EDBT 2026 Demo / reviewers in the wild / expert
Dirk Balfanz
dblp:b/DBalfanz
· DBLP profile ↗
22ranked-venue papers
9as first author
2since 2021 · last 2026
0009-0003-5497-2729ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 12 · 6 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 2 first-authorHuman-computer interaction and ubiquitous computing · 4 · 1 since 2021Artificial intelligence and machine learning · 1Systems, architecture and hardware · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Human-computer interaction and pervasive computing
4 papers |
Human-AI interaction · 38% Collaborative and social computing · 30% Human-robot interaction · 29% | |
| Network and information security
11 papers |
Authentication and access control · 62% Web and mobile security · 13% Cryptographic primitives and cryptanalysis · 9% |
Topics — the 30 heaviest of 39, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Human-robot interaction › robot autonomy
adaptive autonomy |
0.8 | 1 | 2024 | An Evaluation of Situational Autonomy for Human-AI Collaboration in a Shared Workspace Setting · CHI 2024 |
Human-AI interaction
human-AI collaboration |
0.8 | 1 | 2024 | An Evaluation of Situational Autonomy for Human-AI Collaboration in a Shared Workspace Setting · CHI 2024 |
Collaborative and social computing › groupware
shared workspace |
0.8 | 1 | 2024 | An Evaluation of Situational Autonomy for Human-AI Collaboration in a Shared Workspace Setting · CHI 2024 |
Authentication and access control › multi-factor authentication
two-factor authentication |
0.1 | 1 | 2012 | Strengthening user authentication through opportunistic cryptographic identity assertions · CCS 2012 |
Authentication and access control
user authentication |
0.1 | 1 | 2012 | Strengthening user authentication through opportunistic cryptographic identity assertions · CCS 2012 |
Web and mobile security
web authentication |
0.1 | 1 | 2012 | Origin-Bound Certificates: A Fresh Approach to Strong Client Authentication for the Web · USENIX Security Symposium 2012 |
Authentication and access control
device pairing |
0.1 | 1 | 2006 | Instant Matchmaking: Simple and Secure Integrated Ubiquitous Computing Environments · UbiComp 2006 |
Systems and software security › system auditing
audit logs |
0.0 | 1 | 2004 | Building an Encrypted and Searchable Audit Log · NDSS 2004 |
Cryptographic primitives and cryptanalysis
searchable encryption |
0.0 | 1 | 2004 | Building an Encrypted and Searchable Audit Log · NDSS 2004 |
Network security
wireless network security |
0.0 | 1 | 2004 | Network-in-a-Box: How to Set Up a Secure Wireless Network in Under a Minute · USENIX Security Symposium 2004 |
Web and mobile security
phishing resistance |
0.0 | 1 | 2012 | Strengthening user authentication through opportunistic cryptographic identity assertions · CCS 2012 |
Authentication and access control › authentication
authentication protocols |
0.0 | 1 | 2003 | Secret Handshakes from Pairing-Based Key Agreements · S&P 2003 |
Cryptographic primitives and cryptanalysis › pairing-based cryptography
bilinear diffie-hellman |
0.0 | 1 | 2003 | Secret Handshakes from Pairing-Based Key Agreements · S&P 2003 |
Cryptographic primitives and cryptanalysis
pairing-based cryptography |
0.0 | 1 | 2003 | Secret Handshakes from Pairing-Based Key Agreements · S&P 2003 |
Authentication and access control › authentication
secret handshake |
0.0 | 1 | 2003 | Secret Handshakes from Pairing-Based Key Agreements · S&P 2003 |
Collaborative and social computing
computer-supported cooperative work |
0.0 | 1 | 2002 | Using speakeasy for ad hoc peer-to-peer collaboration · CSCW 2002 |
Authentication and access control
authentication |
0.0 | 1 | 2002 | Talking to Strangers: Authentication in Ad-Hoc Wireless Networks · NDSS 2002 |
Cryptographic protocols and secure computation › key management
group key management |
0.0 | 1 | 2002 | Self-Healing Key Distribution with Revocation · S&P 2002 |
Cryptographic protocols and secure computation › key management
key distribution |
0.0 | 1 | 2002 | Self-Healing Key Distribution with Revocation · S&P 2002 |
Authentication and access control › revocation
key revocation |
0.0 | 1 | 2002 | Self-Healing Key Distribution with Revocation · S&P 2002 |
Cryptographic protocols and secure computation › key management › key distribution › group key distribution
self-healing key distribution |
0.0 | 1 | 2002 | Self-Healing Key Distribution with Revocation · S&P 2002 |
Authentication and access control › authorization
delegated authorization |
0.0 | 1 | 2000 | A Security Infrastructure for Distributed Java Applications · S&P 2000 |
Authentication and access control › access control
distributed access control |
0.0 | 1 | 2000 | A Security Infrastructure for Distributed Java Applications · S&P 2000 |
Authentication and access control › user authentication
smart card authentication |
0.0 | 1 | 1999 | Hand-Held Computers Can Be Better Smart Cards · USENIX Security Symposium 1999 |
Authentication and access control
access control |
0.0 | 1 | 1997 | Extensible Security Architecture for Java · SOSP 1997 |
