José-Fernán Martínez

dblp:00/6614 · also José-Fernán Martínez-Ortega · DBLP profile ↗
← Back
29ranked-venue papers
3as first author
10since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 12 · 6 since 2021Human-computer interaction and ubiquitous computing · 5 · 3 first-authorApplied, interdisciplinary, general and emerging computing · 5 · 2 since 2021Systems, architecture and hardware · 3 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2025 A survey on Identity and Access Management for future IoT services
abstract
The explosive advancement of Artificial Intelligence (AI) and Edge Computing (EC) is accelerating the development of the future Internet of Things (IoT), which spans various application domains and has become an integral part of modern life. However, certain limitations of IoT introduce security and privacy challenges for users and enterprises, hindering its broader adoption. Identity and Access Management (IAM), capable of handling the massive scale of digital identities and permissions while ensuring that only authenticated entities can access authorized resources and interact securely, has been widely adopted as an entry point for securing IoT services. However, traditional IAM systems, primarily designed for cloud-based web services, face several challenges, such as scalability and privacy, when integrated into edge-native IoT architectures. This paper provides a systematic review of IAM solutions in IoT environments. It identifies four key requirements for future IoT services, analyzes IAM architecture and the state of the art of its six primary functionalities, namely storage, identity management, authentication, authorization, audit, and federation, and studies ten more comprehensive IAM solutions. A detailed evaluation of aspects such as functionality completeness, security, privacy, and scalability is carried out. Finally, based on the evaluation results, the missing points in the existing literature, as well as upcoming challenges and development trends, are pointed out. The study aims to inspire further research and development efforts towards building a comprehensive IAM solution for edge-enabled IoT services.
Pedro Castillejo, José-Fernán Martínez, Vicente Hernández Díaz
Comput. Networks3
2025 SISS: Semantic Interoperability Support System for the Internet of Things
abstract
The Internet of Things (IoT) landscape is hindered by a critical challenge: the lack of semantic interoperability among diverse data models. Existing IoT solutions often function as isolated data silos, impeding the seamless integration of heterogeneous data sources crucial for informed decision-making and streamlined processes. This research addresses this issue by introducing a pioneering solution: the Semantic Interoperability Support System (SISS). SISS is an innovative tool designed to bridge the semantic divide between disparate data models within a common application domain. To address the lack of interoperability between current IoT platforms, devices, and solutions that use native data models, SISS facilitates integration by enabling the generation of gateways or translator components. These components establish mappings between the semantic properties of source and target data models, leveraging advanced semantic analysis and inference techniques. The core principle underpinning SISS is its ability to discern and map the semantic content of data models. Through a meticulous analysis of the temporal and spatial dimensions inherent in the data, SISS establishes meaningful connections. This innovative approach fosters interoperability and enables a deeper understanding of the underlying information, enhancing the potential for data-driven insights. This paper delves into the pervasive issue of semantic interoperability in the current IoT paradigm and presents SISS as a transformative solution. By emphasizing its ability to transcend the limitations of existing solutions and its methodology to generate mappings between disparate data models, this research contributes to the achievement of global semantic interoperability in IoT.
Mario San Emeterio de la Parte, José-Fernán Martínez, Néstor Lucas-Martínez, Vicente Hernández Díaz
IEEE Internet Things J.2
2025 Edge-enabled IAM for IoTs with edge-based access management and context-driven syncservice
abstract
The number of edge IoT services is experiencing explosive growth. As an entry point for network services, Identity and Access Management (IAM) effectively prevents unauthorized access and blocks most cyber-attacks. However, most edge systems still rely on remote, cloud-based IAM for permission verification. The few edge-enabled IAM solutions that do exist operate on the assumption that attribute values are always up-to-date and provided by a completely trustworthy source, which make access decisions questionable in highly dynamic and distributed IoT environments. To address these challenges, this work proposes EIAM-IoT, an edge-enabled IAM architecture, and an improved Local Authentication and Authorization (LAA) method. The LAA evaluates multi-factor attributes, incorporating the freshness of attribute values and the trustworthiness of attribute providers, to achieve reliable access control. Additionally, the identity information required for LAA is synchronized and stored in the edge database by a context-aware synchronization strategy, which selectively and timely extends relevant identity data based on edge context, optimizing the trade-off between local data management costs and LAA performance. The performance and security analyses show that the LAA does not introduce significant overhead to traditional attribute-based solutions while enabling more fine-grained access control, increasing decision reliability, and offering additional features, such as local verification and federated identity management. While the LAA relies on cloud-extended local data, the system ensures greater availability and resilience to connectivity issues in edge-to-cloud setups. EIAM-IoT is particularly more suitable for dynamic, multi-authority, and edge-native IoT applications to achieve secure, low-latency, offline access to edge IoT services.
