniability
Shahzad Ahmad 0001, Stefan Rass |
IEEE Internet Things J. | 2 |
| 2026 | On Mixing of Quantum Key Distribution and Post-Quantum Cryptographic Keys: Min-Entropy Bounds, Provisioning Policies, and Network-Oriented Trade-Offs
Miralem Mehic, Stefan Rass, Sergej Jakovlev, Marcin Niemiec, Peppino Fazio, Miroslav Voznak |
IEEE J. Sel. Areas Commun. | 2 |
| 2025 | Robust Distributed Fractional-Order Dynamic Output Feedback for Limited-Time Consensus Control in Multi-Agent SystemsabstractThis paper presents a new approach to tackling one of the intricate challenges of consensus control in distributed systems, specifically targeting the stabilization of fractional-order outputs in linear fractional-order multi-agent systems. We introduce an innovative distributed feedback control strategy that leverages dynamic output feedback to stabilize the closed-loop system. By refining the H2robust control method, the controller and observer gains are precisely determined through an eigenvalue-based optimization process. The effectiveness and robustness of the proposed methodology are validated through simulations, with graphical results illustrating enhanced system performance and stability. Mohammad Fiuzy, Stefan Rass |
CoDIT | 2 |
| 2025 | Distributed Observer-Based Control for Consensus in Nonlinear Fractional-Order Multi-Agent SystemsabstractThe consensus problem among agents has long intrigued researchers in the field of coordination control. This study investigates a nonlinear fractional-order system with 0 < α < 1. A controller based on distributed observers is designed to assist agents in achieving consensus within a multi-agent nonlinear fractional-order system. The primary strategy for addressing the nonlinear term involves feedback linearization. The controller is developed with a stability proof, and the resulting observer-based controller is applied to an example of a nonlinear fractional-order multi-agent system. Additionally, a nonlinear example is solved analytically in this context. The estimation error is thoroughly analyzed, demonstrating notable convergence to zero based on the Lyapunov stability synthesis. Mohammad Fiuzy, Stefan Rass |
CoDIT | 2 |
| 2025 | Control Flow Protection by Cryptographic Instruction Chaining
Shahzad Ahmad 0001, Stefan Rass, Maksim Goman, Manfred Schlägl, Daniel Große |
SECRYPT | 2 |
| 2025 | Post-Quantum Cryptography for Secure Authentication Key Distribution in QKD NetworksabstractThis paper presents a vendor-agnostic architecture for secure pre-shared key (PSK) exchange between Quantum Key Distribution (QKD) nodes, leveraging post-quantum cryptography (PQC) tools. The proposed system combines PQC-OpenVPN and OQS-OpenSSH with USB mass storage emulation and single-board computers (SBCs) to automate the transfer of initial authentication secrets. This design significantly reduces manual intervention and mitigates risks associated with physical key handling. The solution was experimentally validated on IDQ Clavis3 and Cerberis3 devices and is broadly applicable to other QKD platforms that support only USB-based key input. Integration of lattice-based algorithms such as Kyber, Dilithium, and ML-DSA enables encapsulation and authentication of quantum-safe keys. Furthermore, a layered design using VPN and SSH channels provides robust cryptographic isolation for authentication material in transit. The work contributes a reproducible and cost-effective testbed for post-quantum hardened QKD deployments and demonstrates the practical feasibility of combining PQC mechanisms with QKD systems to enhance trust in future quantum-safe infrastructures. Filip Lauterbach, Lukas Kapicak, Sergej Jakovlev, Miralem Mehic, Stefan Rass, Miroslav Voznak |
TrustCom | 5 |
| 2024 | RobotPerf: An Open-Source, Vendor-Agnostic, Benchmarking Suite for Evaluating Robotics Computing System PerformanceabstractWe introduce RobotPerf, a vendor-agnostic bench-marking suite designed to evaluate robotics computing performance across a diverse range of hardware platforms using ROS 2 as its common baseline. The suite encompasses ROS 2 packages covering the full robotics pipeline and integrates two distinct benchmarking approaches: black-box testing, which measures performance by eliminating upper layers and replacing them with a test application, and grey-box testing, an application-specific measure that observes internal system states with minimal interference. Our benchmarking framework provides ready-to-use tools and is easily adaptable for the assessment of custom ROS 2 computational graphs. Drawing from the knowledge of leading robot architects and system architecture experts, RobotPerf establishes a standardized approach to robotics benchmarking. As an open-source initiative, RobotPerf remains committed to evolving with community input to advance the future of hardware-accelerated robotics. Victor Mayoral Vilches, Jason Jabbour, Yu-Shun Hsiao, Zishen Wan, Martiño Crespo-Álvarez, Matthew Stewart, Juan Manuel Reina-Muñoz, Prateek Nagras, Gaurav Vikhe, Mohammad Bakhshalipour, Martin Pinzger 0001, Stefan Rass, Smruti Panigrahi, Giulio Corradi, Niladri Roy, Phillip B. Gibbons, Sabrina M. Neuman, Brian Plancher, Vijay Janapa Reddi |
