Jens B. Schmitt

dblp:s/JensBSchmitt · DBLP profile ↗
← Back
78ranked-venue papers
10as first author
5since 2021 · last 2025
0000-0002-3066-4305ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 42 · 7 first-authorSecurity and privacy · 17 · 3 since 2021Systems, architecture and hardware · 9 · 1 since 2021Software engineering, systems software and programming languages · 3 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 3Artificial intelligence and machine learning · 1Human-computer interaction and ubiquitous computing · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2025 Per-Flow Performance Guarantees in Networked Systems with Complex Feedback Structures
Anja Hamscher, Lukas Wildberger, Jens B. Schmitt
ECRTS3
2025 They See Me Scooting - A Long-Term Real-World Data Analysis of Shared Micro-Mobility Services and their Privacy Leakage
abstract
In many places, a surge of micro-mobility sharing systems, as for instance e-scooters, can be observed. Shared micro-mobility is a cost-efficient and flexible alternative to owning vehicles and, furthermore, leads to reduced traffic and air pollution. However, sharing information about vehicles impacts the privacy of the individuals using such vehicles as changes in vehicle state are linked to an individual’s mobility pattern. Malicious exploitation of knowledge on mobility patterns of individuals may assist in criminal activities such as stalking or burglary. Thus, it is very important that micro-mobility sharing platforms do not leak sensitive data about the mobility patterns of their users, resulting in a tradeoff between sharing and privacy.To characterize the privacy leakage in one specific instance of shared micro-mobility, we conducted a large-scale, long-term data collection from scooters run by the e-scooter company Tier in the European university town Kaiserslautern. Indeed, the data reveals several privacy issues: For instance, we were able to reconstruct work and school schedules of various individuals. Furthermore, we could infer interests and hobbies by visits to, e.g., sports facilities. Our initial discovery of such leakages was aided by the fact that the specific e-scooter company does not comply with existing privacy standards, in particular the use of dynamic IDs. Yet, an a-posteriori analysis of our data shows that even with dynamic IDs, we are able to re-construct 80% of the trips, which still constitutes a substantial privacy leakage.
Karina Elzer, Eric Jedermann, Stefanie Roos, Jens B. Schmitt
EuroS&P4
2024 Extending Network Calculus to Deal with Min-Plus Service Curves in Multiple Flow Scenarios
abstract
Network Calculus (NC) is a versatile analytical methodology to efficiently compute performance bounds in networked real-time systems. The arrival and service curve abstractions allow to model diverse and heterogeneous distributed real-time systems. The operations to compute residual service curves and to concatenate sequences of systems enable an efficient and accurate calculation of per-flow timing guarantees. Yet, in some scenarios involving multiple concurrent flows at a system, the central notion of so-called min-plus service curves is too weak to still be able to compute a meaningful residual service curve. In these cases, one usually resorts to so-called strict service curves that enable the computation of per-flow bounds. However, strict service curves are restrictive: (1) there are service elements for which only min-plus service curves can be provided but not strict ones and (2) strict service curves generally have no concatenation property, i.e., a sequence of two strict systems does not yield a strict service curve. In this paper, we extend NC to deal with systems only offering aggregate min-plus service curves to multiple flows. The key to this extension is the exploitation of minimal arrival curves, i.e., lower bounds on the arrival process. Technically speaking, we provide basic performance bounds (backlog and delay) for the case of negative service curves. We also discuss their accuracy and show them to be tight in many cases and approximately tight up to a constant in the others. In order to illustrate their usefulness we also present patterns of application of these new results for: (1) heterogeneous systems involving computation and communication resources and (2) finite buffers that are shared between multiple flows.
Anja Hamscher, Vlad-Cristian Constantin, Jens B. Schmitt
RTAS3
2024 RECORD: A RECeption-Only Region Determination Attack on LEO Satellite Users
Eric Jedermann, Martin Strohmeier, Vincent Lenders, Jens B. Schmitt
USENIX Security Symposium4
2021 Orbit-based authentication using TDOA signatures in satellite networks
abstract
Given the nature of satellites orbiting the Earth on a fixed trajectory, in principle, it is interesting to investigate how this invariant can be exploited for security purposes. In particular, satellite orbit information can be retrieved from public databases. Using time difference of arrival (TDOA) measurements from multiple receivers, we can check this orbit information against a corresponding TDOA-based signature of the satellite. In that sense, we propose an orbit-based authentication scheme for down-link satellite communications in this paper. To investigate the properties and fundamentals of our novel TDOA signature scheme we study two satellite systems at different altitudes: Iridium and Starlink.
Eric Jedermann, Martin Strohmeier, Matthias Schäfer 0002, Jens B. Schmitt, Vincent Lenders
WISEC4
2019 h-Mitigators: Improving your stochastic network calculus output bounds
Paul Nikolaus, Jens B. Schmitt, Malte Schütze
Comput. Commun.2
2018 Crowd-GPS-Sec: Leveraging Crowdsourcing to Detect and Localize GPS Spoofing Attacks
abstract
The aviation industry's increasing reliance on GPS to facilitate navigation and air traffic monitoring opens new attack vectors with the purpose of hijacking UAVs or interfering with air safety. We propose Crowd-GPS-Sec to detect and localize GPS spoofing attacks on moving airborne targets such as UAVs or commercial airliners. Unlike previous attempts to secure GPS, Crowd-GPS-Sec neither requires any updates of the GPS infrastructure nor of the airborne GPS receivers, which are both unlikely to happen in the near future. In contrast, Crowd-GPS-Sec leverages crowdsourcing to monitor the air traffic from GPS-derived position advertisements that aircraft periodically broadcast for air traffic control purposes. Spoofing attacks are detected and localized by an independent infrastructure on the ground which continuously analyzes the contents and the times of arrival of these advertisements. We evaluate our system with real-world data from a crowdsourced air traffic monitoring sensor network and by simulations. We show that Crowd-GPS-Sec is able to globally detect GPS spoofing attacks in less than two seconds and to localize the attacker up to an accuracy of 150 meters after 15 minutes of monitoring time.
Kai Jansen, Matthias Schäfer 0002, Daniel Moser, Vincent Lenders, Christina Pöpper, Jens B. Schmitt
IEEE Symposium on Security and Privacy6
2017 Localization of Spoofing Devices using a Large-scale Air Traffic Surveillance System
abstract
Systems relying on satellite positioning techniques such as GPS can be targeted by spoofing attacks, where attackers try to inject fake positioning information. With the growing spread of flying drones and their usage of GPS for localization, these systems become interesting targets of attacks with the purpose of hijacking or to distract air safety surveillance. The most recent development in air traffic surveillance is the automatic dependent surveillance -- broadcast (ADS-B). Aircraft periodically broadcast their location, speed, or environmental measurements via ADS-B. The open research project OpenSky Network collects ADS-B reports and makes them available for research purposes. This poster presents a concept to detect and localize spoofing devices by utilizing the information provided by a large-scale air traffic surveillance system. We utilize ADS-B reports collected by the OpenSky Network and provide first results on the effectiveness of localizing spoofing sources.