José-Fernán Martínez, Pedro Castillejo, Mario San Emeterio de la Parte
J. Syst. Archit.2
2024 Underwater Wireless Sensor Network-Based Delaunay Triangulation (UWSN-DT) Algorithm for Sonar Map Fusion
abstract
Abstract Robust and fast image recognition and matching is an important task in the underwater domain. The primary focus of this work is on extracting subsea features with sonar sensor for further Autonomous Underwater Vehicle navigation, such as the robotic localization and landmark mapping applications. With the assistance of high-resolution underwater features in the Side Scan Sonar (SSS) images, an efficient feature detector and descriptor, Speeded Up Robust Feature, is employed to seabed sonar image fusion task. In order to solve the nonlinear intensity difference problem in SSS images, the main novelty of this work is the proposed Underwater Wireless Sensor Network-based Delaunay Triangulation (UWSN-DT) algorithm for improving the performances of sonar map fusion accuracy with low computational complexity, in which the wireless nodes are considered as underwater feature points, since nodes could provide sufficiently useful information for the underwater map fusion, such as the location. In the simulated experiments, it shows that the presented UWSN-DT approach works efficiently and robustly, especially for the subsea environments where there are few distinguishable feature points.
Xin Yuan 0003, Ning Li 0003, Xiaobo Gong, Changli Yu, Xiaoteng Zhou, José-Fernán Martínez
Comput. J.6
2024 Batch data recovery from gradients based on generative adversarial networks
Yunbo Huang, Yuwen Chen 0002, José-Fernán Martínez, Haiyang Yu 0001, Zhen Yang 0004
Neural Comput. Appl.3
2024 High Efficiency Inference Accelerating Algorithm for NOMA-Based Edge Intelligence
abstract
Even the artificial intelligence (AI) has been widely used and significantly changed our life, deploying the large AI models on resource limited edge devices directly is not appropriate. Thus, the model split inference is proposed to improve the performance of edge intelligence (EI), in which the AI model is divided into different sub-models and the resource-intensive sub-model is offloaded to edge server wirelessly for reducing resource requirements and inference latency. Unfortunately, with the sharp increasing of edge devices, the shortage of spectrum resource in edge network becomes seriously in recent years, which limits the performance improvement of EI. Refer to the NOMA-based edge computing (EC), integrating non-orthogonal multiple access (NOMA) technology with split inference in EI is attractive. However, the NOMA-based communication aspect and the influence of intermediate data transmission fail to be considered properly in model split inference of EI in previous works, and the sophistication in resource allocation caused by NOMA scheme makes it further complicated. Thus, the Effective Communication and Computing resource allocation algorithm is proposed in this paper for accelerating the split inference in NOMA-based EI, shorted as ECC. Specifically, the ECC takes the energy consumption and the inference latency into account to find the optimal model split strategy and resource allocation strategy (subchannel, transmission power, computing resource). Since the minimum inference delay and energy consumption cannot be satisfied simultaneously, the gradient descent (GD) based algorithm is adopted to find the optimal tradeoff between them. Moreover, the loop iteration GD approach (Li-GD) is developed to reduce the complexity of the GD algorithm caused by parameter discretization. The key idea of Li-GD is that: the initial value of the$i\mathrm {th}$layer’s GD procedure is selected from the optimal results of the former$(i-1)$layers’ GD procedure whose intermediate data size is the closest to$i\mathrm {th}$layer. Additionally, the properties of the proposed algorithms are investigated, including convergence, complexity, and approximation error. The experimental results demonstrate that the performance of ECC is much better than that of the previous studies.
