Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Andrés Marín López

dblp:00/535 · also Andrés Marín · DBLP profile ↗
← Back
20ranked-venue papers
1as first author
2since 2021 · last 2024
0000-0001-9350-0669ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 6 · 1 first-author · 1 since 2021Security and privacy · 5Human-computer interaction and ubiquitous computing · 3Systems, architecture and hardware · 2 · 1 since 2021Software engineering, systems software and programming languages · 1Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
4 papers
Cryptographic protocols and secure computation · 39% Authentication and access control · 25% Usable security · 16%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
Electronic design automation · 100%

Topics — the 13 heaviest of 16, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Cryptographic protocols and secure computation › key management › public key infrastructure
certificate validation
0.422018
RiskLaine: A Probabilistic Approach for Assessing Risk in Certificate-Based Security · IEEE Trans. Inf. Forensics Secur. 2018
Building an Open Toolkit of Digital Certificate Validation for Mobile Web Services · PerCom 2008
Cryptographic protocols and secure computation › key management
public key infrastructure
0.422018
RiskLaine: A Probabilistic Approach for Assessing Risk in Certificate-Based Security · IEEE Trans. Inf. Forensics Secur. 2018
Building an Open Toolkit of Digital Certificate Validation for Mobile Web Services · PerCom 2008
Authentication and access control › password security › password management
password managers
0.412019
"I don't see why I would ever want to use it": Analyzing the Usability of Popular Smartphone Password Managers · CCS 2019
Systems and software security
risk assessment
0.312018
RiskLaine: A Probabilistic Approach for Assessing Risk in Certificate-Based Security · IEEE Trans. Inf. Forensics Secur. 2018
Authentication and access control › mobile authentication
smartphone authentication
0.112019
"I don't see why I would ever want to use it": Analyzing the Usability of Popular Smartphone Password Managers · CCS 2019
Web and mobile security
mobile application security
0.112018
RiskLaine: A Probabilistic Approach for Assessing Risk in Certificate-Based Security · IEEE Trans. Inf. Forensics Secur. 2018
Cryptographic protocols and secure computation › secure data sharing
secure file sharing
0.112008
A Trust-based Middleware for Providing Security to Ad-Hoc Peer-to-Peer Applications · PerCom 2008
Authentication and access control
trust management
0.112008
A Trust-based Middleware for Providing Security to Ad-Hoc Peer-to-Peer Applications · PerCom 2008
Electronic design automation
hardware description language
0.011997
A Refinement Calculus for the Synthesis of Verified Hardware Descriptions in VHDL · ACM Trans. Program. Lang. Syst. 1997
Electronic design automation › hardware verification and test
hardware verification
0.011997
A Refinement Calculus for the Synthesis of Verified Hardware Descriptions in VHDL · ACM Trans. Program. Lang. Syst. 1997
Electronic design automation › hardware description language
VHDL
0.011997
A Refinement Calculus for the Synthesis of Verified Hardware Descriptions in VHDL · ACM Trans. Program. Lang. Syst. 1997
Logic in computer science › program logic
hoare logic
0.011997
A Refinement Calculus for the Synthesis of Verified Hardware Descriptions in VHDL · ACM Trans. Program. Lang. Syst. 1997
Logic in computer science
program logic
0.011997
A Refinement Calculus for the Synthesis of Verified Hardware Descriptions in VHDL · ACM Trans. Program. Lang. Syst. 1997

Methods — techniques the papers use, named apart from their topics

think-aloud protocol · 0.4system usability scale · 0.4empirical user study · 0.4trust management · 0.3probabilistic modeling · 0.3refinement · 0.0formal semantics · 0.0
YearPublicationVenuePosition
2024 Evaluating integration methods of a quantum random number generator in OpenSSL for TLS
abstract
The rapid advancement of quantum computing poses a significant threat to conventional cryptography. Whilst post-quantum cryptography (PQC) stands as the prevailing trend for fortifying the security of cryptographic systems, the coexistence of quantum and classical computing paradigms presents an opportunity to leverage the strengths of both technologies, for instance, nowadays the use of Quantum Random Number Generators (QRNGs) – considered as True Random Number Generators (TRNGs) – opens up the possibility of discussing hybrid systems. In this paper, we evaluate both aspects, on the one hand, we use hybrid TLS (Transport Layer Security) protocol that leverages the widely used secure protocol on the Internet and integrates PQC algorithms, and, on the other hand, we evaluate two approaches to integrate a QRNG, i.e., Quantis PCIe-240M, in OpenSSL 3.0 to be used by TLS. Both approaches are compared through a Nginx Web server, that uses OpenSSL’s implementation of TLS 1.3 for secure web communication. Our findings highlight the importance of optimizing such integration method, because while direct integration can lead to performance penalties specific to the method and hardware used, alternative methods demonstrate the potential for efficient QRNG deployment in cryptographic systems.