Kai Jansen, Matthias Schäfer 0002, Vincent Lenders, Christina Pöpper, Jens B. Schmitt
AsiaCCS5
2017 Generalized finitary real-time calculus
abstract
Real-time Calculus (RTC) is a non-stochastic queuing theory to the worst-case performance analysis of distributed real-time systems. Workload as well as resources are modelled as piece-wise linear, pseudo-periodic curves and the system under investigation is modelled as a sequence of algebraic operations over these curves. The memory footprint of computed curves increases exponentially with the sequence of operations and RTC may become computationally infeasible fast. Recently, Finitary RTC has been proposed to counteract this problem. Finitary RTC restricts curves to finite input domains and thereby counteracts the memory demand explosion seen with pseudo periodic curves of common RTC implementations. However, the proof to the correctness of Finitary RTC specifically exploits the operational semantic of the greed processing component (GPC) model and is tied to the maximum busy window size. This is an inherent limitation, which prevents a straight-forward generalization. In this paper, we provide a generalized Finitary RTC that abstracts from the operational semantic of a specific component model and reduces the finite input domains of curves even further. The novel approach allows for faster computations and the extension of the Finitary RTC idea to a much wider range of RTC models.
Kai Lampka, Steffen Bondorf, Jens B. Schmitt, Nan Guan, Wang Yi 0001
INFOCOM3
2017 Generalizing window flow control in bivariate network calculus to enable leftover service in the loop
Michael A. Beck, Jens B. Schmitt
Perform. Evaluation2
2016 Achieving Efficiency without Sacrificing Model Accuracy: Network Calculus on Compact Domains
abstract
Messages traversing a network commonly experience waiting times due to sharing the forwarding resources. During those times, the crossed systems must provide sufficient buffer space for queueing messages. Network Calculus (NC) is a mathematical methodology for bounding flow delays and system buffer requirements. The accuracy of these performance bounds depends mainly on two factors: the principles manifesting in the NC flow equation and the functions describing the system. We focus on the latter aspect. Common implementations of NC overapproximate these functions in order to keep the analysis computationally feasible. However, overapproximation often results in a loss of accuracy of the performance bounds. In this paper, we make such compromising tradeoffs between model accuracy and computational effort obsolete. We limit the accurate system description to functions of a compact domain, such that the accuracy of the NC analysis is preserved. Tying the domain bound to the algebraic operators of NC instead of the operational semantics of components, allows us to directly apply our solution to algebraic NC analyses that implement principles such as pay burst only once and pay multiplexing only once.
Kai Lampka, Steffen Bondorf, Jens B. Schmitt
MASCOTS3
2016 Secure Motion Verification using the Doppler Effect
abstract
Future transportation systems highly rely on the integrity of spatial information provided by their means of transportation such as vehicles and planes. In critical applications (e.g. collision avoidance), tampering with this data can result in life-threatening situations. It is therefore essential for the safety of these systems to securely verify this information. While there is a considerable body of work on the secure verification of locations, movement of nodes has only received little attention in the literature. This paper proposes a new method to securely verify spatial movement of a mobile sender in all dimensions, i.e., position, speed, and direction. Our scheme uses Doppler shift measurements from different locations to verify a prover's motion. We provide formal proof for the security of the scheme and demonstrate its applicability to air traffic communications. Our results indicate that it is possible to reliably verify the motion of aircraft in currently operational systems with an equal error rate of zero.
Matthias Schäfer 0002, Patrick Leu, Vincent Lenders, Jens B. Schmitt
WISEC4
2016 Friendly Jamming on Access Points: Analysis and Real-World Measurements
abstract
Frequency jamming is known as an efficient attack tool to disrupt wireless communication. This efficiency can also be exploited for the benefit of a network—an idea often referred to as friendly jamming. A prominent application case is the blocking of unauthenticated or malicious communication, such as injection attacks. In this paper, we propose access points as a natural place to implement friendly jamming functionality. We analyze this proposal using simulations, introduce an implementation on customer-grade access points, and report measurement results from the first real-world study of friendly jamming in an IEEE 802.11 campus network. We discover a fundamental tradeoff between the effectiveness of friendly jamming and the orthogonal aspect of having minimal side-effects to the campus network’s traffic. In particular, we observed what we call the power amplification phenomenon. This effect aggravates the known hidden station problem when the number of jammers increases. We also find evidence that the collaboration between jammers can enable friendly jamming, which is both effective and minimally invasive.
Daniel S. Berger, Francesco Gringoli, Nicolò Facchi, Ivan Martinovic, Jens B. Schmitt
IEEE Trans. Wirel. Commun.5
2015 Boosting sensor network calculus by thoroughly bounding cross-traffic
abstract
Sensor Network Calculus (SensorNC) provides a framework for worst-case analysis of wireless sensor networks. The analysis proceeds in two steps: For a given flow, (1) the network is reduced to a tandem of nodes by computing the arrival bounds of cross-traffic; (2) the flow is separated from the cross-traffic by subtracting cross-flows and concatenating nodes on its path. While the second step has seen much treatment, the first step has not at all. This is in sharp contrast to the fact that arrival bounding takes roughly 80% of the total analysis time and is equally crucial for the tightness of the bounds. Therefore, we turn our attention to this first SensorNC analysis step with the goal to boost the performance and applicability of the overall framework. The main technical contribution is a generalized version of the concatenation theorem within the SensorNC setting. This generalization is instrumental in simplifying and streamlining the cross-traffic arrival bound computations such that run times can be reduced by more than a factor of 5. Even more important, it enables a localization of the information necessary to execute the calculations at the node level, thus enabling a distribution of the SensorNC analysis within a self-modeling WSN.
Steffen Bondorf, Jens B. Schmitt
INFOCOM2
2015 Secure Track Verification
abstract
We propose a new approach for securely verifying sequences of location claims from mobile nodes. The key idea is to exploit the inherent mobility of the nodes in order to constrain the degree of freedom of an attacker when spoofing consecutive location updates along a claimed track. We show that in the absence of noise, our approach is able to securely verify any 2-D track with a minimum of three verifiers or any 3-D track with four verifiers. Our approach is lightweight in the sense that it considerably relaxes the system requirements compared to previous secure location verification schemes which are all agnostic to mobility. As opposed to previous schemes, our track verification solution is at the same time (i) passive, (ii) does not require any time synchronization among the verifiers, (iii) does not need to keep the location of the verifiers secret, (iv) nor does it require specialized hardware. This makes our solution particularly suitable for large-scale deployments. We have evaluated our solution in a realistic air traffic monitoring scenario using real-world data. Our results show that 25 position claims on a track are sufficient to detect spoofing attacks with a false positive rate of 1.4% and a false negative rate of 1.2%. For tracks with more than 40 claims, the false positive and false negative rates drop to zero.
Matthias Schäfer 0002, Vincent Lenders, Jens B. Schmitt
IEEE Symposium on Security and Privacy3
2015 Security by mobility in location and track verification
abstract
This poster presents the idea of exploiting mobility to improve the security in location and track verification. Unlike traditional approaches which require tight time synchronization or two-way communication, mobility can be used to derive lightweight verification schemes. By ensuring independent movement of the verifiers, our scheme can provide security guarantees even if the verifiers' positions are known to the attacker. We also give an outlook on more general opportunities for mobility-aided security.
Matthias Schäfer 0002, Daniel S. Berger, Vincent Lenders, Jens B. Schmitt
WISEC4
2014 Towards a statistical network calculus - Dealing with uncertainty in arrivals
abstract
The stochastic network calculus (SNC) has become an attractive methodology to derive probabilistic performance bounds. So far the SNC is based on (tacitly assumed) exact probabilistic assumptions about the arrival processes. Yet, in practice, these are only true approximately-at best. In many situations it is hard, if possible at all, to make such assumptions a priori. A more practical approach would be to base the SNC operations on measurements of the arrival processes (preferably even on-line). In this paper, we develop this idea and incorporate measurements into the framework of SNC taking the further uncertainty resulting from estimation errors into account. This is a crucial step towards a statistical network calculus (StatNC) eventually lending itself to a self-modelling operation of networks with a minimum of a priori assumptions. In numerical experiments, we are able to substantiate the novel opportunities by StatNC.
