EDBT 2026 Demo / reviewers in the wild / expert
Axel Küpper
dblp:k/AxelKupper
· DBLP profile ↗
30ranked-venue papers
3as first author
13since 2021 · last 2026
0000-0002-4356-5613ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 9 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 8 · 1 first-author · 1 since 2021Computer networks · 6 · 3 since 2021Security and privacy · 5 · 4 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | AI Agents with Decentralized Identifiers and Verifiable Credentials
Sandro Rodriguez Garzon, Awid Vaziry, Enis Mert Kuzu, Dennis Enrique Gehrmann, Buse Varkan, Alexander Gaballa, Axel Küpper |
ICAART (1) | 7 |
| 2026 | SoK: After Decades of Web Tracker Detection, What's Next?
Wolf Rieder, Philip Raschke, Thomas Cory, Christian René Sechting, Axel Küpper |
SP | 6 |
| 2026 | Word-level Annotation of GDPR Transparency Compliance in Privacy Policies using Large Language ModelsabstractEnsuring transparency of data practices related to personal information is a core requirement of the General Data Protection Regulation (GDPR). However, large-scale compliance assessment remains challenging due to the complexity and diversity of privacy policy language. Manual audits are labour-intensive and inconsistent, while current automated methods often lack the granularity required to capture nuanced transparency disclosures. In this paper, we present a modular large language model (LLM)-based pipeline for fine-grained word-level annotation of privacy policies with respect to GDPR transparency requirements. Our approach integrates LLM-driven annotation with passage-level classification, retrieval-augmented generation, and a self-correction mechanism to deliver scalable, context-aware annotations across 21 GDPR-derived transparency requirements. To support empirical evaluation, we compile a corpus of 703,791 English-language privacy policies and generate a ground-truth sample of 200 manually annotated policies based on a comprehensive, GDPR-aligned annotation scheme. We propose a two-tiered evaluation methodology capturing both passage-level classification and span-level annotation quality and conduct a comparative analysis of seven state-of-the-art LLMs on two annotation schemes, including the widely used OPP-115 dataset. The results of our evaluation show that decomposing the annotation task and integrating targeted retrieval and classification components significantly improve annotation accuracy, particularly for well-structured requirements. Our work provides new empirical resources and methodological foundations for advancing automated transparency compliance assessment at scale. Thomas Cory, Wolf Rieder, Julia Krämer, Philip Raschke, Patrick Herbke, Axel Küpper |
Proc. Priv. Enhancing Technol. | 6 |
| 2025 | Enhancing the A2A Protocol with Blockchain-Based Identities and x402 Micropayments for Agentic AI
Awid Vaziry, Sandro Rodriguez Garzon, Axel Küpper |
IJCCI (1) | 3 |
| 2025 | Trusted Storage Management in Edge/Cloud with Verifiable Credentials in KubernetesabstractWith the increasing deployment of 5G and emerging 6G network functions (NF) in cloud-native environments, persistent storage management has become a critical concern, particularly regarding data sovereignty, integrity, and transparency. This paper presents a novel approach to volume claim management leveraging Verifiable Credentials (VCs) as a mechanism to ensure trusted and tamper-resistant storage provisioning across decentralized infrastructure providers. Our framework empowers service creators—rather than cloud providers—to retain control over their data, enabling granular, selective disclosure and policy enforcement in multi-stakeholder ecosystems typical of 6G architectures. By integrating VCs into the persistent storage lifecycle, we introduce cryptographic assurances around volume ownership, access rights, and lifecycle events. This mitigates the risks of unauthorized data modification, supports data residency requirements, and enhances interoperability across federated environments. The proposed model not only strengthens transparency but also aligns with the principles of decentralized trust essential for the next generation of cloud-native network deployments. Sanjeet Raj Pandey, Ismail Kutlay Acar, Patrick Herbke, Axel Küpper |
MSWiM | 4 |
| 2025 | Introduction to the Special Issue on "Blockchain Research and Applications for Innovative Networks and Services (BRAINS 2023)"
Yackolley Amoussou-Guenou, Emmanuelle Anceaume, Emmanuel Bertin, Antonella Del Pozzo, Axel Küpper |
Distributed Ledger Technol. Res. Pract. | 5 |
| 2024 | Architectural Elements of Decentralized Process Management Systems
Kai Grunert, Janis Joderi Shoferi, Lucas Gold, Wolf Rieder, Axel Küpper |
ICSOC (1) | 5 |