Javier Blanco-Romero, Vicente Lorenzo, Florina Almenárez, Daniel Díaz Sánchez, Carlos García-Rubio, Celeste Campo, Andrés Marín López
Comput. Networks7
2023 Kriper: A blockchain network with permissioned storage
abstract
Blockchain has been a revolution in the past few years. Beyond the new currencies that were created around different incarnations of the blockchain concept, there are many other contributions that provide interesting services as a data linked structure using a decentralized network that provide a high level of security. Companies have developed many projects to incorporate blockchain into their business logic pursuing to incorporate other related services as persistence of large volumes of data, privacy or anonymity of transactions, distributed data processing, security (confidentiality, integrity, and availability), document management or micro messages in real time. Nevertheless, as it will be discussed in this article, current blockchains do not meet the needs of companies in many aspects, leading to a scarce or superficial adoption. This article introduces Kriper, a blockchain that aims at meeting corporate world needs by responding with a community-based, open blockchain that may also be segregated and private for certain uses whereas it provides a permissioned distributed storage and micro message lightweight services.
María Isabel Rojo-Rivas, Daniel Díaz Sánchez, Florina Almenárez, Andrés Marín López
Future Gener. Comput. Syst.4
2019 "I don't see why I would ever want to use it": Analyzing the Usability of Popular Smartphone Password Managers
abstract
Passwords are an often unavoidable authentication mechanism, despite the availability of additional alternative means. In the case of smartphones, usability problems are aggravated because interaction happens through small screens and multilayer keyboards. While password managers (PMs) can improve this situation and contribute to hardening security, their adoption is far from widespread. To understand the underlying reasons, we conducted the first empirical usability study of mobile PMs, covering both quantitative and qualitative evaluations. Our findings show that popular PMs are barely acceptable according to the standard System Usability Scale, and that there are three key areas for improvement: integration with external applications, security, and user guidance and interaction. We build on the collected evidence to suggest recommendations that can fill this gap.
Sunyoung Seiler-Hwang, Patricia Arias Cabarcos, Andrés Marín López, Florina Almenárez, Daniel Díaz Sánchez, Christian Becker 0001
CCS3
2018 Speeding-Up DPI Traffic Classification with Chaining
abstract
The importance of network traffic classification has grown over the last two decades in line with the increasing diver- sity of networked applications. Nowadays traditional approaches to traffic classification, relying on port numbers and on Deep Packet Inspection (DPI), are not very effective in real scenarios respectively due to the usage of random or non-standard port numbers and to the wide usage of end-to-end encryption. Despite their limitations, port- based and DPI approaches are still widely used in operational networks for a number of network monitoring and management tasks. This paper proposes a practical approach for improving the efficiency of traditional traffic classification techniques by chain- ing fast classification stages (port-based and machine-learning- based), combined to lower their false-positive rate, and a more precise - but time- and resource-demanding - stage based on DPI. Experimental results demonstrate that Chain obtains results in line with DPI approaches in term of Precision, Recall, Accuracy and Area Under the Curve (AUC), while it is 45% faster when compared to nDPIng, a well- known DPI implementation. The appealing of the proposed approach in Network Function Virtualization (NFV) contexts is also discussed.
Hossein Doroud, Giuseppe Aceto, Walter de Donato, Elnaz Alizadeh Jarchlo, Andrés Marín López, César D. Guerrero, Antonio Pescapè
GLOBECOM5
2018 RiskLaine: A Probabilistic Approach for Assessing Risk in Certificate-Based Security
abstract
Digital certificates, based on X.509 PKI standard, are located at the core of many security mechanisms implemented in services and applications. However, the usage of certificates has revealed flaws in the certificate validation process (e.g., possibility of unavailable or non-updated data). This fact implies security risks that are not assessed. In order to address these issues that such flaws entail, we propose a novel probabilistic approach for quantitative risk assessment in X.509 PKI, together with trust management when there is uncertainty. We have evaluated our risk assessment approach and demonstrated its usage, considering as a use case the secure installation of mobile applications. The results show that our approach provides more granularity, appropriate values according to the impact, and relevant information in the risk calculation than other approaches.