Michael A. Beck, Sebastian A. Henningsen, Simon Birnbach, Jens B. Schmitt
INFOCOM4
2014 Sharp per-flow delay bounds for bursty arrivals: The case of FIFO, SP, and EDF scheduling
abstract
The practicality of the stochastic network calculus (SNC) is often questioned on grounds of potential looseness of its performance bounds. In this paper, it is uncovered that for bursty arrival processes (specifically Markov-Modulated On-Off (MMOO)), whose amenability to per-flow analysis is typically proclaimed as a highlight of SNC, the bounds can unfortunately be very loose (e.g., by several orders of magnitude off). In response to this uncovered weakness of SNC, the (Standard) per-flow bounds are herein improved by deriving a general sample-path bound, using martingale based techniques, which accommodates FIFO, SP, and EDF scheduling. The obtained (Martingale) bounds capture an extra exponential decay factor of O (e−αn) in the number of flows n. Moreover, numerical comparisons against simulations show that the Martingale bounds are not only remarkably accurate, but they also improve the Standard SNC bounds by factors as large as 100 or even 1000.
Florin Ciucu, Felix Poloczek, Jens B. Schmitt
INFOCOM3
2014 On the catalyzing effect of randomness on the per-flow throughput in wireless networks
abstract
This paper investigates the throughput capacity of a flow crossing a multi-hop wireless network, whose geometry is characterized by general randomness laws including Uniform, Poisson, Heavy-Tailed distributions for both the nodes' densities and the number of hops. The key contribution is to demonstrate how the per-flow throughput depends on the distribution of 1) the number of nodes Njinside hops' interference sets, 2) the number of hops K, and 3) the degree of spatial correlations. The randomness in both Nj's and K is advantageous, i.e., it can yield larger scalings (as large as Θ(n)) than in non-random settings. An interesting consequence is that the per-flow capacity can exhibit the opposite behavior to the network capacity, which was shown to suffer from a logarithmic decrease in the presence of randomness. In turn, spatial correlations along the end-to-end path are detrimental by a logarithmic term.
Florin Ciucu, Jens B. Schmitt
INFOCOM2
2014 On the relevance of adversarial queueing theory in practice
abstract
Adversarial Queueing Theory (AQT) has shown that seemingly innocent traffic injection rates might lead to unbounded queues in packet-switched networks - depending on scheduling strategies as well as topological characteristics. Little attention has been given to quantifying these effects in realistic network configurations. In particular, the existing AQT literature makes two unrealistic assumptions: infinite buffers and perfect synchrony. Because finite buffers inherently limit queue sizes, adversarial effects ultimately lead to packet loss which we address in this work. In addition, we study the effect of imperfect network synchronization under the packet loss metric. Our results, using analysis and simulation, indicate that classical AQT examples appear harmless under realistic assumptions but for a novel class of adversaries considerably higher loss can be observed. We introduce this class by giving examples of two new AQT concepts to construct loss-efficient network adversaries. Our analysis proves the robustness of these new adversaries against randomized de-synchronization effects in terms of variable link delays and nodal processing.
Daniel S. Berger, Martin Karsten, Jens B. Schmitt
SIGMETRICS3
2014 Gaining insight on friendly jamming in a real-world IEEE 802.11 network
abstract
Frequency jamming is the fiercest attack tool to disrupt wireless communication and its malicious aspects have received much attention in the literature. Yet, several recent works propose to turn the table and employ so-called friendly jamming for the benefit of a wireless network. For example, recently proposed friendly jamming applications include hiding communication channels, injection attack defense, and access control. This work investigates the practical viability of friendly jamming by applying it in a real-world network. To that end, we implemented a reactive and frame-selective jammer on a consumer grade IEEE 802.11 access point. Equipped with this, we conducted a three weeks real-world study on the jammer's performance and side-effects on legitimate traffic (the cost of jamming) in a university office environment. Our results provide detailed insights on crucial factors governing the trade-off between the effectiveness of friendly jamming (we evaluated up to 13 jammers) and its cost. In particular, we observed -- what we call the power amplification phenomenon -- an effect that aggravates the known hidden station problem when the number of jammers increases. However, we also find evidence that this effect can be alleviated by collaboration between jammers, which again enables effective and minimally invasive friendly jamming.
Daniel S. Berger, Francesco Gringoli, Nicolò Facchi, Ivan Martinovic, Jens B. Schmitt
WISEC5
2014 Detection of Reactive Jamming in DSSS-based Wireless Communications
abstract
Reactive jammers have been shown to be a serious threat for wireless communication. Despite this, it is difficult to detect their presence reliably. We propose a novel method to detect such sophisticated jammers in direct sequence spread spectrum (DSSS) wireless communication systems. The key idea is to extract statistics from the jamming-free symbols of the DSSS synchronizer to discern jammed packets from those lost due to bad channel conditions. Our contribution is twofold. First, we experimentally evaluate new empirical models utilizing the preamble symbols of IEEE 802.15.4 packets, thus enabling the accurate prediction of the packet delivery ratio (PDR). We show that the chip error rate-based metric is superior to metrics used in the literature, offering an accurate and reactive indicator of the true PDR. Our second contribution is the design and evaluation of a detection technique relying on this metric to detect reactive jammers. We build a software-defined radio testbed and show that our technique enables the error-free detection of reactive jammers that jam all packets on links with a PDR above 0.3. To the best of our knowledge, our detector is the first to detect reactive jamming attacks targeting the physical layer header of DSSS packets, and does not require any modifications of the wireless communication system.
Michael Spuhler, Domenico Giustiniano, Vincent Lenders, Matthias Wilhelm 0001, Jens B. Schmitt
IEEE Trans. Wirel. Commun.5
2014 On the Reception of Concurrent Transmissions in Wireless Sensor Networks
abstract
Numerous studies have shown that concurrent transmissions can help boost wireless network performance despite the possibility of packet collisions. However, while these works provide empirical evidence that concurrent transmissions may be received reliably, existing signal capture models only partially explain the root causes of this phenomenon. We present a comprehensive mathematical model for MSK-modulated signals that makes the reasons explicit and thus provides fundamental insights into the key parameters governing the successful reception of colliding transmissions. A major contribution is the closed-form derivation of the receiver bit decision variable for an arbitrary number of colliding signals and constellations of power ratios, time offsets, and carrier phase offsets. We systematically explore the factors for successful packet delivery under concurrent transmissions across the whole parameter space of the model. We confirm the capture threshold behavior observed in previous studies but also reveal new insights relevant to the design of optimal protocols. We identify capture zones depending not only on the signal power ratio but also on time and phase offsets.