Xin Yuan 0003, Ning Li 0003, Muqing Li, Yuwen Chen 0002, José-Fernán Martínez, Song Guo 0001
IEEE Trans. Wirel. Commun.6
2023 Trapezoidal Sketch: A Sketch Structure for Frequency Estimation of Data Streams
abstract
Abstract The sketch is one of the typical and widely used data structures for estimating the frequencies of items in data streams. However, since the counter sizes in traditional rectangular sketch (r-sketch) are the same, it is hard to achieve small space usage, high capacity (i.e. the maximum frequency can be recorded) and high estimated accuracy simultaneously. Moreover, when considering the high skewness of data streams, this problem will become even worse. Consequently, we propose the trapezoidal sketch (t-sketch) in this paper. In the t-sketch, different from the r-sketch, the counter sizes in different layers are different. Therefore, the low space usage and high capacity can be achieved simultaneously in the t-sketch. Moreover, based on the basic t-sketch, we propose the space-saving t-sketch and the capacity-improvement t-sketch and analyze the properties of these two t-sketches. Finally, for improving the estimation accuracy of the t-sketch further, we propose the probabilistic-based estimation error-reducing algorithm. Compared with the CM sketch, CU sketch, C sketch and A sketch, the simulation results show that the performances on space usage, capacity and estimation accuracy are improved successfully by the space-saving t-sketch and the capacity-improvement t-sketch.
Ning Li 0003, Xin Yuan 0003, José-Fernán Martínez, Vicente Hernández Díaz
Comput. J.3
2023 A Resilient Group-Based Multisubset Data Aggregation Scheme for Smart Grid
abstract
Smart meters are deployed in the smart grid to achieve bidirectional communication, the control center can monitor, predict energy consumption data in real time, and adjust energy supply dynamically. Unfortunately, real-time data may divulge users’ private information. To protect the privacy of real-time data, data aggregation schemes have been proposed to assist the control center in adjusting the supply to meet users’ electricity demands without sacrificing data privacy. However, extreme weather events and potential attacks may damage the meters and change the structure of the smart grid dynamically, it is important to improve the reliability of the data aggregation scheme. Even if some schemes have improved reliability, but the scalability is poor, they are not suitable for the dynamically changing smart grid network structure. To meet this end, a resilient data aggregation scheme for the smart grid is proposed, which 1) offers better reliability by defending against malicious attacks, group management techniques are proposed, and meters can update their keys when the smart grid network structure changes; 2) affords higher scalability; and 3) enables the control center to make fine-grained adjustments. A prototype implementation shows that the proposed scheme is efficient enough for smart meters.
Yuwen Chen 0002, Shisong Yang, José-Fernán Martínez, Lourdes López-Santidrián, Zhen Yang 0004
IEEE Internet Things J.3
2021 The Trapezoidal Sketch for Frequency Estimation in Network Flow
abstract
The sketch is one of the typical and widely-used data structures for estimating the frequencies of items in data streams. However, since the counter sizes in traditional rectangular sketch (r-sketch) are the same, it is hard to achieve small space usage, high capacity (i.e., the maximum frequency can be recorded), and high estimated accuracy simultaneously. Moreover, when considering the high skewness of data streams, this problem will become even worse. Consequently, we propose the trapezoidal sketch (t-sketch) in this paper. In the t-sketch, different from the r-sketch, the counter sizes in different layers are different. Therefore, the low space usage and high capacity can be achieved simultaneously in the t-sketch. Moreover, based on the basic t-sketch, we propose the space-saving t-sketch and the capacity-improvement t-sketch, and analyze the properties of these two t-sketches. Compared with the CM sketch, CU sketch, C sketch, and A sketch, the simulation results show that the performances on space usage, capacity, and estimation accuracy are improved successfully by the space-saving t-sketch and the capacity-improvement t-sketch.
Ning Li 0003, Xin Yuan 0003, José-Fernán Martínez, Vicente Hernández Díaz
ICNP3
2021 A Dynamic Membership Group-Based Multiple-Data Aggregation Scheme for Smart Grid
abstract
In the smart grid, meters report their real-time electricity consumption data to a utility supplier, and the utility supplier can adjust its supply accordingly. However, adversaries can infer users' privacy behaviors based on publicly transferred real-time electricity consumption data. Data aggregation schemes protect users' privacy from being leaked. We find two major problems are unsolved: 1) meter failure problem and 2) dynamic membership problem. To solve these problems, we designed a dynamic membership group-based multiple-data aggregation scheme. First, a group-based key establishment scheme is proposed, meters are divided into groups, meters in a group build keys to encrypt their data, the meter failure problem is alleviated. If one group has broken meters, the other groups will not be affected. Second, the dynamic join, dynamic leave, and meter replacement techniques are proposed, and the dynamic membership is achieved by allowing meters to update their keys. The simulation results show a meter's computation cost and communication cost are the minima among the related works, which makes the proposed scheme more suitable for the IoT scenario. Besides, we designed a data encoding method and a data retrieve method, we designed two attacks: 1) “bilinear map pairing attack” and 2) “zero attack.”