| 2024 | DID Link: Authentication in TLS with Decentralized Identifiers and Verifiable CredentialsabstractAuthentication in TLS is predominately carried out with X.509 digital certificates issued by certificate au-thorities (CA). The centralized nature of current public key infrastructures, however, comes along with severe risks, such as single points of failure and susceptibility to cyber-attacks, potentially undermining the security and trustworthiness of the entire system. With Decentralized Identifiers (DID) alongside distributed ledger technology, it becomes technically feasible to prove ownership of a unique identifier without requiring an attestation of the proof's public key by a centralized and therefore vulnerable CA. This article presents DID Link, a novel authentication scheme for TLS 1.3 that empowers entities to authenticate in a TLS-compliant way with self-issued X.509 certificates that are equipped with ledger-anchored DIDs instead of CA-issued identifiers. It facilitates the exchange of tamper-proof and 3rd-party attested claims in the form of DID-bound Verifiable Credentials after the TLS handshake to complete the authentication with a full identification of the communication partner. A prototypical implementation shows comparable TLS handshake durations of DID Link if verification material is cached and reasonable prolongations if it is obtained from a ledger. The significant speed improvement of the resulting TLS channel over a widely used, DID-based alternative transport protocol on the application layer demonstrates the potential of DID Link to become a viable solution for the establishment of secure and trustful end-to-end communication links with decentrally managed digital identities. Sandro Rodriguez Garzon, Dennis Natusch, Artur Philipp, Axel Küpper, Hans Joachim Einsiedler, Daniela Schneider |
PST | 4 |
| 2024 | On data minimization and anonymity in pervasive mobile-to-mobile recommender systemsabstractData minimization is a legal principle that mandates limiting the collection of personal data to a necessary minimum. In this context, we address ourselves to pervasive mobile-to-mobile recommender systems in which users establish adhoc wireless connections between their mobile computing devices in physical proximity to exchange ratings that represent personal data on which they calculate recommendations. The specific problem is: How can users minimize the collection of ratings over all users while only being able to communicate with a subset of other users in physical proximity? A main difficulty is the mobility of users, which prevents, for instance, the creation and use of an overlay network to coordinate data collection. Users, therefore, have to decide whether to exchange ratings and how many when an ad hoc wireless connection is established. We model the randomness of these connections and apply an algorithm based on distributed gradient descent to solve the distributed data minimization problem at hand. We show that the algorithm robustly produces the least amount of connections and also the least amount of collected ratings compared to an array of baselines. We find that this simultaneously reduces the chances of an attacker relating users to ratings. In this sense, the algorithm also preserves the anonymity of users, yet only of those users who do not establish an adhoc wireless connection with each other. Users who do establish a connection with each other are trivially not anonymous toward each other. We find that users can further minimize data collection and preserve their anonymity if they aggregate multiple ratings on the same item into a single rating and change their identifiers between connections. Tobias Eichinger, Axel Küpper |
Pervasive Mob. Comput. | 2 |
| 2023 | Instant Function Calls Using Synchronized Cross-Blockchain Smart ContractsabstractMost current cross-blockchain approaches focus on exchanging or transferring tokens between networks. While some concepts foster smart contract invocations across blockchains, they require multiple transactions and operate asynchronously. We present a concept enabling instant smart contract calls by creating synchronized client contracts on arbitrary blockchains. Other smart contracts can query these client contracts on the target blockchain for retrieving information without requiring cross-chain message queues. With this, we reduce the dependency of smart contracts on their host blockchain, as remote contracts become available as read-only instances. The synchronization process does not require trust in the executing intermediary since Merkle proofs based on shared state roots are utilized to guarantee correct execution. We propose a novel concept called transition proofs for efficiently proving the correctness of state updates. The prototypical implementation permits smart contract synchronization between EVM-compatible blockchains. Our evaluation shows the approach’s applicability regarding execution costs and delay. Further, we conduct a case study by synchronizing one of the largest decentralized exchanges deployed to the Ethereum network. Martin Westerkamp, Axel Küpper |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2022 | SmartSync: Cross-Blockchain Smart Contract Interaction and SynchronizationabstractCross-Blockchain communication has gained traction due to