Matthias Wilhelm 0001, Vincent Lenders, Jens B. Schmitt
IEEE Trans. Wirel. Commun.3
2013 Neighborhood watch: On network coding throughput and key sharing
abstract
Network coding (NC) has frequently been promoted as an approach for improving throughput in wireless networks. Existing work has mostly focused on the fundamental aspects of NC, while constraints arising in real-world network deployments have not received much attention. In particular, NC requires network nodes to overhear each other's packets, which oftentimes contradicts many security standards that attempt to provide link-layer confidentiality, e.g., by utilizing pairwise encryption keys as is the case IEEE 802.11i and ZigBee. There is an inherent trade-off between gains from NC and link-layer security: if many nodes share the secret link-layer key, NC will improve throughput, yet a leakage of the key will affect many nodes. On the other hand, having distinct secret keys will increase resilience against key compromise, but will also minimize the coding gain. We formulate this security vs. performance trade-off as an optimization problem and evaluate the effectiveness of NC under different sizes of key-sharing groups and network topologies. Our results show that increasing the key-sharing group by a single node can result in a maximum coding gain between 1.3% and 13.7%.
Martin Strohmeier, Ivan Martinovic, Utz Roedig, Karim M. El Defrawy, Jens B. Schmitt
GLOBECOM5
2013 Sharp bounds in stochastic network calculus
abstract
The practicality of the stochastic network calculus (SNC) is often questioned on grounds of potential looseness of its performance bounds. In this paper it is uncovered that for bursty arrival processes (specifically Markov-Modulated On-Off (MMOO)), whose amenability to per-flow analysis is typically proclaimed as a highlight of SNC, the bounds can unfortunately indeed be very loose (e.g., by several orders of magnitude off). In response to this uncovered weakness of SNC, the (Standard) per-flow bounds are herein improved by deriving a general sample-path bound, using martingale based techniques, which accommodates FIFO, SP, and EDF scheduling disciplines. The obtained (Martingale) bounds capture an additional exponential decay factor of O(e-α n) in the number of flows $n$, and are remarkably accurate even in multiplexing scenarios with few flows.
Florin Ciucu, Felix Poloczek, Jens B. Schmitt
SIGMETRICS3
2013 Detection of reactive jamming in DSSS-based wireless networks
abstract
We propose a novel approach to detect reactive jammers in direct sequence spread spectrum (DSSS) wireless networks. The key idea is to use the chip error rate of the first few jamming-free symbols at the DSSS demodulator during the signal synchronization phase of regular packet reception to estimate the probability of successful packet delivery. If the estimated probability is significantly higher than the actual packet delivery ratio, we declare jamming. As a proof of concept, we implement a prototype in a network of three USRP software-defined radios (transmitter, receiver, and jammer) and evaluate the feasibility, responsiveness, and accuracy of our approach in a controlled lab environment. Our experiments with IEEE 802.15.4 DSSS-based communication show that for links with a jamming-free packet delivery probability above 0.5, the false positive and negative detection rates remain below 5%.
Domenico Giustiniano, Vincent Lenders, Jens B. Schmitt, Michael Spuhler, Matthias Wilhelm 0001
WISEC3
2013 Who do you sync you are?: smartphone fingerprinting via application behaviour
abstract
The overall network traffic patterns generated by today's smartphones result from the typically large and diverse set of installed applications. In addition to the traffic generated by the user, most applications generate characteristic traffic from their background activities, such as periodic update requests or server synchronisation. Although the encryption of transmitted data in 3G networks prevents an eavesdropper from analysing the content, periodic traffic patterns leak side-channel information like timing and data volume. In this work, we extract such side-channel features from network traffic generated from the most popular applications, such as Facebook, WhatsApp, Skype, Dropbox, and others, and evaluate whether they can be used to reliably identify a smartphone. By computing fingerprints from approx,6,hours of background traffic, we show that 15 minutes of monitored traffic suffice to reliably identify a smartphone based on its behavioural fingerprint with a success probability of 90%.
Tim Stöber, Mario Frank 0001, Jens B. Schmitt, Ivan Martinovic
WISEC3
2013 Secure Key Generation in Sensor Networks Based on Frequency-Selective Channels
abstract
Key management in wireless sensor networks faces several unique challenges. The scale, resource limitations, and new threats such as node capture suggest the use of in-network key generation. However, the cost of such schemes is often high because their security is based on computational complexity. Recently, several research contributions justified experimentally that the wireless channel itself can be used to generate information-theoretic secure keys. By exchanging sampling messages during device movement, a bit string is derived known only to the two involved entities. Yet, movement is not the only option to generate randomness: the channel response strongly depends on the signal frequency as well. In this work, we introduce a key generation protocol based on the frequency-selectivity of multipath fading channels. The practical advantage of this approach is that it does not require device movement during key establishment. Thus the frequent case of a sensor network with static nodes is supported. We show the protocol's applicability by implementing it on MICAz motes, and evaluating its robustness and security through experiments and analysis. The error correction property of the protocol mitigates the effects of measurement errors and temporal effects, giving rise to an agreement rate of over 97 %.
Matthias Wilhelm 0001, Ivan Martinovic, Jens B. Schmitt
IEEE J. Sel. Areas Commun.3
2012 Achieving High Lifetime and Low Delay in Very Large Sensors Networks Using Mobile Sinks
abstract
For smaller scale wireless sensor networks (WSN) it has been clearly shown that a single mobile sink can be very beneficial with respect to the network lifetime. Yet, how to plan the trajectories of many mobile sinks in very large WSNs in order to simultaneously achieve lifetime and delay goals has not been treated so far. In this paper, we delve into this difficult problem and propose a heuristic framework using multiple orbits for the sinks' trajectories. The framework is carefully designed based on geometric arguments to achieve both, high lifetime and low delay. In simulations, we compare two different instances of our framework, one conceived based on a load balancing argument and one based on a distance minimization argument, with a set of different competitors spanning from statically placed sinks to battery-state aware strategies. We find our heuristics to perform very favorably: both instances outperform the competitors in both, lifetime and delay. Furthermore, and probably even more importantly, the heuristic, while keeping its good delay and lifetime performance, scales well with an increasing number of sinks.
Wint Yi Poe, Michael A. Beck, Jens B. Schmitt
DCOSS3
2012 Perspectives on network calculus: no free lunch, but still good value
abstract
ACM Sigcomm 2006 published a paper [26] which was perceived to unify the deterministic and stochastic branches of the network calculus (abbreviated throughout as DNC and SNC) [39]. Unfortunately, this seemingly fundamental unification---which has raised the hope of a straightforward transfer of all results from DNC to SNC---is invalid. To substantiate this claim, we demonstrate that for the class of stationary and ergodic processes, which is prevalent in traffic modelling, the probabilistic arrival model from [26] is quasi-deterministic, i.e., the underlying probabilities are either zero or one. Thus, the probabilistic framework from [26] is unable to account for statistical multiplexing gain, which is in fact the raison d'être of packet-switched networks. Other previous formulations of SNC can capture statistical multiplexing gain, yet require additional assumptions [12], [22] or are more involved [14], [9] [28], and do not allow for a straightforward transfer of results from DNC. So, in essence, there is no free lunch in this endeavor.
Florin Ciucu, Jens B. Schmitt
SIGCOMM2
2011 On expressing networks with flow transformations in convolution-form
abstract
Convolution-form networks have the property that the end-to-end service of network flows can be expressed in terms of a (min, +)-convolution of the per-node services. This property is instrumental for deriving end-to-end queueing results which fundamentally improve upon alternative results derived by a node-by-node analysis. This paper extends the class of convolution-form networks with stochastic settings to scenarios with flow transformations, e.g., by loss, dynamic routing or retransmissions. In these networks, it is shown that by using the tools developed in this paper end-to-end delays grow as O(n) in the number of nodes n; in contrast, by using the alternative node-by-node analysis, end-to-end delays grow as O(n2).