ICRA | 12 |
| 2024 | Honeyquest: Rapidly Measuring the Enticingness of Cyber Deception Techniques with Code-based QuestionnairesabstractFooling adversaries with traps such as honeytokens can slow down cyber attacks and create strong indicators of compromise. Unfortunately, cyber deception techniques are often poorly specified. Also, realistically measuring their effectiveness requires a well-exposed software system together with a production-ready implementation of these techniques. This makes rapid prototyping challenging. Our work translates 13 previously researched and 12 self-defined techniques into a high-level, machine-readable specification. Our open-source tool, Honeyquest, allows researchers to quickly evaluate the enticingness of deception techniques without implementing them. We test the enticingness of 25 cyber deception techniques and 19 true security risks in an experiment with 47 humans. We successfully replicate the goals of previous work with many consistent findings, but without a time-consuming implementation of these techniques on real computer systems. We provide valuable insights for the design of enticing deception and also show that the presence of cyber deception can significantly reduce the risk that adversaries will find a true security risk by about 22% on average. Mario Kahlhofer, Stefan Achleitner, Stefan Rass, René Mayrhofer |
RAID | 3 |
| 2024 | PentestGPT: Evaluating and Harnessing Large Language Models for Automated Penetration Testing
Gelei Deng, Yi Liu 0069, Victor Mayoral Vilches, Yuekang Li, Yuan Xu 0033, Martin Pinzger 0001, Stefan Rass, Tianwei Zhang 0004, Yang Liu 0003 |
USENIX Security Symposium | 8 |
| 2024 | Tell me who you are friends with and I will tell you who you are: Unique neighborhoods in random graphsabstractThe identity of a physical entity in a network is traditionally defined by some secret knowledge, personal possession, or (biometric) property. What if no such unique property exists or can be defined “safely”, for example, in the interest of anonymity? In this work, we study the problem of defining an identity for an entity u under the constraint that there is no subjective property that u carries by itself, or in other words, any property that u has, may also be likewise present in another entity v. In the absence of an intrinsic property of u to define its identity, we thus consider the possibility of an “extrinsically defined identity” via the connections that u maintains to other entities. Letting u∈V be part of a graph G=(V,E), we study the question of whether the links that u has to its neighbors lend themselves to uniquely distinguish u from all other nodes v in the graph. A practical instance of this setting appears in symmetric cryptography, if we assume an edge between two nodes u,v if and only if u and v share a common secret. A single shared secret known by u is, in symmetric cryptography, also known to some other entity v. However, is the set of all secrets that u has likewise known to another node v in a network? If not, we can implement end-to-end authentication without shared secrets and exclusively using symmetric cryptography. This concept is here reviewed as peer-authentication. It works in a graph class that we call Unique-Neighborhood Network (UNN), which has been introduced in prior literature for the purpose of emulating public-key digital signatures with symmetric cryptography only. Our findings suggest that some networks naturally grow into UNNs, but even if not, we can efficiently identify substructures that allow to pin down a node's identity based on its “friend-nodes” in a graph. Stefan Rass |
Theor. Comput. Sci. | 1 |
| 2024 | Threshold samplingabstractWe consider the problem of sampling elements with some desired property from a large set, without testing the property of interest, but with the (probabilistic) assurance to have at least one match among the random sample. Like in ranked set sampling (RSS), we consider an infinite population under study, whose properties of interest are too expensive and/or time-consuming to measure. Unlike RSS, we are void of a ranking mechanism, so our sampling is done entirely blind. We show how it is nonetheless doable to assure, with controllably large likelihood, to either have at least one of the interesting elements in a random sample, or, contrarily, sample with the likewise assurance of not having one of the interesting elements in the sample. Our technique utilizes density bounds for distributions and threshold functions from random graph theory. • Algorithm for sampling elements of a set with a desired property, but without ever testing this property. • Construction of a formal language that is poly-time “sampleable” in the above respect. • Provides a new algorithmic application of threshold functions from random graph theory. • Has possible applications for the construction of “hard” problems for cryptography. Stefan Rass, Max-Julian Jakobitsch, Stefan Haan, Moritz Hiebler |