the increasing fragmentation of blockchain networks and scalability solutions such as side-chaining and sharding. With SmartSync, we propose a novel concept for cross-blockchain smart contract interactions that creates client contracts on arbitrary blockchain networks supporting the same execution environment. Client contracts mirror the logic and state of the original instance and enable seamless on-chain function executions providing recent states. Synchronized contracts supply instant read-only function calls to other applications hosted on the target blockchain. Hereby, current limitations in cross-chain communication are alleviated and new forms of contract interactions are enabled. State updates are transmitted in a verifiable manner using Merkle proofs and do not require trusted intermediaries. To permit lightweight synchronizations, we introduce transition confirmations that facilitate the application of verifiable state transitions without re-executing transactions of the source blockchain. We prove the concept’s soundness by providing a prototypical implementation that enables smart contract forks, state synchronizations, and on-chain validation on EVM-compatible blockchains. Our evaluation demonstrates SmartSync’s applicability for presented use cases providing crosschain state access via read-only function calls. Execution costs scale sub-linearly with the number of value updates and depend on the depth and index of corresponding Merkle proofs. Martin Westerkamp, Axel Küpper |
ICBC | 2 |
| 2021 | Connecting Self-Sovereign Identity with Federated and User-centric Identities via SAML IntegrationabstractSelf-sovereign identity provides a feasible alternative to login via username and password through an identity provider to access digital services. It allows identity subjects to control and own their data. Although this is an appealing approach, it requires a whole new infrastructure with almost no dependencies on the existing ones. We designed and implemented a solution that combines an existing federated identity access management solution with the new approach by enabling authentication via self-sovereign-identity-based credentials while the identity provider retains verification and communication with the service provider via Security Assertion Mark Up Language. Thanks to the standardized federated systems in the German higher education domain, the solution not only enables a smooth transition to self-sovereign identities but can also be easily transferred to other universities using the same federated identity framework. Hakan Yildiz, Christopher Ritter, Lan Thao Nguyen, Berit Frech, Maria Mora-Martinez, Axel Küpper |
ISCC | 6 |
| 2021 | Decentralized Identifiers and Self-Sovereign Identity - A New Identity Management for 6G Integration? : MobileCloud 2021 Invited TalkabstractDecentralized Identifiers (DIDs) and Self-Sovereign Identity (SSI) are emerging decentralized identity solutions. DIDs allow legal entities like organizations to create and fully control their identifiers while building the necessary infrastructure for SSI, enabling entities like persons, organizations, or machines to fully control and own their digital identities without the involvement of an intermediate central authority. DIDs are identifiers that are used to reference entities unambiguously and, together with DID Documents stored in a verifiable data registry, establish a new, decentralized public-key infrastructure. An SSI-based digital identity may be composed of many different claims certified by an issuer. Examples are the identity holder’s name, age, gender, university degree, driving license, or other attributes. What makes SSI unique compared to other identity management solutions is that the users keep their digital identities in storage of their choice and thus determine their distribution and processing.With this privacy-by-design approach, the emergence of DIDs and SSI can shape the architecture of the future Internet and its applications, which will impact the future of mobile networks. While 5G networks are currently being rolled out, a discussion about the new capabilities of 6G networks, which are still in the distant future, has long since begun. In addition to even faster access, shorter delays, and new applications, features such as human-centricity, data protection, and privacy are being addressed in particular in the discussions. These latter points make DIDs, SSI, and related concepts and architectures promising candidates for 6G adoption.The talk gives a brief introduction to DIDs and SSI and then discusses the benefits and drawbacks the integration of these technologies into 6G may have. Furthermore, the talk identifies different use cases and identifies the system components and functions of cellular networks affected by a 6G integration. Axel Küpper |
JCC | 1 |