Florin Ciucu, Jens B. Schmitt, Hao Wang 0023
INFOCOM2
2011 Pay bursts only once holds for (some) non-FIFO systems
abstract
Non-FIFO processing of flows by network nodes is not a rare phenomenon. Unfortunately, the state-of-the-art analytical tool for the computation of performance bounds in packet-switched networks, network calculus, cannot deal well with non-FIFO systems. The problem lies in its conventional service curve definitions. Either the definition is too strict to allow for a concatenation and consequent beneficial end-to-end analysis, or it is too loose and results in infinite delay bounds. Hence, in this paper, we propose a new service curve definition and demonstrate its strength with respect to achieving both finite delay bounds and a concatenation of systems resulting in a favorable end-to-end delay analysis. In particular, we show that the celebrated pay bursts only once phenomenon is retained even without any assumptions on the processing order of packets. This seems to contradict previous work [15]; the reasons for this are discussed.
Jens B. Schmitt, Nicos Gollan, Steffen Bondorf, Ivan Martinovic
INFOCOM1
2011 WiFire: a firewall for wireless networks
abstract
Firewalls are extremely effective at enforcing security policies in wired networks. Perhaps surprisingly, firewalls are entirely nonexistent in the wireless domain. Yet, the need to selectively control and block radio communication is particularly high in a broadcast environment since any node may receive and send packets. In this demo, we present WiFire, a system that brings the firewall concept to wireless networks. First, WiFire detects and analyzes packets during their transmission, checking their content against a set of rules. It then relies on reactive jamming techniques to selectively block undesired communication. We show the feasibility and performance of WiFire, which is implemented on the USRP2 software-defined radio platform, in several scenarios with IEEE 802.15.4 radios. WiFire is able to classify and effectively block undesired communication without interfering with desired communication.
Matthias Wilhelm 0001, Ivan Martinovic, Jens B. Schmitt, Vincent Lenders
SIGCOMM3
2011 Short paper: reactive jamming in wireless networks: how realistic is the threat?
abstract
In this work, we take on the role of a wireless adversary and investigate one of its most powerful tools---radio frequency jamming. Although different jammer designs are discussed in the literature, reactive jamming, i.e., targeting only packets that are already on the air, is generally recognized as a stepping stone in implementing optimal jamming strategies. The reason is that, while destroying only selected packets, the adversary minimizes its risk of being detected. One might hope for reactive jamming to be too challenging or uneconomical for an attacker to conceive and implement due to its strict real-time requirements. Yet, in this work we disillusion from such hopes as we demonstrate that flexible and reliable software-defined reactive jamming is feasible by designing and implementing a reactive jammer against IEEE 802.15.4 networks. First, we identify the causes of loss at the physical layer of 802.15.4 and show how to achieve the best performance for reactive jamming. Then, we apply these insights to our USRP2-based reactive jamming prototype, enabling a classification of transmissions in real-time, and reliable and selective jamming. The prototype achieves a reaction time in the order of microseconds, a high precision (such as targeting individual symbols), and a 97.6% jamming rate in realistic indoor scenarios for a single reactive jammer, and over 99.9% for two concurrent jammers.
Matthias Wilhelm 0001, Ivan Martinovic, Jens B. Schmitt, Vincent Lenders
WISEC3
2011 Dynamic demultiplexing in network calculus - Theory and application
Hao Wang 0023, Jens B. Schmitt, Ivan Martinovic
Perform. Evaluation2
2010 A Self-adversarial Approach to Delay Analysis under Arbitrary Scheduling
Jens B. Schmitt, Hao Wang 0023, Ivan Martinovic
ISoLA (1)1
2010 Statistical response time bounds in randomly deployed wireless sensor networks
abstract
Response time bounds are important for many application scenarios of wireless sensor networks (WSN). Often, during the planning phase of a WSN its topology is not known. It rather results from a deployment process. This makes the provision of deterministic response time bounds difficult. In this paper, we strive for statistical response time bounds in WSNs that take the stochastic nature of the deployment process into account. Based on a Monte Carlo method we derive estimates for quantiles of the maximum response time distribution under uncertainty about the topology. In numerical experiments we show that the long but light tail of this distribution causes considerably lower bounds compared to the deterministic one even under small violation probabilities and, yet, on the other hand compare favourably with the median of the distribution.
Steffen Bondorf, Jens B. Schmitt
LCN2
2010 Secret keys from entangled sensor motes: implementation and analysis
abstract
Key management in wireless sensor networks does not only face typical, but also several new challenges. The scale, resource limitations, and new threats such as node capture and compromise necessitate the use of an on-line key generation, where secret keys are generated by the nodes themselves. However, the cost of such schemes is high since their secrecy is based on computational complexity. Recently, several research contributions justified that the wireless channel itself can be used to generate information-theoretic secure keys between two parties. By exchanging sampling messages during movement, a bit string can be derived that is only known to the involved entities. Yet, movement is not the only possibility to generate randomness. The channel response is also strongly dependent on the frequency of the transmitted signal. In our work, we introduce a protocol for key generation based on the frequency-selectivity of channel fading. The great practical advantage of this approach is that we do not rely on node movement as the source of randomness. Thus, the frequent case of a sensor network with static motes is supported. Furthermore, the error correction property of the proposed protocol mitigates the effects of measurement errors and other temporal effects, giving rise to a key agreement rate of over 97%. We show the applicability of our protocol by implementing it on MICAz motes, and evaluate its robustness and secrecy through experiments and analysis.
Matthias Wilhelm 0001, Ivan Martinovic, Jens B. Schmitt
WISEC3
2009 Self-organized sink placement in large-scale wireless sensor networks
abstract
The deficient energy supplies of wireless sensor networks (WSNs) drives network designers to optimize energy consumption in various ways. Not only with regard to the energy issue but also with respect to system performance, we design a local search technique for sink placement in WSNs that tries to minimize the maximum worst-case delay and extend the lifetime of a WSN, simultaneously. Since it is not feasible for a sink to use global information, which especially applies to large-scale WSNs, we introduce a self-organized sink placement (SOSP) strategy that combines the advantages of our previous works. The goal of this research is to provide a better sink placement strategy with a lower communication overhead. Avoiding the costly design of using nodes' location information, each sink sets up its own group by communicating to its n-hop distance neighbors. While keeping the locally optimal placement, SOSP exhibits a quality of the solutions with respect to communication overhead as well as computational effort that are better than previous solutions. To model and consequently control the worst-case delay of a given WSN we build upon the so-called sensor network calculus (a recent methodology first introduced).
Wint Yi Poe, Jens B. Schmitt
MASCOTS2
2009 Jamming for good: a fresh approach to authentic communication in WSNs
abstract
While properties of wireless communications are often considered as a disadvantage from a security perspective, this work demonstrates how multipath propagation, a broadcast medium, and frequency jamming can be used as valuable security primitives. Instead of conventional message authentication by receiving, verifying, and then discarding fake data, sensor nodes are prevented from receiving fake data at all. The erratic nature of signal propagation distributes the jamming activity over the network which hinders an adversary in predicting jamming nodes and avoids selective battery-depletion attacks. By conducting real-world measurements, we justify the feasibility of such a security design and provide details on implementing it within a realistic wireless sensor network.