Theor. Comput. Sci. | 1 |
| 2024 | Metricizing the Euclidean Space Toward Desired Distance Relations in Point CloudsabstractWe introduce the concept of an$\varepsilon $-semimetric that satisfies the same axioms as a topological metric, except for an arbitrarily small allowance to violate the triangle inequality. Under this modification, we demonstrate the possibility of taking arbitrary points in space, assigning arbitrary desired distances between them (independent of their geometric location relative to each other, that is, independent of their “features”), and constructing an$\varepsilon $-semimetric that measures exactly the desired distances in the point cloud. This results in a threat to fairness and objectiveness in applications of clustering algorithms: suppose that an adversary subjectively classifies people according to its whim or discriminatory preferences. Upon accusations of unethical behavior, the malicious data processor can plausibly deny these as follows: it designs a distance function (an$\varepsilon $-semimetric) that is (up to a fully controllable numeric “round-off-error”$\varepsilon $) equivalent to a standard distance like the Euclidean. However, this crafted distance will exactly reproduce the (malicious) results and thus confirm them while pretending objectivity and transparency, since only standard and explainable artificial intelligence was used. This demonstration works without any data poisoning. We illustrate the method on randomly chosen points with stochastically independent random classifications assigned to them. Then, we apply standard implementations of k-Means and DBSCAN on the data points, which both exactly reproduce the desired (randomly chosen) classes. We also discuss non-adversarial applications of$\varepsilon $-semimetrics, and corroborate the construction with examples and implementation in Octave. Stefan Rass, Sandra König, Shahzad Ahmad 0001, Maksim Goman |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Anonymously Publishing Liveness Signals with Plausible Deniability
Michael Sonntag, René Mayrhofer, Stefan Rass |
MoMM | 3 |
| 2023 | How to Plausibly Deny Steganographic Secrets
Shahzad Ahmad 0001, Stefan Rass |
SECRYPT | 2 |
| 2023 | Game-theoretic APT defense: An experimental study on roboticsabstractThis paper proposes a novel game-theoretic framework for defending against Advanced Persistent Threats (APTs). It applies the original Cut-The-Rope model into an experimental study extending the previously studied attacker movements beyond the Poisson distribution to a realistic set of attack actions. More importantly, it demonstrates the value of this framework on an experimental study of an APT defense game on attack graphs, which lets a security officer establish an optimized defense policy against stealthy intrusions. The security model and algorithm under study is designed for practical use with attack graphs as threat models, possibly including vulnerability information if available. The game-theoretic optimization delivers a proactive defense policy under the following assumptions or requirements: first, we do not need to assume that the system is, or has been, clean from adversaries at any time. At the moment when the defender computes the defense policy, the attacker is assumed to already be in the system (also having penetrated it until an unknown depth). Second, the defender does not rely on any signaling or other indicators of adversarial activity, nor is there a reliable feedback mechanism to tell the defender if its actions were successful or not. Third, the model can use information on exploits, such as Common Vulnerabilities and Exposures (CVE) numbers, to refine the defense game, but can also operate without such information. We corroborate our findings on publicly documented attack graphs from the robotics domain; without and with CVE information. We run experiments against two different types of defense regimes, and compare the results against an intuitive baseline defense heuristic. The results show that the optimized defense strongly outperforms simple heuristics, like taking the shortest or easiest attack paths. Stefan Rass, Sandra König, Jasmin Wachter, Victor Mayoral Vilches, Emmanouil A. Panaousis |