| 2020 | Heimdall: Illuminating the Hidden Depths of Third-party Tracking in Android ApplicationsabstractAlthough the problems surrounding the ubiquity of Web tracking and its risk to the privacy of online users have attracted public attention in recent years, efforts to counter their adverse effects and protect the privacy and personal data of users, either through counter-tracking solutions or legislation, have done little to stem the tide. This problem is especially pronounced in the mobile world, where the generally opaque nature of mobile platforms prevents effective research to ascertain the nature and extent of third-party tracking and protect user privacy. For this reason, we present Heimdall, an Android Web traffic measurement tool designed to allow users and researchers to shed light on the inner workings of mobile applications and identify connections to third-party trackers that have the potential to abuse users' personal data present on their mobile devices. We demonstrate the feasibility of the concept underlying Heim-dall by using it to monitor the network traffic of 450 Android applications, mapping out their connections to 3,453 unique hosts. Analysing this dataset reveals that 70.9% of monitored apps communicate with known tracking and advertising hosts, highlighting the prevalence of third-party tracking in mobile applications. Thomas Cory, Philip Raschke, Axel Küpper |
TrustCom | 3 |
| 2018 | Establishing User-centric Cloud Service RegistriesabstractMany potential cloud consumers are overburdened by the challenges persisting when discovering, assessing, and selecting contemporary Cloud Service offerings: the cloud market is vast and fast-moving, the selection criteria are ambiguous, service knowledge is scattered through the Internet, and features as well as prices are complex and incomparable. Much research has been carried out to create cloud service registries to help users select cloud services for eventual consumption, especially within the field of semantic web services. Through analyzing real-world requirements of six use cases we identified a gap in research for user-centric technologies. We fill this gap by creating a business vocabulary reflecting common service selection criteria, defining a textual domain specific language to let any user describe services easily, and implementing a novel brokering and matchmaking component to support users in their selection process. As a combination of those technologies, we create the Open Service Compendium (OSC), a crowd-sourced cloud service registry. Our evaluation activities highlight how these developments solve real-world challenges in diverse near-production settings. All of this implies that a substantial benefit for service registry users can be created by following a simple architecture that is focused on their concrete needs — instead of aiming for highest sophistication and broadest applicability as observed in many of the related works. Mathias Slawik, Begüm Ilke Zilci, Axel Küpper |
Future Gener. Comput. Syst. | 3 |
| 2017 | Geofence Index: A Performance Estimator for the Reliability of Proactive Location-Based ServicesabstractAn ever-increasing number of today's mobile applications take advantage of location-based services (LBS) in order to proactively notify mobile users about location-dependent content or to execute location-dependent actions once the user enters or leaves a dedicated zone. The proactive LBS are thereby responsible to track the user's position energy-efficiently in the background and to continuously match the position against a set of zones for which geo-triggered actions are defined, better known as geofences. Unfortunately, proactive LBS suffer from a highly erratic reliability. Sometimes, location-dependent actions are not triggered although a user entered a geofence while in other situations location-dependent actions are executed even though a user did not enter any geofence. The reasons are manifold, ranging from an imprecise positioning technique over a lack of cellular network coverage to an inadequate configuration. This paper discusses the technical and environmental factors that have an influence on the reliability of proactive LBS. To make the reliability predictable, it introduces an estimator for the probability that a location-dependent action - as defined for a given geofence - gets triggered by a proactive LBS in case a user crosses the respective geofence. As a proof-of-concept, a prototypical implementation of the estimator is presented together with the outcome of comparing the computed estimations against the real world experiences with an exemplary proactive LBS. Sandro Rodriguez Garzon, Dmytro Arbuzin, Axel Küpper |
MDM | 3 |
| 2016 | Privacy-aware social music playlist generationabstractTwo of the most popular applications of smartphones are online social networking and playing back music. In this paper, we present the design and implementation of a prototype that combines those usages by creating an architecture that allows the generation and playback of group music playlists that are based on the musical taste of individual guests attending a meeting. In our architecture, we utilize automatically collected data on smartphones for the automatized generation of group music playlists. We follow the idea of utilizing context data in a preprocessing step to generate a group music profile for the recommendation process that generates a group music playlist. For designing such an architecture, we consider current discussions on privacy, data ownership, and data control. Felix Beierle, Kai Grunert, Sebastian Göndör, Axel Küpper |