M. Francisca Hinarejos, Florina Almenárez, Patricia Arias Cabarcos, Josep-Lluís Ferrer-Gomila, Andrés Marín López
IEEE Trans. Inf. Forensics Secur.5
2017 Collaborative eHealth Meets Security: Privacy-Enhancing Patient Profile Management
abstract
Collaborative healthcare environments offer potential benefits, including enhancing the healthcare quality delivered to patients and reducing costs. As a direct consequence, sharing of electronic health records (EHRs) among healthcare providers has experienced a noteworthy growth in the last years, since it enables physicians to remotely monitor patients' health and enables individuals to manage their own health data more easily. However, these scenarios face significant challenges regarding security and privacy of the extremely sensitive information contained in EHRs. Thus, a flexible, efficient, and standards-based solution is indispensable to guarantee selective identity information disclosure and preserve patient's privacy. We propose a privacy-aware profile management approach that empowers the patient role, enabling him to bring together various healthcare providers as well as user-generated claims into an unique credential. User profiles are represented through an adaptive Merkle Tree, for which we formalize the underlying mathematical model. Furthermore, performance of the proposed solution is empirically validated through simulation experiments.
Rosa Sánchez-Guerrero, Florina Almenárez, Daniel Díaz Sánchez, Patricia Arias Cabarcos, Andrés Marín López
IEEE J. Biomed. Health Informatics5
2016 PECEVA: An adaptable and energy-saving credential validation solution for pervasive networks
Florina Almenárez, M. Francisca Hinarejos, Andrés Marín López, Josep-Lluís Ferrer-Gomila, Daniel Díaz Sánchez
Inf. Sci.3
2011 Trust management for multimedia P2P applications in autonomic networking
Florina Almenárez, Andrés Marín López, Daniel Díaz Sánchez, Alberto Cortés-Martín, Celeste Campo, Carlos García-Rubio
Ad Hoc Networks2
2010 Introducing Infocards in NGN to Enable User-Centric Identity Management
abstract
With the rapid evolution of networks and the widespread penetration of mobile devices with increasing capabilities, that have already become a commodity, we are getting a step closer to ubiquity. Thus, we are moving a great part of our lives from the physical world to the online world, i.e. social interactions, business transactions, relations with government administrations, etc. However, while identity verification is easy to handle in the real world, there are many unsolved challenges when dealing with digital identity management, especially due to the lack of user awareness when it comes to privacy. Thus, with the aim to enhance the navigation experience and security in multiservice and multiprovider environments the user must be empowered to control how her attributes are shared and disclosed between different domains.With these goals on mind, we leverage the benefits of the Infocard technology and introduce this usercentric paradigm into the emerging NGN architectures. This paper proposes a way to combine the gains of a SAML federation between service and identity providers with the easiness for the final user of the Inforcard System using the well known architectural schema of IP Multimedia Subsystem.
Davide Proserpio, Fabio Sanvido, Patricia Arias Cabarcos, Rosa Sánchez-Guerrero, Florina Almenárez, Daniel Díaz Sánchez, Andrés Marín López
GLOBECOM7
2010 Pervasive authentication and authorization infrastructures for mobile users
Jordi Forné, M. Francisca Hinarejos, Andrés Marín López, Florina Almenárez, Javier López 0001, José A. Montenegro, Marc Lacoste, Daniel Díaz Sánchez
Comput. Secur.3
2009 Towards dynamic trust establishment for identity federation
abstract
Federation has emerged as a key concept for identity management, as it is the basis to reduce complexity in the companies and improve user experience. However, the problem of establishing identity federations in dynamic open environments, where it is desirable to speed up the processes of service provisioning and deprovisioning, has not been fully addressed. This paper reviews the existing frameworks for identity federation, analyzing the underlying trust mechanisms and its suitability to be applied in the mentioned environments. Finally, we propose a generic extension for the Security Assertion Markup Language (SAML) standard in order to facilitate the creation of federation relationships in a secure dynamic way between prior unknown parties.