Ivan Martinovic, Paul Pichota, Jens B. Schmitt
WISEC3
2009 Bringing law and order to IEEE 802.11 networks - A case for DiscoSec
Ivan Martinovic, Paul Pichota, Matthias Wilhelm 0001, Frank A. Zdarsky, Jens B. Schmitt
Pervasive Mob. Comput.5
2009 Chaotic communication improves authentication: protecting WSNs against injection attacks
abstract
Abstract In this paper, we propose a system leveraging peculiarities of the wireless medium, such as the broadcast nature of wireless communication and the unpredictability of indoor signal propagation to achieve effective protection against attacks based on the injection of fake data. Using a real‐world WSN deployment and a realistic implementation of an attacker, we analyze this protection scheme and demonstrate that neither position change, transmission power manipulation, nor complete knowledge of wireless parameters can help an attacker to successfully attack the network. As a result, this work demonstrates how the chaotic nature of radio communication, which is often considered a disadvantage in regard to security objectives, can be exploited to enhance protection and support implementation of lightweight security mechanisms. Copyright © 2009 John Wiley & Sons, Ltd.
Ivan Martinovic, Nicos Gollan, Luc Cappellaro, Jens B. Schmitt
Secur. Commun. Networks4
2009 Minimizing contention through cooperation between densely deployed wireless LANs
Frank A. Zdarsky, Ivan Martinovic, Jens B. Schmitt
Wirel. Networks3
2008 Delay Bounds under Arbitrary Multiplexing: When Network Calculus Leaves You in the Lurch
abstract
Network calculus has proven as a valuable and versatile methodology for worst-case analysis of communication networks. One issue in which it is still lacking is the treatment of aggregate multiplexing, in particular if the FIFO property cannot be assumed when flows are merged. In this paper, we address the problem of bounding the delay of individual traffic flows in feed-forward networks under arbitrary multiplexing. Somewhat surprisingly, we find that direct application of network calculus results in loose bounds even in seemingly simple scenarios. The reasons for this "failure" of network calculus are discussed in detail and a method to arrive at tight delay bounds for arbitrary (aggregate) multiplexing is presented. This method is based on the solution of an optimization problem. For the special case of sink-tree networks this optimization problem is solved explicitly, thus arriving at a closed-form expression for the delay bound. Numerical experiments illustrate that in sink-tree networks the improvement over bounds based on direct application of network calculus can be considerable.
Jens B. Schmitt, Frank A. Zdarsky, Markus Fidler
INFOCOM1
2008 Firewalling wireless sensor networks: Security by wireless
abstract
Networked sensors and actuators for purposes from production monitoring and control to home automation are in increasing demand. Until recently, the main focus laid on wired systems, although their deployment requires careful planning and expensive infrastructure that may be difficult to install or modify. Hence, solutions based on wireless sensor networks (WSNs) are gaining popularity to reduce cost and simplify installation. Clearly, one of the key issues rising from the switch to wireless communication lies in security; while an air gap is among the most effective security measures in wired networks, wireless communication is not as easy to isolate from attack. In this paper, we propose a system leveraging the peculiarities of the wireless medium, such as the broadcast nature of wireless communication and the unpredictability of indoor signal propagation to achieve effective protection against attacks based on the injection of fake data. Using a real-world WSN deployment and a realistic implementation of an attacker, we analyze this protection scheme and demonstrate that neither position change, transmission power manipulation, nor complete knowledge of wireless parameters can help an attacker to successfully attack the network. As a result, this work demonstrates how the chaotic nature of radio communication, which is often considered a disadvantage in regard to security objectives, can be used to enhance protection and support implementation of lightweight security mechanisms.
Ivan Martinovic, Nicos Gollan, Jens B. Schmitt
LCN3
2008 Wireless client puzzles in IEEE 802.11 networks: security by wireless
abstract
Resource-depletion attacks against IEEE 802.11 access points (APs) are commonly executed by flooding APs with fake authentication requests. Such attacks may exhaust an AP's memory resources and result in denied association service, thus enabling more sophisticated impersonation attacks accomplished by rogue APs.
Ivan Martinovic, Frank A. Zdarsky, Matthias Wilhelm 0001, Christian Wegmann, Jens B. Schmitt
WISEC5
2008 Design, implementation, and performance analysis of DiscoSec - Service pack for securing WLANs
abstract
To improve the already tarnished reputation of WLAN security, the new IEEE 802.11i security standard provides means for an enhanced user authentication and strong data confidentiality. However, the standard focuses on securing higher-layer data, i.e., protecting IEEE 802.11 data frames. Management frames used for connection administration are left unprotected and a wide spectrum of known attacks is still applicable and even extended against the IEEE 802.11i/IEEE 802.1X protocol execution. This work describes DiscoSec, a service pack for “patching” WLANs against the most prominent vulnerabilities resulting in resource-depletion and impersonation attacks. DiscoSec provides DoS-resilient key exchange, an efficient frame authentication, and a performance-oriented implementation. By means of extensive real-world measurements the performance of DiscoSec is evaluated showing that even on very resource-limited devices the throughput is decreased by only 22% compared to the throughput without any authentication, and by 6%on more powerful hardware. To demonstrate its effectiveness, DiscoSec is available as an open-source WLAN device driver.
Ivan Martinovic, Paul Pichota, Matthias Wilhelm 0001, Frank A. Zdarsky, Jens B. Schmitt
WOWMOM5
2007 Energy-Efficent TDMA Design Under Real-Time Constraints in Wireless Sensor Networks
abstract
Many wireless sensor networks (WSNs) are used to collect and aggregate data from potentially hostile environments. Catering to this, early application scenarios did not put tight constraints on performance properties like delay, but rather focused on ruggedness and energy conservation. Yet, there is a growing number of sceanarios like e.g. production monitoring, intrusion detection, or health care systems which depend on the sensor network to provide performance guarantees in order to be able to act upon the phenomena being sensed in a timely fashion. Nevertheless, these applications still face the traditional issue of energy-efficiency. In this paper, we present means to find energy-efficient medium assignments in time-slotted multi-hop networks that satisfy given real-time constraints. Specifically, we present a way to find the optimal length of time slots and periods in TDMA schemes. We also present a software to compute those values for typical sink-tree WSNs. Index Terms--Wireless Sensor Networks, Energy-Efficiency, Real-time guarantees, Optimal TDMA, Network calculus.
Nicos Gollan, Jens B. Schmitt
MASCOTS2
2007 A Comprehensive Worst-Case Calculus for Wireless Sensor Networks with In-Network Processing
abstract
Today's wireless sensor networks (WSN) focus on energy-efficiency as the main metric to optimize. However, an increasing number of scenarios where sensor networks are considered for time-critical purposes in application sce- narios like intrusion detection, industrial monitoring, or health care systems demands for an explicit support of per- formance guarantees in WSNs and, thus, in turn for a re- spective mathematical framework. In [1], a sensor network calculus was introduced in order to accommodate a worst- case analysis of WSNs. This sensor network calculus fo- cused on the communication aspect in WSNs, but had not yet a possibility to treat in-network processing in WSNs. In this work, we now incorporate in-network processing fea- tures as they are typical for WSNs by taking into account computational resources on the sensor nodes. Furthermore, we propose a simple, yet effective priority queue manage- ment discipline which achieves a good balance of response times across sensor nodes in the field.