ICC | 4 |
| 2015 | The Inaugural Panel on Novel Applications and Technology Advances in ComputingabstractToday, we see ICT everywhere in our life. ICT has been continuously finding new application fields to enrich our quality of life. This also implies that ICT has been continuously finding new challenges that promotes deeper understanding of computing. New application fields would include green computing, e-Health, mobile computing and big data analysis. To solve the problems in these fields, we are seeing substantial deepening in computing technologies such as supercomputing and machine learning. NATA is designed as a forum where novel applications and technology advances in computing meet. At this panel of the first symposium, we would like to share the state of the art of their interactions. Four specialists of green computing, service centric networking, e-health and machine learning will meet, show the points from their views, and exchange ideas. Ali R. Hurson, Axel Küpper, Kin-ichi Yoshida |
COMPSAC | 2 |
| 2015 | Message from MOWU Symposium Organizing CommitteeabstractPresents a listing of the Symposium organizing committee. Axel Küpper, Hong Va Leong, Paolo Bellavista, J. Morris Chang, Vladimir Getov |
COMPSAC | 1 |
| 2015 | Cloud Service Matchmaking Using Constraint ProgrammingabstractService requesters with limited technical knowledge should be able to compare services based on their quality of service (QoS) requirements in cloud service marketplaces. Existing service matching approaches focus on QoS requirements as discrete numeric values and intervals. The analysis of existing research on non-functional properties reveals two improvement opportunities: list-typed QoS properties as well as explicit handling of preferences for lower or higher property values. We develop a concept and constraint models for a service matcher which contributes to existing approaches by addressing these issues using constraint solvers. The prototype uses an API at the standardisation stage and discovers implementation challenges. This paper concludes that constraint solvers provide a valuable tool to solve the service matching problem with soft constraints and are capable of covering all QoS property types in our analysis. Our approach is to be further investigated in the application context of cloud federations. Begüm Ilke Zilci, Mathias Slawik, Axel Küpper |
WETICE | 3 |
| 2014 | Optimizing the Power Consumption of Mobile Networks Based on Traffic PredictionabstractNowadays, mobile networks approach a steady growth in traffic demand. As a result, mobile network providers continuously expand their network infrastructure mainly by installing more base stations. Currently, there is a huge number of base stations serving mobile users all over the world, and this number is expected to double in the coming few years, which leads to a larger wastage of energy during low demand times. Exploiting the possibility of turning off base stations at low demand times is one of the promising approaches for saving energy and reducing CO2emissions. Here, an early and accurate estimation of the traffic is crucial for managing resources proactively. Therefore, in this paper, we introduce a Power Management System that applies a global provisioning policy to base stations for enabling network reconfigurations in terms of power efficiency. This system is based on a Hybrid Traffic Prediction Model that forecasts the workload of base stations by utilizing historic traffic traces. A simulator is implemented to evaluate the proposed management system, which is fed with real data provided by the Open Mobile Network project. The experimental results show the possibility of turning off 49% of the base stations at some times of the day without degrading the QoS. Safaa Dawoud, Abdulbaki Uzun, Sebastian Göndör, Axel Küpper |
COMPSAC | 4 |
| 2013 | Deriving a Distributed Cloud Proxy Architecture for Managed Cloud Service ConsumptionabstractBusinesses adopting Cloud Computing often have to comply with strict constraints, such as enterprise policies and legal regulations. From these compliance issues arise the need to enable managed cloud service consumption as a prerequisite for adoption. As we have shown before, the proposed TRusted Ecosystem for Standardized and Open cloud-based Resources (TRESOR) cloud ecosystem can achieve management of cloud service consumption [1]. In this paper we motivate and derive the architecture of the distributed TRESOR cloud proxy from technical, business and legal requirements within the context of the TRESOR project. We apply a derivation method where we evaluate the impact of each incremental architecture decision separately. This process enables researchers with supplementary requirements to adapt the intermediate derivations within other contexts in flexible ways. Dirk Thatmann, Mathias Slawik, Sebastian Zickau, Axel Küpper |