Yuwen Chen 0002, José-Fernán Martínez, Lourdes López-Santidrián, Haiyang Yu 0001, Zhen Yang 0004
IEEE Internet Things J.2
2020 Search-tree Based SDN Candidate Selection in Hybrid IP/SDN Network
abstract
The link failure recovery is important to the Internet. For improving the performance of link failure recovery in the IP network, the software defined networking (SDN) is applied to achieve this target. The SDN is effective on solving this kind of issue. However, considering the deployment cost, only a few IP routers can be replaced by the SDN switches. Thus, to minimize the number of SDN switches, the greedy-based approach is proposed to select the most appropriate deployment locations. But the greedy-based approach has disadvantages. For addressing these disadvantages, in this paper, we proposed the search-tree based SDN candidate selection (SCS) algorithm. In this algorithm, for achieving better performance than the greedy-based approach, three algorithms are proposed, which are the search-tree based feasible solutions calculation algorithm, the most appropriate feasible solution selection algorithm, and the most appropriate designated SDN switch selection algorithm. Based on these algorithms, the performance of the search-tree based SCS algorithm is improved greatly compared with the greedy-based algorithms.
Ning Li 0003, José-Fernán Martínez, Xin Yuan 0003
ICNP4
2020 Game Theory based Joint Task Offloading and Resource Allocation Algorithm for Mobile Edge Computing
abstract
Mobile edge computing (MEC) has emerged for reducing energy consumption and latency by allowing mobile users to offload computationally intensive tasks to the MEC server. Due to the spectrum reuse in the network of MEC, the inner-cell interference has a great effect on MEC's performance. In this paper, for reducing the energy consumption and latency of MEC, we propose a game theory based approach to join task offloading decision and resource allocation together in the MEC system. In this algorithm, the offloading decision, the CPU capacity adjustment, the transmission power control, and the network interference management of mobile users are regarded as a game. In this game, based on the best response strategy, each mobile user makes their own utility maximum rather than the utility of the whole system. We prove that this game is an exact potential game and the Nash equilibrium (NE) of this game exists. We also investigate the properties of this algorithm, including the convergence, the computational complexity, and the Price of anarchy (PoA). We evaluate the performance of this algorithm by simulation. The simulation results illustrate that this algorithm is effective in improving the performance of the multi-user MEC system.
Ning Li 0003, Jianen Yan, José-Fernán Martínez, Xin Yuan 0003
MSN4
2020 Continuous Delivery of Customized SaaS Edge Applications in Highly Distributed IoT Systems
abstract
Edge computing is a reality for the current IoT systems that need fast processing and quick response time to make real-time decisions and IoT systems without permanent connectivity to the cloud (e.g., car manufacturing, precision agriculture, or cattle raising). Additionally, these industries are facing the need for rapid and continuous innovation by accelerating the delivery of over-the-air (OTA) software updates in edge devices. DevOps promotes collaboration between development and operation teams and automation at all steps of software construction to achieve continuous delivery (CD) of business value. Although DevOps has demonstrated numerous successful cases in the Web domain, in the IoT domain and, more specifically, at the edge, there are few reported cases. This work presents a success case of CD of customized software as a service software as a service (SaaS) updates at the IoT Edge. This may enable new business models at the IoT Edge. This article presents an architectural model of a highly distributed (cloud and edge) IoT system and a CD process flow for customized SaaS applications in edge nodes. Both the architectural model and the CD process flow are instantiated in a case study for precision agriculture.
