Karl NorrmanView profile
Researcher
Karl Norrman is an Industry doctoral student and Researcher at the Department of Theoretical Computer Science (TCS) at KTH Royal Institute of Technology, concurrently working as a Security Researcher at Ericsson Research since 2001. His academic appointment at KTH is part-time (20% time allocation), while he spends the majority of his time (80%) at Ericsson, where he holds the formal title of Expert Mobile Network Security. He is supervised by Professor Mads Dam for his doctoral studies and receives partial research funding from the Wallenberg AI, Autonomous Systems and Software Program (WASP). His educational background includes: PhD candidate in Computer Science at KTH Royal Institute of Technology, Department of Theoretical Computer Science (ongoing). Research focuses on formal modeling and proofs for cryptographic protocols using pen-and-paper proofs and mechanized proof-support tools such as Tamarin and EasyCrypt. Master's degree in Computer Science from Stockholm University, Department of Mathematics (2001). Thesis: "RTP Security in 3G Networks." During this work, he contributed to the development of the Secure Real-time Transport Protocol (SRTP), standardized in IETF as RFC 3711. Norrman's research centers on formal methods for security protocol verification , with particular expertise in cryptographic protocol analysis, modeling, and mechanized proof techniques. His work bridges theoretical computer science and practical security applications, focusing on making formal verification tools accessible for industrial adoption. Key research areas include 5G/6G security architectures, privacy-preserving mechanisms for mobile networks, authentication and key agreement protocols, and software security. He advocates for "goal oriented and motivated security designs" that balance theoretical rigor with practical implementation constraints while specializing in translating complex security requirements into implementable solutions for telecommunications infrastructure. Analysis of Norrman's publication history reveals a consistent evolution from foundational work on SRTP (2002-2007) through LTE security analysis (2014-2015) to pioneering 5G security research (2016-2020) and now 6G security exploration (2024). His work demonstrates methodological progression from analyzing existing protocols to designing novel security mechanisms and developing verification frameworks like OpenSAW. A distinctive pattern is his focus on industrial applicability —ensuring theoretical security models translate to real-world implementations, particularly evident in his work on USIM-compatible protocols and error-correcting authentication for noisy wireless channels. Recent publications increasingly address cross-domain challenges like secure federated learning in mobile networks, reflecting the expanding scope of telecommunications security. Professional engagement: Reviewer for ACM CCS 2023, EURO S&P 2023, ACM CCS 2022, NordSec 2022, Vietcrypt 2006, IEEE Telecommunications Journal Active contributor to 3GPP security standardization processes Co-author on multiple Ericsson whitepapers shaping industry security practices Norrman maintains a unique dual affiliation that enables direct translation of academic research into industrial security solutions. At KTH, he contributes to the Theoretical Computer Science group's formal methods research, while at Ericsson he applies these techniques to real-world security challenges in mobile network development. His work on OpenSAW exemplifies this bridge between academia and industry, creating practical tools for automated security testing of component-based software systems. This position allows him to identify emerging security challenges in next-generation networks while maintaining theoretical rigor in his approach.