Authentication and access control › access control
capability-based security |
0.0 | 1 | 1997 | Extensible Security Architecture for Java · SOSP 1997 |
Systems and software security › operating system security
extensible security architecture |
0.0 | 1 | 1997 | Extensible Security Architecture for Java · SOSP 1997 |
Systems and software security
software protection |
0.0 | 1 | 1997 | Extensible Security Architecture for Java · SOSP 1997 |
Wireless networking
WLAN |
0.0 | 1 | 2004 | Network-in-a-Box: How to Set Up a Secure Wireless Network in Under a Minute · USENIX Security Symposium 2004 |
Wireless networking
mobile ad hoc networks |
0.0 | 1 | 2002 | Talking to Strangers: Authentication in Ad-Hoc Wireless Networks · NDSS 2002 |
Methods — techniques the papers use, named apart from their topics
user study · 0.8pilot study · 0.8cryptographic protocol design · 0.1certificate-based authentication · 0.1cryptographic authentication · 0.1attribute certificates · 0.1SSL · 0.1SDSI/SPKI · 0.1encrypted search · 0.0pairing-based key agreement · 0.0TLS cipher suite · 0.0self-healing key distribution · 0.0
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Risk Assessment Framework for Digital Identification SystemsabstractWe introduce a risk assessment framework for digital identification systems, as well as recommended best practices to enhance privacy, security, and other desirable properties in these systems. To generate these resources, we created a casebook of a wide range of digital identification systems, and we then applied expert analysis and critique to identify patterns. We piloted the framework on several reviews within our organization over a period of approximately one year, and found it to be robust and helpful for those reviews. This work is intended to inform product review and development, product policy, and standards efforts, and to help guide a consistent responsible approach to digital identification across the broader digital identification ecosystem. Allison Woodruff, Dirk Balfanz, Will Drewry, Mariana Raykova 0001 |
Proc. Priv. Enhancing Technol. | 2 |
| 2024 | An Evaluation of Situational Autonomy for Human-AI Collaboration in a Shared Workspace SettingabstractDesigning interactions for human-AI teams (HATs) can be challenging due to an AI agent’s potential autonomy. Previous work suggests that higher autonomy does not always improve team performance, and situation-dependent autonomy adaptation might be beneficial. However, there is a lack of systematic empirical evaluations of such autonomy adaptation in human-AI interaction. Therefore, we propose a cooperative task in a simulated shared workspace to investigate effects of fixed levels of AI autonomy and situation-dependent autonomy adaptation on team performance and user satisfaction. We derive adaptation rules for AI autonomy from previous work and a pilot study. We implement these rule for our main experiment and find that team performance was best when humans collaborated with an agent adjusting its autonomy based on the situation. Additionally, users rated this agent highest in terms of perceived intelligence. From these results, we discuss the influence of varying autonomy degrees on HATs in shared workspaces. Vildan Salikutluk, Janik Schöpper, Franziska Herbert, Katrin Scheuermann, Eric Frodl, Dirk Balfanz, Frank Jäkel, Dorothea Koert |
CHI | 6 |
| 2012 | Strengthening user authentication through opportunistic cryptographic identity assertionsabstractUser authentication systems are at an impasse. The most ubiquitous method -- the password -- has numerous problems, including susceptibility to unintentional exposure via phishing and cross-site password reuse. Second-factor authentication schemes have the potential to increase security but face usability and deployability challenges. For example, conventional second-factor schemes change the user authentication experience. Furthermore, while more secure than passwords, second-factor schemes still fail to provide sufficient protection against (single-use) phishing attacks. Alexei Czeskis, Michael Dietz, Tadayoshi Kohno, Dan S. Wallach, Dirk Balfanz |
CCS | 5 |
| 2012 | Origin-Bound Certificates: A Fresh Approach to Strong Client Authentication for the Web
Michael Dietz, Alexei Czeskis, Dirk Balfanz, Dan S. Wallach |
USENIX Security Symposium | 3 |
| 2006 | Instant Matchmaking: Simple and Secure Integrated Ubiquitous Computing Environments
Diana K. Smetters, Dirk Balfanz, Glenn Durfee, Trevor F. Smith, Kyung-Hee Lee |
UbiComp | 2 |
| 2006 | User-Centric Multimedia Information Visualization for Mobile Devices in the Ubiquitous Environment
Yoo-Joo Choi, Seong-Joon Yoo, Soo-Mi Choi, Carsten Waldeck, Dirk Balfanz |
KES (1) | 5 |