Ramón López-Viana, Jessica Díaz, Vicente Hernández Díaz, José-Fernán Martínez
IEEE Internet Things J.4
2020 Editorial: Security and Privacy Protection for Mobile Applications and Platforms
Victor Sucasas, Georgios Mantas, Saud Althunibat, José-Fernán Martínez
Mob. Networks Appl.4
2019 The AFarCloud ECSEL Project
abstract
Farming is facing many economic challenges in terms of productivity and cost-effectiveness. Labor shortage partly due to depopulation of rural areas, especially in Europe, is another challenge. Domain specific problems such as accurate identification and proper quantification of pathogens affecting plant and animal health are key factors for minimizing economical risks, and not risking human health. The ECSEL AFarCloud (Aggregate FARming in the CLOUD) project will provide a distributed platform for autonomous farming that will allow the integration and cooperation of agriculture Cyber Physical Systems in real-time in order to increase efficiency, productivity, animal health, food quality and reduce farm labour costs. This platform will be integrated with farm management software and will support monitoring and decision-making solutions based on big data and real-time data mining techniques.
Pedro Castillejo, Baran Çürüklü, Roberto Fresco, Gorm Johansen, Sonia Bilbao-Arechabala, Belén Martínez Rodriguez, Luigi Pomante, José-Fernán Martínez, Marco Santic
DSD8
2019 A Novel Intrusion Detection and Prevention Scheme for Network Coding-Enabled Mobile Small Cells
abstract
Network coding (NC)-enabled mobile small cells are observed as a promising technology for fifth-generation (5G) networks that can cover the urban landscape by being set up on-demand at any place and at any time on any device. Nevertheless, despite the significant benefits that this technology brings to the 5G of mobile networks, major security issues arise due to the fact that NC-enabled mobile small cells are susceptible to pollution attacks; a severe security threat exploiting the inherent vulnerabilities of NC. Therefore, intrusion detection and prevention mechanisms to detect and mitigate pollution attacks are of utmost importance so that NC-enabled mobile small cells can reach their full potential. Thus, in this article, we propose for the first time, to the best of our knowledge, a novel intrusion detection and prevention scheme (IDPS) for NC-enabled mobile small cells. The proposed scheme is based on a null space-based homomorphic message authentication code (MAC) scheme that allows detection of pollution attacks and takes proper risk mitigation actions when an intrusive incident is detected. The proposed scheme has been implemented in Kodo and its performance has been evaluated in terms of computational overhead.
Reza Parsamehr, Alireza Esfahani, Georgios Mantas, Ayman Radwan, Shahid Mumtaz, Jonathan Rodriguez 0001, José-Fernán Martínez
IEEE Trans. Comput. Soc. Syst.7
2018 Cross-Layer Balanced Relay Node Selection Algorithm for Opportunistic Routing in Underwater Ad-Hoc Networks
abstract
Due to the different transmission media, the underwater environment poses a more severe situation for routing algorithm design than that of the terrestrial environment. In this paper, we propose a weight based fuzzy logic (WBFL) relay node selection algorithm for the underwater Ad-hoc network, which can get the most balanced result than the previous algorithms without increasing the computation complexity. In this algorithm, the parameter scatters instead of the parameter values are inputted into the fuzzy logic inference system. By this innovation, the algorithm can take as much cross-layer parameters into account as possible during the relay node selection. Moreover, taking the node mobility into account, we propose a geographic based link lifetime prediction algorithm for underwater Ad-hoc network. The simulation results show that the WBFL algorithm can improve the network throughput at most 50% compare with the ExOR algorithm; moreover, the WBFL is effective and accurate on selecting relay nodes and the computation complexity is less than the previous algorithms.
Ning Li 0003, José-Fernán Martínez, Vicente Hernández Díaz, Lourdes López-Santidrián
AINA2
2018 Security Threats in Network Coding-Enabled Mobile Small Cells
Reza Parsamehr, Georgios Mantas, Ayman Radwan, Jonathan Rodriguez 0001, José-Fernán Martínez
BROADNETS5
2018 A Semantic-Middleware-Supported Receding Horizon Optimal Power Flow in Energy Grids
abstract
Energy management in electric grids with multiple energy sources, generators, storage devices, and interacting loads along with their complex behaviors requires grid wide control. Communication infrastructure that aggregates information from heterogeneous devices in the electric grid making the applications completely independent of physical connectivity is essential for building in the context of control applications. This investigation presents a semantic middleware that is used to implement a receding-horizon-based optimal power flow (OPF) in smart grids. The presence of renewable energy sources, storage systems, and loads dispersed all along the grid necessitates the use of grid wide control and a communication infrastructure to support it. To this extent, the proposed middleware will serve as the basis for representing various components of the power grid. It is enriched with intelligence by semantic annotation and ontologies that provide situation awareness and context discovery. The middleware deployment is demonstrated by implementing the receding horizon OPF in a network in Steinkjer, Norway. Our results demonstrate the advantages of both the middleware and the algorithm. Furthermore, the results prove the added flexibility obtained in the grid due to the addition of renewable energy and storage systems. The significant advantage of the proposed approach is that the real-time monitoring infrastructure is used for improving the flexibility, reliability, and efficiency of the grid.