Jens B. Schmitt, Frank A. Zdarsky, Lothar Thiele
RTSS1
2007 Phishing in the Wireless: Implementation and Analysis
Ivan Martinovic, Frank A. Zdarsky, Adam Bachorek, Jens B. Schmitt
SEC5
2005 Sensor Network Calculus - A Framework for Worst Case Analysis
Jens B. Schmitt, Utz Roedig
DCOSS1
2005 Packet marking for integrated load control
abstract
Combining low-complexity packet marking at internal nodes with path-based load observation at edge gateways enables a rich set of control mechanisms in a packet-switched network. In this paper, we propose a method to estimate the relative per-node load at internal nodes, based on only the aggregated marking signal available at edge nodes, without any knowledge of internal capacities. We present the design of an integrated network system that supports both admission control and per-node load estimation using only two bits in the packet header, which requires a specific encoding of the two distinct marking signals. Finally, we describe a prototype implementation and a few simulation and lab experiments as a proof-of-concept for this approach.
Martin Karsten, Jens B. Schmitt
Integrated Network Management2
2005 Best-Effort Versus Reservations Revisited
Oliver Heckmann, Jens B. Schmitt
IWQoS2
2005 M^2 DR: A Near-optimal Multiclass Minimum-delay Routing Algorithm for Smart Radio Access Networks
abstract
Today, we witness a transformation of radio access network topologies from strictly tree-structured towards meshed architectures. Yet, these edge networks follow mostly circuit-switched paradigms to support quality of service applications such as voice or video communication. In this work, we develop a novel quality of service aware routing framework to optimize the performance of edge networks in the packet-switched domain. Starting from the Internet's best-effort routing paradigm and building on related work, we formulate a near-optimal multiclass minimum-delay routing algorithm. Our algorithm optimizes network-wide end-to-end delay and allows for differentiation of service. We exploit two orthogonal dimensions namely multipath routing and class-based service prioritization. We provide a precise description of our algorithm and a detailed experimental analysis against state of the art routing algorithms. Our algorithm is able to achieve excellent performance while maintaining the simplicity of a decentralized and distributed routing algorithm, thus matching the requirements for future radio access networks.
Matthias Hollick, Parag S. Mogre, Tronje Krop, Hans-Peter Huth, Jens B. Schmitt, Ralf Steinmetz
LCN5
2005 Multimedia and firewalls: a performance perspective
Utz Roedig, Jens B. Schmitt
Multim. Syst.2
2005 Layer-encoded video in scalable adaptive streaming
abstract
Combining the concepts of caching and transmission control protocol (TCP)-friendly streaming of layer-encoded video bears the problem that those videos might not be cached in full quality. Therefore, we focus in this work on the scheduling of retransmissions of missing segments of a cached video in a manner that allows clients to receive the content in an improved quality. In a first step, we conducted subjective assessments of variations in layer-encoded video with the goal to validate existing quality metrics, including our own, which are based on certain assumptions. A statistical analysis of the subjective assessment validates these assumptions. We also show that the frequently used peak signal-to-noise ratio (PSNR) is not an appropriate metric for variations in layer-encoded video. With the insight from the subjective assessment we develop heuristics for retransmission scheduling and prove their applicability by conducting a series of simulations.
Michael Zink, Jens B. Schmitt, Ralf Steinmetz
IEEE Trans. Multim.2
2004 On the effect of node misbehavior in ad hoc networks
abstract
The dependability of the routing system in ad hoc networks inherently relies on node behavior. In order to support multihop operation in the network, most ad hoc routing algorithms assume well-behaving nodes. However, in reality there may exist constrained, selfish or malicious nodes. We discuss the influence of node misbehavior on the routing process. In particular, we derive a classification for misbehaving nodes and extend an analytical model of the route acquisition process executed by the ad hoc on-demand distance vector (AODV) routing protocol to cover different classes of misbehavior. The validation of the behavior model, and the clarification of the impact misbehaving nodes impose onto the routing process, is completed using an experimental analysis.
Matthias Hollick, Jens B. Schmitt, Christian Seipl, Ralf Steinmetz
ICC2
2004 Network calculus meets queueing theory -a simulation based approach to bounded queues
abstract
Quality of Service (QoS) is an area with high academic curiosity. Our long-term goal is to develop a unified mathematical model. This paper is a first step towards this ambitious goal. The most widespread models for network QoS are network calculus and queueing theory. While the strength of queueing theory is its proven applicability to a wide area of problems, Network calculus can offer performance guarantees. We analyse by simulation the benefit of bringing the two of them together, i.e., bounding the stochastic processes of a queue with methods from network calculus. A basic result from network calculus is that enforcing traffic shaping and service curves bounds the buffer. This leads to denying buffer states in queues with infinite buffer. Specifically, we analyse what happens with the probability mass of such buffer states. Finally, we discuss how our results can be used for dimensioning buffers for multiplexed traffic.
Krishna Pandit, Jens B. Schmitt, Ralf Steinmetz
IWQoS2
2004 Enhancing mobile QoS based on movement contracts
abstract
Resource management for individual flows can significantly improve quality of service (QoS) in mobile cellular networks. However, its efficiency depends on the availability of information about the movement of mobile terminals. Movement prediction can potentially provide this information, but is costly if performed by the network and usually assumes a certain movement model, which may not adequately reflect each individual user's behavior. Instead, we propose the concept of movement contracts, where a mobile terminal specifies its movement to the network, which in return provides a better QoS as long as the provided specification is sufficiently accurate. We describe approaches to specify the spatial and temporal aspects of movement with a parsimonious parameter set and evaluate these approaches through simulations. We find that movement contracts can significantly reduce both session blocking and handover dropping probability simultaneously, whereas existing approaches have to make a tradeoff between these.
Frank A. Zdarsky, Jens B. Schmitt
IWQoS2
2004 Performance Modelling and Evaluation of Firewall Architectures for Multimedia Applications
Utz Roedig, Jens B. Schmitt
NETWORKING2
2004 Optimizing interconnection policies
Oliver Heckmann, Jens B. Schmitt, Ralf Steinmetz
Comput. Networks2
2004 Modeling mobility and workload for wireless metropolitan area networks
Matthias Hollick, Tronje Krop, Jens B. Schmitt, Hans-Peter Huth, Ralf Steinmetz
Comput. Commun.3
2004 A Modular Approach to Mobile QoS Signaling- Motivation, Design & Implementation
Nicole Karsten-Beriér, Martin Karsten, Jens B. Schmitt, Ralf Steinmetz
Multim. Tools Appl.3
2003 Per-flow guarantees under class-based priority queueing
abstract
We present an admission control scheme which provides per-flow delay and bandwidth guarantees based solely upon simple class-based strict priority queueing. We derive basic properties of the worst-case behaviour in strict priority queueing systems using network calculus. Building upon these properties, a flow admission control scheme is devised. The rationale behind this work is the appealing simplicity as well as the almost ubiquitous availability of strict priority queueing in today's routers and the thus promising applicability of our results for practical purposes in providing quality of service (QoS) in the Internet.
Jens B. Schmitt, Paul Hurley, Matthias Hollick, Ralf Steinmetz
GLOBECOM1
2003 Equation-based approach to TCP-compatible multicast congestion control for layered transmission in low-multiplexing environments
abstract
Multi-rate multicast has been proposed as a scalable solution to transmitting video over the Internet to receivers with heterogeneous and dynamic rate requirements. The applicability of an equation-based mechanism to congestion control for a protocol which bases its join and leave actions on the calculation of the TCP response function is investigated. We focus on the rate calculation algorithm proposed in TFRC (TCP-friendly rate control), as it is currently a very promising and mature approach to calculating a TCP-compatible rate. By means of a network simulator and an adjusted TFRC protocol implementation, we show that the TCP-compatible rate calculated with the algorithm as originally proposed tends to be biased when applied in environments with a low degree of statistical multiplexing. To improve the performance of the basic algorithm, we propose a simple heuristic approach.