Comput. Secur. | 1 |
| 2022 | Supervised Machine Learning with Plausible Deniability
Stefan Rass, Sandra König, Jasmin Wachter, Manuel Egger, Manuel Hobisch |
Comput. Secur. | 1 |
| 2021 | Multi-categorical Risk Assessment for Urban Critical Infrastructures
Sandra König, Stefan Schauer, Stefan Rass |
CRITIS | 3 |
| 2020 | IT-Application Behaviour Analysis: Predicting Critical System States on OpenStack using Monitoring Performance Data and Log Files
Patrick Kubiak, Stefan Rass, Martin Pinzger 0001 |
ICSOFT | 2 |
| 2020 | Computer & security special issue editorial
Stefan Rass, Quanyan Zhu |
Comput. Secur. | 1 |
| 2020 | synERGY: Cross-correlation of operational and contextual data to timely detect and mitigate attacks to cyber-physical systems
Florian Skopik, Max Landauer, Markus Wurzenberger, Gernot Vormayr, Jelena Milosevic, Joachim Fabini, Wolfgang Prüggler, Oskar Kruschitz, Benjamin Widmann, Kevin Truckenthanner, Stefan Rass, Michael Simmer, Christoph Zauner |
J. Inf. Secur. Appl. | 11 |
| 2020 | A Novel Approach to Quality-of-Service Provisioning in Trusted Relay Quantum Key Distribution NetworksabstractIn recent years, noticeable progress has been made in the development of quantum equipment, reflected through the number of successful demonstrations of Quantum Key Distribution (QKD) technology. Although they showcase the great achievements of QKD, many practical difficulties still need to be resolved. Inspired by the significant similarity between mobile ad-hoc networks and QKD technology, we propose a novel quality of service (QoS) model including new metrics for determining the states of public and quantum channels as well as a comprehensive metric of the QKD link. We also propose a novel routing protocol to achieve high-level scalability and minimize consumption of cryptographic keys. Given the limited mobility of nodes in QKD networks, our routing protocol uses the geographical distance and calculated link states to determine the optimal route. It also benefits from a caching mechanism and detection of returning loops to provide effective forwarding while minimizing key consumption and achieving the desired utilization of network links. Simulation results are presented to demonstrate the validity and accuracy of the proposed solutions. Miralem Mehic, Peppino Fazio, Stefan Rass, Oliver Maurhart, Momtchil Peev, Andreas Poppe, Jan Rozhon, Marcin Niemiec, Miroslav Voznak |
IEEE/ACM Trans. Netw. | 3 |
| 2019 | Estimating Cascading Effects in Cyber-Physical Critical Infrastructures
Stefan Schauer, Thomas Grafenauer, Sandra König, Manuel Warum, Stefan Rass |
CRITIS | 5 |
| 2018 | A Simulation Tool for Cascading Effects in Interdependent Critical InfrastructuresabstractCritical infrastructures are a core part in modern society, supplying essential goods and services for our everyday life. Therefore, any incident compromising the operation of a critical infrastructure can directly affect the social life. Moreover, due to the increasing interconnections between critical infrastructures, any incident can have cascading effects on other infrastructures as well. In this article, we present a novel simulation framework which allows to model the interdependencies and thus also the cascading effects among critical infrastructures. This framework builds upon stochastic processes describing, on the one hand, the relations between the critical infrastructures and, on the other hand, the random and sometimes arbitrary propagation of the consequences. This existing framework is extended and implemented in OMNeT++, which allows an easy and swift implementation of the mathematical algorithms and also provides a built-in visualization of the propagation of consequences within the critical infrastructure network. The goal is to support risk and security officers within the critical infrastructure in their decisions. Thomas Grafenauer, Sandra König, Stefan Rass, Stefan Schauer |
ARES | 3 |