| 2004 | Securing a Remote Terminal Application with a Mobile Trusted DeviceabstractMany real-world applications use credentials such as passwords as means of user authentication. When accessed from untrusted public terminals, such applications are vulnerable to credential sniffing attacks, as shown by recent highly publicized compromises. In this paper, we describe a secure remote terminal application that allows users possessing a trusted device to delegate their credentials for performing a task to a public terminal without being in danger of disclosing any long-term secrets. Instead, the user gives the terminal the capability of performing a task temporarily (as long as the user is in its proximity). Our model is intuitive in the sense that the user exposes to the untrusted terminal only what he sees on the display, and nothing else. We present the design and implementation of such a system. The overhead - in terms of additional network traffic - created by introducing a trusted third party is a moderate 12%. Alina Oprea, Dirk Balfanz, Glenn Durfee, Diana K. Smetters |
ACSAC | 2 |
| 2004 | Mobile Liquid 2D Scatter Space (ML2DSS)abstractThis (video-) paper describes a user interface concept, which facilitates browsing of comparably large amounts of information on small screens. The viewing concept is based on a visually optimized star field display (Ahlberg & Shneiderman 1994) and is introducing new concepts like liquid browsing (an expansion lens with pressure controlled magnetic force simulation), selection based filtering and representation manipulation, multimotion behavior tagging, (interaction-) transparent spaces and continuous state animation. All these create a very versatile information space with a liquid-like look and feel, which can be used in a very intuitive way, providing all the advantages of a mature interactive scatter plot and can easily be scaled to different screen sizes without any adjustment efforts. This paper focuses on visual design and interaction details and emphasizes the importance of the visual interactive quality for mobile information visualization. Carsten Waldeck, Dirk Balfanz |
IV | 2 |
| 2004 | Building an Encrypted and Searchable Audit Log
Brent Waters, Dirk Balfanz, Glenn Durfee, Diana K. Smetters |
NDSS | 2 |
| 2004 | Network-in-a-Box: How to Set Up a Secure Wireless Network in Under a Minute
Dirk Balfanz, Glenn Durfee, Rebecca E. Grinter, Diana K. Smetters, Paul Stewart |
USENIX Security Symposium | 1 |
| 2004 | Editorial video technology and interactive broadcasting
Dirk Balfanz, David Shrimpton |
Comput. Graph. | 1 |
| 2004 | A reference architecture supporting hypervideo content for ITV and the internet domain
Matthias Finke, Dirk Balfanz |
Comput. Graph. | 2 |
| 2003 | Usable Access Control for the World Wide WebabstractWhile publishing content on the World Wide Web has moved within reach of the nontechnical mainstream, controlling access to published content still requires expertise in Web server configuration, public-key certification, and a variety of access control mechanisms. Lack of such expertise results in unnecessary exposure of content published by nonexperts, or force cautious nonexperts to leave their content off-line. Recent research has focused on making access control systems more flexible and powerful, but not on making them easier to use. We propose a usable access control systems for the World Wide Web, i.e., a system that is easy to use both for content providers (who want to protect their content from unauthorized access) and (authorized) content consumers (who want hassle-free access to such protected content). Our system is constructed with judicious use of conventional building blocks, such as access control lists and public-key certificates. We point out peculiarities in existing software that make it unnecessarily hard to achieve our goal of usable access control, and assess the security provided by our usable system. Dirk Balfanz |
ACSAC | 1 |
| 2003 | Secret Handshakes from Pairing-Based Key AgreementsabstractConsider a CIA agent who wants to authenticate herself to a server but does not want to reveal her CIA credentials unless the server is a genuine CIA outlet. Consider also that the CIA server does not want to reveal its CIA credentials to anyone but CIA agents - not even to other CIA servers. We first show how pairing-based cryptography can be used to implement such secret handshakes. We then propose a formal definition for secure secret handshakes, and prove that our pairing-based schemes are secure under the Bilinear Diffie-Hellman assumption. Our protocols support role-based group membership authentication, traceability, indistinguishability to eavesdroppers, unbounded collusion resistance, and forward repudiability. Our secret-handshake scheme can be implemented as a TLS cipher suite. We report on the performance of our preliminary Java implementation. Dirk Balfanz, Glenn Durfee, Narendar Shankar, Diana K. Smetters, Jessica Staddon, Hao-Chi Wong |
S&P | 1 |
| 2003 | Mobile situation-awareness within the project map
Dirk Balfanz, Jürgen Schirmer, Matthias Grimm, Mohammad-Reza Tazari |
Comput. Graph. | 1 |