Florina Almenárez, Patricia Arias Cabarcos, Andrés Marín López, Daniel Díaz Sánchez
EATIS3
2008 A Trust-based Middleware for Providing Security to Ad-Hoc Peer-to-Peer Applications
abstract
Trust has emerged as an important facet of inter-domain relationships. Trust management in fixed networks is not functional in ad hoc P2P networks, because these require an autonomous, user-centric and non-static trust management. The trust model is the basis of any security infrastructure. In this paper, we propose a trust-based middleware for secure digital content sharing between pervasive devices. Such middleware allows to enhance security support of pervasive devices. Likewise, we propose a suitable and efficient secure file exchange protocol, WSFEP, for content sharing. Both middleware and file sharing application have been successfuly integrated and tested on PDAs.
Florina Almenárez, Andrés Marín López, Daniel Díaz Sánchez, Alberto Cortés-Martín, Celeste Campo, Carlos García-Rubio
PerCom2
2008 Building an Open Toolkit of Digital Certificate Validation for Mobile Web Services
abstract
Mobile devices can both consume and provide services. They act indeed as a peer, according to the OMA mobile Web services specification. It is a move from simple data sharing to full deliver of application services down to mobile devices. The use of digital certificates to ensure the provision of services is suitable because devices can belong to different trust domains without having previously an established relationship. Besides, by interoperability issues, the use of PKI continues to grow and move into diverse environments. However, applications making use of such certificates are burdened with the overhead of constructing and validating the certification paths. These processes can become more complex and costly than fixed-infrastructure networks due to the wireless communications and restricted processing and power capabilities. The IETF PKIX WG has specified different mechanisms for delegating the certificate validation and making lighter the status information obtaining. However, these are not supported currently by mobile devices. For these reasons, we propose to develop an open toolkit for X.509 public key certificate validating based on OpenSSL. This toolkit is being developed and tested successfully in PDAs.
Florina Almenárez, Andrés Marín López, Daniel Díaz Sánchez, Alberto Cortés-Martín, Celeste Campo, Carlos García-Rubio
PerCom2
2007 Access Control Agnostic Trust Negotiation Decision Engine
abstract
Dynamic open environments demand trust negotiation systems for unknown entities willing to communicate. A security context have to be negotiated gradually in a fair peer to peer basis. Trust negotiation engines are driven by decision engines that lack of flexibility: they depend on the implementation, policies languages or credentials types to be used. In this paper we present a trust negotiation engine agnostic regarding policies and rules. The engine is based on iterative weighted Multidimensional Scaling to assist a mobile device during a trust negotiation.
Daniel Díaz Sánchez, Andrés Marín López, Florina Almenárez
PIMRC2
2007 Smart card-based agents for fair non-repudiation
Andrés Marín López, Daniel Díaz Sánchez, Florina Almenárez, Carlos García-Rubio, Celeste Campo
Comput. Networks1
2006 A Smart Card Solution for Access Control and Trust Management for Nomadic Users
Daniel Díaz Sánchez, Andrés Marín López, Florina Almenárez
CARDIS2
2006 PDP: A lightweight discovery protocol for local-scope interactions in wireless ad hoc networks
Celeste Campo, Carlos García-Rubio, Andrés Marín López, Florina Almenárez
Comput. Networks3
2004 Secure Ad-Hoc mBusiness: EnhancingWindowsCE Security
Florina Almenárez, Daniel Díaz Sánchez, Andrés Marín López
TrustBus3
1997 A Refinement Calculus for the Synthesis of Verified Hardware Descriptions in VHDL
abstract
A formal refinement calculus targeted at system-level descriptions in the IEEE standard hardware description language VHDL is described here. Refinement can be used to develop hardware description code that is “correct by construction”. the calculus is closely related to a Hoare-style programming logic for VHDL and real-time systems in general. That logic and a semantics for a core subset of VHDL are described. The programming logic and the associated refinement calculus are shown to be complete. This means that if there is a code that can be shown to implement a given specification, then it will be derivable from the specification via the calculus.
Peter T. Breuer, Carlos Delgado Kloos, Andrés Marín López, Natividad Martínez Madrid, Luis Sánchez-Fernández 0001
ACM Trans. Program. Lang. Syst.3
1993 VHDL generation from a timed extension of the formal description technique LOTOS within the FORMAT project
Carlos Delgado Kloos, Tomás de Miguel, Tomás Robles 0001, Guadalberto Rabay Filho, Andrés Marín López
Microprocess. Microprogramming5