| 2018 | Game Theory Meets Network Security: A TutorialabstractThe increasingly pervasive connectivity of today's information systems brings up new challenges to security. Traditional security has accomplished a long way toward protecting well-defined goals such as confidentiality, integrity, availability, and authenticity. However, with the growing sophistication of the attacks and the complexity of the system, the protection using traditional methods could be cost-prohibitive. A new perspective and a new theoretical foundation are needed to understand security from a strategic and decision-making perspective. Game theory provides a natural framework to capture the adversarial and defensive interactions between an attacker and a defender. It provides a quantitative assessment of security, prediction of security outcomes, and a mechanism design tool that can enable security-by-design and reverse the attacker's advantage. This tutorial provides an overview of diverse methodologies from game theory that includes games of incomplete information, dynamic games, mechanism design theory to offer a modern theoretic underpinning of a science of cybersecurity. The tutorial will also discuss open problems and research challenges that the CCS community can address and contribute with an objective to build a multidisciplinary bridge between cybersecurity, economics, game and decision theory. Quanyan Zhu, Stefan Rass |
CCS | 2 |
| 2018 | A Measure for Resilience of Critical Infrastructures
Sandra König, Thomas Schaberreiter, Stefan Rass, Stefan Schauer |
CRITIS | 3 |
| 2016 | Application-level security for ROS-based applicationsabstractWhile the topic of security in industrial applications has gained some momentum in recent years, there are still severe security vulnerabilities which are actively exploited for attacks. The robot operating system (ROS) is expected to further grow in usage and to be used in many industrial applications. Analysis, however, shows that it lacks several security enhancements in order to make it suitable for industrial use. In its current state, false data and commands can be injected posing a possible safety risk for the resulting product and humans in the production. In addition, data may be eavesdropped and used by outsiders to gain insight into the production process. In this paper we propose a security architecture intended for use on top of ROS on the application level. We use a dedicated authorization server to ensure that only valid nodes are part of the application. Cryptographic methods ensure data confidentiality and integrity. We show in a demonstration with a collaborative robot how our architecture can be used to secure a ROS-based application. Bernhard Dieber, Severin Kacianka, Stefan Rass, Peter Schartner |
IROS | 3 |
| 2016 | Arguable anonymity from key-privacy: The deterministic crowds protocolabstractAnonymous communication is traditionally achieved by communication over a sequence of proxies so that the relation between the sender and receiver is obfuscated. Security of anonymization is usually understood as the inability to discover the initiator or receiver of a transmission. We introduce a different notion here, which defines anonymity as the inability to confirm a given guess about the initiator or receiver. We call this arguable anonymity, as it offers the suspect a way of plausible repudiation on grounds of the accusal being not independently verifiable. As a proof of concept, we introduce a deterministic version of Crowds that achieves this kind of anonymity. As a separate (and independent) contribution, the derandomizing of Crowds additionally achieves receiver anonymity to the protocol, based on key-privacy properties of an underlying encryption scheme. Stefan Rass, Raphael Wigoutschnigg |
NOMS | 1 |
| 2016 | Modelling security risk in critical utilities: The system at risk as a three player game and agent societyabstractIt becomes essential when reasoning about the security risks to critical utilities such electrical power and water distribution to recognize that the interests of producers and consumers do not fully coincide. They may have incentives to behave strategically towards each other, as well as toward some third party adversary. We therefore argue for the need to extend the prior literature, which has concentrated on the strategic, adaptive game between adversary and defender, towards 3-player games. But it becomes hard to justify modelling a population of consumers as a single, decision making actor. So we also show how we can model consumers as a group of mutually-influencing, yet not centrally co-ordinated, heterogeneous agents. And we suggest how this representation can be integrated into a game-theoretic framework. This requires a framework in which payoffs are known by the players only stochastically. We present some basic models and demonstrate the nature of the modelling commitments that need to be made in order to reason about utilities' security risk. Jeremy Busby, Antonios Gouglidis, Stefan Rass, Sandra König |
SMC | 3 |