| 2002 | Using speakeasy for ad hoc peer-to-peer collaborationabstractPeer-to-peer systems appear promising in terms of their ability to support ad hoc, spontaneous collaboration. However, current peer-to-peer systems suffer from several deficiencies that diminish their ability to support this domain, such as inflexibility in terms of discovery protocols, network usage, and data transports. We have developed the Speakeasy framework, which addresses these issues, and supports these types of applications. We show how Speakeasy addresses the shortcomings of current peer-to-peer systems, and describe a demonstration application, called Casca, that supports ad hoc peer-to-peer collaboration by taking advantages of the mechanisms provided by Speakeasy. W. Keith Edwards, Mark W. Newman, Jana Z. Sedivy, Trevor F. Smith, Dirk Balfanz, Diana K. Smetters, H. Chi Wong, Shahram Izadi |
CSCW | 5 |
| 2002 | Talking to Strangers: Authentication in Ad-Hoc Wireless Networks
Dirk Balfanz, Diana K. Smetters, Paul Stewart, H. Chi Wong |
NDSS | 1 |
| 2002 | Self-Healing Key Distribution with RevocationabstractWe address the problem of establishing a group key amongst a dynamic group of users over an unreliable, or lossy, network. We term our key distribution mechanisms self-healing because users are capable of recovering lost group keys on their own, without requesting additional transmissions from the group manager thus cutting back on network traffic, decreasing the load on the group manager and reducing the risk of user exposure through traffic analysis. A user must be a member both before and after the session in which a particular key is sent in order to be able to recover the key through self-healing. Binding the ability to recover keys to membership status enables the group manager to use short broadcasts to establish group keys, independent of the group size. In addition, the self-healing approach to key distribution is stateless, meaning that a group member who has been off-line for some time is able to recover new session keys immediately after coming back on-line. Jessica Staddon, Sara Miner More, Matthew K. Franklin, Dirk Balfanz, Michael Malkin, Drew Dean |
S&P | 4 |
| 2000 | A Security Infrastructure for Distributed Java ApplicationsabstractWe describe the design and implementation of a security infrastructure for a distributed Java application. This work is inspired by SDSI/SPKI, but has a few twists of its own. We define a logic for access control, such that access is granted iff a proof that it should be granted is derivable in the logic. Our logic supports linked local name spaces, privilege delegation across administrative domains, and attribute certificates. We use SSL to establish secure channels through which principals can "speak", and have implemented our access control system in Java. While we implemented our infrastructure for the Placeless Documents System, our design is applicable to other applications as well. We discuss general issues related to building secure, distributed Java applications that we discovered. Dirk Balfanz, Drew Dean, Mike Spreitzer |
S&P | 1 |
| 1999 | Hand-Held Computers Can Be Better Smart Cards
Dirk Balfanz, Edward W. Felten |
USENIX Security Symposium | 1 |
| 1998 | Experience with Secure Multi-Processing in JavaabstractAs the Java/sup TM/ platform is the preferred environment for the deployment of network computers, it is appealing to run multiple applications on a single Java enabled desktop. We experimented with using the Java platform as a multiprocessing, multi user environment. Although the Java Virtual Machine (JVM) is not inherently a single application design, we have found that the implementation of the Java Development Kit (JDK) often implicitly assumes that the JVM runs exactly one application at any one time. We report on the limitations we encountered and propose improvements to several aspects of the Java technology architecture, including its security features. We have implemented all the proposed changes in a prototype based on an in-house beta version of JDK 1.2. Our prototype uses a Bourne shell like command line tool to launch multiple applications (such as Appletviewer) within one JVM. Dirk Balfanz |
ICDCS | 1 |
| 1997 | Extensible Security Architecture for JavaabstractMobile code technologies such as Java, JavaScript, and ActiveX generally limit all programs to a single security policy. However, software-based protection can allow for more flexible security models, with potentially significant performance improvements over traditional hardware-based solutions. We describe and analyze three implementation strategies for interposing flexible security policies in software-based security systems. Implementations exist for all three strategies: several vendors have adapted capabilities to Java, Netscape Communicator extended Java's stack introspection, and we built a typehiding system as an add-on to Microsoft Internet Explorer. 1 Introduction The growth of the World Wide Web has enabled the Internet to reach new levels of popularity and ease of use. We are now seeing the arrival of HTML-enabled mail and news-reading tools, heralding the complete acceptance of Web documents as a medium of exchange. As Web applications have blossomed, developers have bee... Dan S. Wallach, Dirk Balfanz, Drew Dean, Edward W. Felten |
SOSP | 2 |