Dr.-Ing. André Schaller
Independent cyber security consultant combining academic depth with hands-on delivery — from the formal analysis of cryptographic protocols to penetration testing of production systems.

I help organizations understand what their systems can really withstand — with an honest, evidence-based view of actual risk, free of scaremongering or sales pressure.
My work spans security architecture reviews, cryptographic implementation, and offensive testing. I advise vendor-neutrally: my recommendations follow your risk, not a product catalog.
I work as a Security Engineer at EUMETSAT and provide my expertise in cyber security as a freelancer. Prior to that I have been working as a Cyber Security researcher at CYSEC / Technical University Darmstadt, Germany, where I graduated as a Doctor of Engineering as a member of the Security Engineering research group. Working on cutting-edge Cyber Security research projects, I gained experience in various fields including information security, engineering of secure protocols and applications, lightweight cryptography and security of embedded devices.
Focus areas
- Security architecture & threat modeling
- Applied cryptography & protocol analysis
- Penetration testing & secure code review
- Information security risk assessments (ISO 27001)
- Incident response planning & Unix/Linux hardening
Selected publications
Peer-reviewed work on physically unclonable functions, lightweight cryptography and the security of embedded and IoT devices.
Abusing Commodity DRAMs in IoT Devices to Remotely Spy on Temperature
F. Frank, W. Xiong, N. A. Anagnostopoulos, A. Schaller, T. Arul, F. Koushanfar, S. Katzenbeisser, U. Rührmair, J. Szefer
Software Protection Using Dynamic PUFs
W. Xiong, A. Schaller, S. Katzenbeisser, J. Szefer
Decay-Based DRAM PUFs in Commodity Devices
A. Schaller, W. Xiong, N. A. Anagnostopoulos, M. U. Saleem, S. Gabmeyer, B. Skoric, S. Katzenbeisser, J. Szefer
Eliminating Leakage in Reverse Fuzzy Extractors
A. Schaller, T. Stanko, B. Skoric, S. Katzenbeisser
Lightweight Protocols and Applications for Memory-Based Intrinsic Physically Unclonable Functions on Commercial Off-The-Shelve Devices
A. Schaller
Boot Attestation: Secure Remote Reporting with Off-The-Shelf IoT Sensors
S. Schulz, A. Schaller, F. Kohnhäuser, S. Katzenbeisser
Intrinsic Rowhammer PUFs: Leveraging the Rowhammer Effect for Improved Security
A. Schaller, W. Xiong, N. A. Anagnostopoulos, M. U. Saleem, S. Gabmeyer, S. Katzenbeisser, J. Szefer
Run-Time Accessible DRAM PUFs in Commodity Devices
W. Xiong, A. Schaller, N. A. Anagnostopoulos, M. U. Saleem, S. Gabmeyer, S. Katzenbeisser, J. Szefer
Inherent PUFs and Secure PRNGs on Commercial Off-the-Shelf Microcontrollers
A. Van Herrewege, A. Schaller, S. Katzenbeisser, I. Verbauwhede