| 2015 | Side-Channel Leakage Models for RISC Instruction Set Architectures from Empirical DataabstractSide-channel attacks are currently among the most serious threats for embedded systems. Popular countermeasures to mitigate the impact of such attacks are masking schemes, where secret intermediate values are split in two or more values by virtue of secret sharing. Processing the secret happens on separate execution paths, which are executed on the same central processing unit (CPU). In case of unwanted correlations between different registers inside the CPU the shared secret may leak out through a side-channel. This problem is particularly evident on low cost embedded systems, such as nodes for the Internet of Things (IoT), where cryptographic algorithms are often implemented in pure software on a reduced instruction set computer (RISC). On such an architecture, all data manipulation operations are carried out on the contents of the CPU's register file. This means that all intermediate values of the cryptographic algorithm at some stage pass through the register file. Towards avoiding unwanted correlations and leakages thereof, special care has to be taken in the mapping of the registers to intermediate values of the algorithm. In this work, we describe an empirical study that reveals effects of unintended unmasking of masked intermediate values and thus leaking secret values. The observed phenomena are related to the leakage of masked hardware implementations caused by glitches in the combinatorial path of the circuit but the effects are abstracted to the level of the instruction set architecture on a RISC CPU. Furthermore, we discuss countermeasures to have the compiler thwart such leakages. Hermann Seuschek, Stefan Rass |
DSD | 2 |
| 2015 | Private function evaluation by local two-party computationabstractInformation processing services are becoming increasingly pervasive, such as is demonstrated by the Internet of Things or smart grids. Given the importance that these services have reached in our daily life, the demand for security and privacy in the data processing appears equally large. Preserving the privacy of data during its processing is a challenging issue that has led to ingenious new cryptographic solutions, such as fully homomorphic encryption (to name only one). An optimal cryptographic support for private data processing must in any case be scalable and lightweight. To this end, we discuss the application of standard (off-the-shelf) cryptography to enable the computation of any function under permanent disguise (encryption). Using a local form of multiparty computation (essentially in a non-distributed fashion), we show how to execute any data processing algorithm in complete privacy. Our solution can, for example, be used with smart grid equipment, when small hardware security modules are locally available (such as in smart meters). Stefan Rass, Peter Schartner, Monika Brodbeck |
EURASIP J. Inf. Secur. | 1 |
| 2015 | Secure Communication over Software-Defined Networks
Stefan Rass, Benjamin Rainer, Matthias Vavti, Johannes Göllner, Andreas Peer, Stefan Schauer |
Mob. Networks Appl. | 1 |
| 2013 | Shared Crowds: A Token-Ring Approach to Hide the ReceiverabstractBecause of the intensive usage of the internet and services provided over the world wide web, the privacy of the users is threatened by various attacks. This paper shows how to build a protocol for anonymous data transmission, with the primary focus on hiding the identity of the receiver (receiver anonymity), using multi path transmission and secret sharing. This protocol extends the crowds system by Reiter and Rubin, which only weakly hides the identity of the receiver. Due to the use of a circular channel topology the receiver is hidden even if timing attacks are mounted. Additionally this protocol gives the participating nodes the possibility to detect active attacks during the channel setup phase. Another positive aspect is the ability to handle some kind of node failures by repairing the virtual channel. Raphael Wigoutschnigg, Peter Schartner, Stefan Rass |
ARES | 3 |
| 2013 | A Network Modeling and Analysis Tool for Perfectly Secure CommunicationabstractSecure communication is often based on encryption thus hinges on (public-key) infrastructures that handle all the key-management. This inevitably requires human intervention, thus creating a rather vulnerable point in the system. So it appears desirable to automate key-management tasks to the widest possible extent. In this work, we report on a software implementation of secure multipath transmission. Our system takes a network infrastructure model as input and determines the maximal achievable security for a communication between a chosen sender and receiver, while handling all key-management transparently for the user. The security is information-theoretic, and unlike public-key or symmetric cryptography does neither hinge on computational intractability nor empirical evidence. More importantly, security can be measured in quantitative terms, thus making the results useful in enterprise risk management. Our software computes the risk for a given transmission under multipath transmission and generates simple \textsc{OmNet++} models to demonstrate the channel construction as practically doable and to measure the additional network overhead. This is for a-priori decision-support and practical guidance for an installation of secure multipath transmission as a high-security transmission service within the enterprise network. Stefan Rass, Benjamin Rainer, Matthias Vavti, Stefan Schauer |