IEEE CLOUD | 4 |
| 2011 | Energy-Efficient Position Tracking in Proactive Location-Based Services for Smartphone EnvironmentsabstractLocation-based services (LBSs) gain a massive shift in popularity these days and are about to take the next step towards proactive LBSs. In comparison to conventional LBSs, their proactive variant needs continuous position tracking to monitor spatial objects to detect the relationships between a user and surrounding objects and proactively perform actions. But tracking so far also results in severe battery drain in mobile devices due to deficient positioning APIs and the absence of energy-efficient positioning methods with adequate accuracy. By exploiting the combined information from several positioning technologies with different characteristics in terms of energy consumption, accuracy, precision and availability, this paper proposes a hierarchical positioning algorithm, which provides a general algorithmic optimization in order to extend existing positioning APIs to energy-efficiently track a user's position without diminishing accuracy. The algorithm dynamically deactivates different positioning technologies and only activates the positioning method with the least energy consumption that at the same time provides sufficient accuracy to correctly determine topological relationships. In that way, the algorithm can reliably and accurately determine, if the user leaves or enters predefined geographic areas to trigger events for proactive LBSs while preserving valuable energy resources. First results on Android handsets show a reduction in energy consumption of up to 90 percent in comparison to conventional GPS tracking. Ulrich Bareth, Axel Küpper |
COMPSAC | 2 |
| 2010 | geoXmart - A Marketplace for Geofence-Based Mobile ServicesabstractThis paper describes the concept and architecture of geoXmart, a marketplace for proactive context-aware services, which enables users to easily find and subscribe to interesting services and allows providers to specify, export and maintain their services for versatile applications like electronic toll collect, context-aware advertising, or tourist information systems, even without implementing additional infrastructures. A geofence service comprises one or several geographic areas, so called geofences which are associated with actions to be performed, corresponding conditions and related metadata. Our approach defines a formalism of geofence services and their interfaces. Providers can benefit from simple service creation with almost no programming experience and even without the need to provide own infrastructure, because the services are executed mainly on the mobile device and are deployed on the marketplace. From a user's perspective, the concept provides ease of use e.g. finding services in their local surroundings and running serveral services in one single application, which leads to scale effects through combined processing of position and context. Therefore, we developed a concept for a marketplace providing geofence services that can be implemented by everyone, thus helping to increase the overall usage and integration of proactive location-based services in our daily lives. Ulrich Bareth, Axel Küpper, Peter Ruppel |
COMPSAC | 2 |
| 2008 | Advanced location-based services
Miguel A. Labrador, Katina Michael, Axel Küpper |
Comput. Commun. | 3 |
| 2008 | Extending the LBS-framework TraX: Efficient proximity detection with dead reckoning
Georg Treu, Axel Küpper, Thomas Wilder |
Comput. Commun. | 2 |
| 2007 | Vs Golf - Developing Location-based Multi-Player GamesabstractLocation-based multi-player games are currently being pushed by the industry, one main factor being that highly-accurate positioning technologies like GPS as well as broadband mobile networks like UMTS are finally getting widespread. Nevertheless, generic frameworks for efficiently managing user locations are still missing, which strongly complicates game development. This paper presents TraX, a device-centric framework for Location- based Services, which especially supports proactive and multi-player services and thus perfectly matches the challenges mobile game development faces today. The suitability of TraX is evaluated by means of VsGolf, an actual location-based multi-player game, which has been developed and tested by students in only four days. Georg Treu, Johannes Martens, Matthias Schicker, Marc Breisinger, Axel Küpper |
COMPSAC (2) | 5 |
| 1999 | Invoking computational objects on mobile devices
Axel Küpper, Claudia Linnhoff-Popien |
DAIS | 1 |
| 1994 | A Concept for an Odp Service Management
Claudia Linnhoff-Popien, Axel Küpper |
NOMS | 2 |
| 1993 | Software-Sanierung mit Benutzerbeteiligung und Prototyping
Robert Bergann, Hubert Biskup, Axel Küpper |
Requirements Engineering | 3 |