<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Bartolomeo Müller | UCS</title><link>/author/bartolomeo-muller/</link><atom:link href="/author/bartolomeo-muller/index.xml" rel="self" type="application/rss+xml"/><description>Bartolomeo Müller</description><generator>Hugo Blox Builder (https://hugoblox.com)</generator><language>en-us</language><lastBuildDate>Thu, 25 Sep 2025 00:00:00 +0000</lastBuildDate><image><url>/author/bartolomeo-muller/avatar_hu9352006733666497755.jpg</url><title>Bartolomeo Müller</title><link>/author/bartolomeo-muller/</link></image><item><title>ATHENE Usable Security and Privacy Lab</title><link>/post/2025-09-26-usp-lab-launch/</link><pubDate>Thu, 25 Sep 2025 00:00:00 +0000</pubDate><guid>/post/2025-09-26-usp-lab-launch/</guid><description>&lt;h2 id="participation-welcome-launch-of-the-athene-usable-security-and-privacy-lab-at-h_da">Participation welcome: Launch of the ‘ATHENE Usable Security and Privacy Lab’ at h_da&lt;/h2>
&lt;p>At the beginning of October, the ‘ATHENE Usable Security and Privacy Lab’ (USP Lab) began its work at h_da. The lab is run by the User-Centered Security working group and supported by the National Research Center for Applied Cybersecurity ATHENE. Researchers and students at h_da can use the lab for projects and studies on the usability of security and privacy related technologies. The focus lies on questions of how security and privacy technologies can be designed to support users in making informed decisions and effectively protect their personal data. This includes, for example, the comprehensible presentation of privacy policies or transparent cookie banners that openly explain which data are processed and in what form when using an application. Research into user behaviour is also of great interest, for example regarding trust in AI tools and the information users may reveal.&lt;/p>
&lt;p>The USP Lab has comprehensive technical resources and offers methodological support to investigate such issues, for example through usability tests on PCs or mobile devices, user interviews, surveys, eye tracking and more. The laboratory is located in building D19, room 02.12, and can also be used for teaching purposes. Researchers who are not members of ATHENE can request to use the USP Lab at any time. The laboratory website also provides detailed explanations and instructions. If required, the team will be happy to assist you with individual methodological consultation. In addition, the website provides all the necessary information on booking the laboratory and the available equipment. If you have any questions, please contact us (&lt;a href="mailto:usp-lab@h-da.de">usp-lab@h-da.de&lt;/a>).&lt;/p></description></item><item><title>Benchmarking von PQC KEM Algorithmen in QUIC unter variierenden Netzwerkbedingungen</title><link>/theses/2025-mueller/</link><pubDate>Tue, 25 Feb 2025 00:00:00 +0000</pubDate><guid>/theses/2025-mueller/</guid><description>&lt;h2 id="abstract">Abstract&lt;/h2>
&lt;p>The advent of cryptographically relevant quantum computers threatens the currently used classical asymmetric cryptography. Attackers can already record network traffic today, intending to decrypt it later using cryptographically relevant quantum computers. In order to continue to guarantee the security of asymmetric cryptography, post-quantum cryptography (PQC) is being adopted. While the performance of these primitives in isolation is usually well understood, their performance within some protocols remains insufficiently investigated. QUIC is a new general-purpose transport protocol of the IETF but requires further study of PQC Key Encapsulation Mechanism (KEM) algorithms. Thorough investigation of PQC KEM algorithms in QUIC across varying network conditions is therefore highly important to accompany the migration to PQC.&lt;/p>
&lt;p>In this work, handshakes are repeatedly performed in QUIC and comparatively in TLS1.3/TCP in an emulated network and the Time to First Byte is measured. The network conditions, algorithms, and congestion control algorithms are varied across different network scenarios and security levels and then evaluated.&lt;/p>
&lt;p>While the obvious choice is always the algorithm with the shortest calculation time and transmission length, this is not the case in QUIC. Here, it is worth sending a moderate amount of packets in case of random packet loss so that not too many lost packets have to be retransmitted, but the communication is also not initially delayed by a second. ML-KEM is the best choice in every scenario except for high random packet loss. If ML-KEM is not available, the recommendation is not clear, as it varies depending on the scenario and security level between BIKE and HQC. HQC is the better choice if the network conditions are good or if there is a high-latency scenario due to the low calculation time of the KEM operations. BIKE, with its shorter transmission length, is the better choice at low transmission rates, high jitter and at security level 5 with high latency, as the initial packets of the server from HQC do not fit into the initial congestion control window. In case of random packet loss, both BIKE and HQC are good algorithms, HQC rather in lower security levels and at high packet loss, BIKE at lower packet loss and higher security level.&lt;/p>
&lt;p>Future research should extend the investigation to PQC signature algorithms in QUIC, further supporting the migration to PQC.&lt;/p></description></item></channel></rss>