AINA | 1 |
| 2013 | Dynamic Proofs of Retrievability from Chameleon-Hashes
Stefan Rass |
SECRYPT | 1 |
| 2012 | Anonymous Communication by Branch-and-BoundabstractCommunication in which the sender and receiver are both anonymous is usually achieved by using a telescoping construction. The channel is established hop-by-hop, where each relay gets to know the previous and next node along the route. All previously published anonymity services have in common that at least one of these information items inevitably becomes visible to an intermediate node. We present a new protocol that improves on the telescoping approach by additionally hiding the previous and next hops even from the forwarding relay itself. Thus, while achieving sender and receiver anonymity, a certain degree of anonymity among the intermediate relays is additionally assured. The hiding is based on uncertainty due to channel-branching in each step. In order to prevent the so-created tree from growing exponentially, we enforce dead end routes that bound the overall traffic. As a neat and complimentary by-product, the communication enjoys a certain robustness against node failure. Stefan Rass, Peter Schartner, Raphael Wigoutschnigg, Christian Kollmitzer |
ARES | 1 |
| 2012 | On Secure Communication over Wireless Sensor Networks
Stefan Rass, Michal Koza |
SECRYPT | 1 |
| 2011 | Crowds Based on Secret-SharingabstractAnonymous communication has been a long recognized problem, and various solutions of different performance have been proposed over the last decades. Manifold differently strong security notions, being specific for the sender or receiver, are found in the literature. We consider protection of both, the sender's and receiver's identity from each other and a coalition of intermediate relay nodes. The Crowds-system is known to provide probabilistic sender anonymity, but receiver anonymity is only given for asymptotically large networks. Assuming that the adversary notices the communication as such, we prove that the strongest form of receiver anonymity (under this assumption) is efficiently achievable for finite-size (even small) networks. Our construction is secure in the sense that a passive threshold adversary cannot disclose the receiver's identity with a chance better than guessing this information. Stefan Rass, Raphael Wigoutschnigg, Peter Schartner |
ARES | 1 |
| 2011 | On Security and Privacy in Cloud Computing
Daniel Slamanig, Stefan Rass |
CLOSER | 2 |
| 2011 | Information-leakage in Hybrid Randomized Protocols
Stefan Rass, Peter Schartner |
SECRYPT | 1 |
| 2011 | A Unified Framework for the Analysis of Availability, Reliability and Security, With Applications to Quantum NetworksabstractMajor goals of system security comprise confidentiality, integrity, availability, authenticity, and reliability. All of these have seen comprehensive treatment, yielding a vast collection of solutions. Information-theoretic security regarding confidentiality has seen considerable progress recently with the development of commercial quantum cryptographic devices. Solutions for perfectly secure authentication have been around much longer. Achieving perfect security, high availability and reliability, calls for combinations of various approaches. In this study, we propose a simple and uniform framework for the assessment of security, availability, and reliability that arbitrary compositions of security measures can provide. Our methodology facilitates system modeling in a decision-theoretic manner, which makes the models easily understandable even for specialists from fields other than security. At the same time, the models allow for strong assertions and for simple characterizations of the achievable security and safety in a system. We demonstrate the applicability of our results using quantum networks as an example. Stefan Rass, Peter Schartner |
IEEE Trans. Syst. Man Cybern. Part C | 1 |