Ivica Rimac, W. A. Liese, Jens B. Schmitt, Ralf Steinmetz
IPCCC3
2003 Quality of Availability: Replica Placement for Widely Distributed Systems
Giwon On, Jens B. Schmitt, Ralf Steinmetz
IWQoS2
2003 Subjective Impression of Variations in Layer Encoded Videos
Michael Zink, Oliver Künzel, Jens B. Schmitt, Ralf Steinmetz
IWQoS3
2003 Comparative Analysis of Quality of Service Routing in Wireless Metropolitan Area Networks
abstract
Currently, we see the evolution of large scale community and metropolitan area networks based on inexpensive wireless local area network technology. We present the results of an experimental analysis, which investigates the potential of quality of service routing mechanisms within this challenging environment. Our investigation is based on a model of a radio access network designed to cover a large city center by means of decentralized and distributed routers, which are tightly meshed. The workload is modeled to reflect the estimated usage patterns based on statistical data collection of user mobility and combined with synthetic traffic matrices. We present results for various routing strategies including shortest path routing, delay constrained routing as well as various multipath quality of service routing variants. Moreover, we investigate different traffic distributions. Our findings are, that multipath routing is able to enhance the utility of the network significantly.
Matthias Hollick, Tronje Krop, Jens B. Schmitt, Hans-Peter Huth, Ralf Steinmetz
LCN3
2003 The Effectiveness of Realistic Replication Strategies on Quality of Availability for Peer-to-Peer Systems
abstract
We take an availability-centric view on quality of service (QoS) and propose a model and mechanisms for studying the effectiveness of realistic replication schemes on availability QoS for peer-to-peer (P2P) systems. We especially tackle the dynamic replica placement (RP) problem where our focus is on choosing dynamically the number and location of replicas while (1) meeting different availability QoS requirements for all individual peers and (2) taking the intermittent connectivity of peers explicitly into account. We model P2P systems as a dynamic stochastic graph in which the nodes go up and down depending on their assigned up probability. We develop some simple heuristic algorithms for solving the RP problem, which are fully distributed and adaptive. Through an event-driven simulation study we compare and evaluate the achieved availability QoS of the proposed RP algorithms. Simulation results show that (1) even simple heuristics can achieve reasonably high availability QoS, and (2) satisfying availability QoS requires more replicas than for only increasing the hit rate.
Giwon On, Jens B. Schmitt, Ralf Steinmetz
Peer-to-Peer Computing2
2002 On the allocation of network service curves for bandwidth/delay-decoupled scheduling disciplines
abstract
Providing quality of service (QoS) guarantees in packet-switched networks like the Internet has been and still is an important research area. In particular, it is important to ensure strict (deterministic) guarantees for highly time-sensitive data flows. In this paper, we discuss how to efficiently allocate service curves for deterministically guaranteed services. We focus on bandwidth/delay-decoupled service disciplines and their respective service curves due to their distinct advantages over purely rate-based schedulers. Resource-optimal network service curves for deterministic service flows scheduled by bandwidth/delay-decoupled service disciplines are derived and their performance is discussed by numerical examples.
Jens B. Schmitt
GLOBECOM1
2002 Decoupling different time scales of network QoS systems
Jens B. Schmitt, Oliver Heckmann, Martin Karsten, Ralf Steinmetz
Comput. Commun.1
2001 Replication for a Distributed Multimedia System
abstract
Replicating data and services at multiple networked computers increases the service availability of distributed systems. This paper presents the design and implementation architecture of a replication mechanism for a distributed multimedia system medianode which is developed as an infrastructure to share multimedia-enhanced teaching materials among lecture groups. With the replication mechanism, medianode provides enhanced access to presentation materials in both connected and disconnected operation modes. The main contribution of this paper is the identification of new replication requirements in distributed media systems and a multicast-based update propagation mechanism by which not only the update events are signaled, but also the updated data are exchanged between replication managers.
Giwon On, Michael Zink, Michael Liepert, Carsten Griwodz, Jens B. Schmitt, Ralf Steinmetz
ICPADS5
2001 Implementation and Evaluation of the KOM RSVP Engine
abstract
We describe implementation aspects and performance results of an innovative and publicly available RSVP implementation. Much debate exists about the applicability of RSVP as a signalling protocol in the Internet, particularly for a large number of unicast flows. While there has been a significant amount of work published on the theoretical concepts of RSVP signalling and conjectures about its presumed shortcomings, rather little attention has been paid to the implementation details of the core protocol engine. With our work, in spite of being still far from a final judgement, we try to shed light on this issue by presenting certain design details of a new implementation and a study about its performance. One particular result is given by the observation that a relatively cheap router based on PC hardware can sustain the signalling for more than 50,000 unicast flows.
Martin Karsten, Jens B. Schmitt, Ralf Steinmetz
INFOCOM2
2001 Multi-Period Resource Allocation at System Edges -- Capacity Management in a Multi-Provider Multi-Service Internet
abstract
Providing guaranteed QoS necessarily requires allocation of scarce resources. It is conceivable that at least at system edges scarcity of resources, exposed in the form of non-negligible (virtual) costs, will prevail to necessitate explicit allocation of resources as opposed to pure over-dimensioning. An example of this logic is constituted by the Differentiated Services (DiffServ) architecture. Often such resource allocation decisions are done on a multi-period basis because resource allocation decisions at a certain point in time may depend on earlier decisions and thus it can turn out sub-optimal to look at decisions in an isolated fashion. Therefore, we investigate a fairly large and diverse set of (network) QoS problems all of which deal with the problem of multi-period resource allocation at system edges. We devise a taxonomy for the classification of these problems and introduce a common mathematical framework under which these problems can be tackled. The ultimate goal of our work is to strive for solution techniques towards the generalized class of problems such that these are applicable in a number of scenarios which have so far not been regarded in an integrated fashion.
Oliver Heckmann, Jens B. Schmitt, Ralf Steinmetz
LCN2
2001 On the aggregation of deterministic service flows
Jens B. Schmitt, Martin Karsten, Ralf Steinmetz
Comput. Commun.1
2000 Layered Network QoS Signalling - Motivation, Implementation & Measurements
abstract
The support of a single signalling protocol for all components on the data path of a QoS-based transmission cannot necessarily be assumed. We investigate the issues surrounding hierarchically layered network QoS signalling configurations, as e.g. can be found in RSVP over ATM signalling. After introducing and discussing these issues we conclude that many of the decisions involved require understanding the performance characteristics of such layered signalling configurations. We therefore describe the implementation of an RSVP/ATM edge device, which we then use to conduct measurements in a configuration that involves in effect three layered signalling protocols: RSVP and ATM's UNI and PNNI. Using these measurements we review the issues in layering signalling protocols and reinforce design decisions being taken for the edge device mediating between the different mechanisms of the two network QoS architectures.
Jens B. Schmitt, Martin Karsten, Ralf Steinmetz
LCN1
2000 Charging for packet-switched network communication - motivation and overview
Martin Karsten, Jens B. Schmitt, Burkhard Stiller, Lars C. Wolf
Comput. Commun.2
1996 Finding the Conformation of Organic Molecules with Genetic Algorithms
Susanne Beiersdörfer, Jens B. Schmitt, Markus Sauer, Andreas Schulz, Stefan Siebert 0003, Jürgen Hesser, Reinhard Männer, Jürgen Wolfrum
PPSN2