| 2010 | Non-interactive Information Reconciliation for Quantum Key DistributionabstractQuantum key distribution (QKD) is an emerging technology that provides provable security for point-to-point connections. Its security lies in the fragility of its information carriers, being photons rather than electromagnetic waves. Freespace QKD is particularly interesting, because building optical free-space quantum networks possibly circumvents environmental obstacles that the designers of a cable-based network would have faced. The logical divide of channels in QKD calls for novel models that capture distortions of photon transmission, as the security vitally relies on precise error estimation. We present a model for the quantum channel and discuss channel coding for QKD in optical networks. Our model employs no assumptions whatsoever on the QKD protocol itself, apart from it utilizing photon transmissions. Many QKD implementations meet that requirement. In particular, we prove the unexpected fact that higher transmission rates facilitate non-interactive error correction, thus reducing the communication overhead and increasing the output key-rate. Our theoretical model assumptions are supported by experimental results, confirming the non-Gaussian flavor of noise in some quantum channels. Stefan Rass, Peter Schartner |
AINA | 1 |
| 2010 | Anonymous but Authorized Transactions Supporting Selective Traceability
Daniel Slamanig, Stefan Rass |
SECRYPT | 2 |
| 2009 | Security in Quantum Networks as an Optimization ProblemabstractWe present a general framework for casting the problem of designing secure quantum networks into a classical optimization problem. We introduce a measure of risk that serves as upper bound on the probability of loosing a message to the adversary. Based on this results, we can transform the problem of secure network design into an optimization procedure, which opens the field for the entire framework of optimization theory to tackle the problem most efficiently. The latter is particularly appealing, since we prove the problem to be NP-hard in general. Our methodology is formulated to yield results that have interpretations in probabilistic terms, but can be generalized to other settings in a straightforward manner. The modeling approach is simple, and naturally accounts for different notions of security, depending on the situation at hand. Furthermore, our results are not limited to security in quantum networks, as we rely on quantum cryptography only to the extent of securing links. Hence, the analysis is equally applicable for any (multipath) transmission setup, where information-theoretic security is demanded. Stefan Rass, Peter Schartner |
ARES | 1 |
| 2009 | Quantum Coin-Flipping-Based AuthenticationabstractQuantum cryptographic key distribution (QKD) is a promising candidate for achieving unconditional security, making the renowned one-time pad encryption technically feasible for building computer networks. However, although well-developed theoretical foundations perfectly ensure protection against eavesdropping, no natural mechanism is yet able to successfully repel an adversary sitting between Alice and Bob, performing QKD with both and re-encrypting each message after heaving read it in plain text. Authentication is hence of crucial importance, and normally applied to all messages that are related to the public discussion part of the QKD protocol. We present an analysis of a scenario, in which authentication is postponed until the end of the QKD protocol. This yields to reduced computational effort, as well as simple and tight bounds on the amount of pre-shared key material. Our solution relies on a combination of quantum key distribution and quantum coin-flipping, which ensures non- controllability of the QKD key. Based on this assumption, we can apply a standard fingerprint comparison for authentication, to guard the protocol against a person-in-the-middle attack. Stefan Rass, Peter Schartner, Michaela Greiler |
ICC | 1 |
| 2008 | Application framework for high security requirements in R&D environments based on quantum cryptographyabstractCompanies running research and development (R&D) departments invest considerable effort into the protection of results and security of communication channels. In cases where particular expertise is unavailable within the company, R&D may be partially outsourced to external specialists being universities or independent research centers. In any such case where highly valuable data is to be exchanged between departments of a company or a university, quantum cryptography offers a convenient way to protect the investment and revenue tied to the research. Upon recent results within the EU-project SECOQC, we present an application framework that is suitable for meeting R&D security requirements. We draw from the latest experimental results, demonstrating the feasibility and efficiency of using quantum cryptography in that context. Christian Kollmitzer, Oliver Maurhart, Stefan Schauer, Stefan Rass |
CRiSIS | 4 |
| 2006 | Achieving Unconditional Security in Existing Networks Using Quantum Cryptography
Stefan Rass, Mohamed Ali Sfaxi, Solange Ghernaouti-Helie |
SECRYPT | 1 |