Alessio Maffei, Seshadhri Srinivasan, Pedro Castillejo, José-Fernán Martínez, Luigi Iannelli, Eilert Bjerkan, Luigi Glielmo
IEEE Trans. Ind. Informatics4
2018 Probability Prediction-Based Reliable and Efficient Opportunistic Routing Algorithm for VANETs
Ning Li 0003, José-Fernán Martínez, Vicente Hernández Díaz, José Antonio Sánchez Fernández
IEEE/ACM Trans. Netw.2
2017 Precise Real-Time Detection of Nonforested Areas With UAVs
abstract
This paper presents a new method for real-time automatic detection of nonforested and eroded areas in tropical rain forests. It is based on simple image algebra between color components, which enhances the contrast between brown and green areas. A successive segmentation through multiple thresholds, based on newly proposed indices of “brown color excess” and the “nonforest detection index,” leads to a binary map that clearly identifies forested and nonforested areas. Experimental tests, performed and compared with other recommended methods based on: region growing, active contours, and clustering, outperformed in detection accuracy (Fm= 96.4%) and processing times (Tp= 0.082 s). The method presented copes well with detecting regional irregularities and reduces frequent issues of nondetection, as well as false positives caused by intensity changes, shadows, and/or partial occlusions. The low processing times achieved with the proposed method allow real-time applications for low-cost unmanned aerial vehicle and unmanned aircraft systems with conventional camera equipment.
Henry Cruz, Martina Eckert, Juan M. Meneses, José-Fernán Martínez
IEEE Trans. Geosci. Remote. Sens.4
2017 Uncertainty Quantification in Mathematics-Embedded Ontologies Using Stochastic Reduced Order Model
abstract
To resolve one of uncertainty features, randomness, in ontologies, this paper shows how to characterize uncertainty of concepts from a statistical viewpoint. In addition, with a focus on indirect entities, which are computed from direct entities through mathematical models, the uncertainties propagated from those direct entities are important and should be quantified. Thus, a novel algorithm, named Stochastic Reduced Order Model (SROM), is presented to be applied to quantify the ontological uncertainty propagation in presence of multiple input entities. This SROM-based method could approximate the statistics of indirect entities accurately and efficiently by using a very small amount of samples of input entities. The computational cost is considerably reduced while guaranteeing a reasonable degree of accuracy. Furthermore, the predicted statistics of output entities could be regarded as high-level information and be beneficial for other ontological operations, such as ontology filtering and ontology reasoning. The implementation of the SROM algorithm is non-intrusive to the mathematical model; therefore, this algorithm could be applicable to quantify uncertainty in ontologies with any mathematical relationships.
Xin Li 0032, José-Fernán Martínez, Martina Eckert, Gregorio Rubio
IEEE Trans. Knowl. Data Eng.2
2017 A Privacy Protection User Authentication and Key Agreement Scheme Tailored for the Internet of Things Environment: PriAuth
abstract
In a wearable sensor-based deployment, sensors are placed over the patient to monitor their body health parameters. Continuous physiological information monitored by wearable sensors helps doctors have a better diagnostic and a suitable treatment. When doctors want to access the patient’s sensor data remotely via network, the patient will authenticate the identity of the doctor first, and then they will negotiate a key for further communication. Many lightweight schemes have been proposed to enable a mutual authentication and key establishment between the two parties with the help of a gateway node, but most of these schemes cannot enable identity confidentiality. Besides, the shared key is also known by the gateway, which means the patient’s sensor data could be leaked to the gateway. In PriAuth, identities are encrypted to guarantee confidentiality. Additionally, Elliptic Curve Diffie–Hellman (ECDH) key exchange protocol has been adopted to ensure the secrecy of the key, avoiding the gateway access to it. Besides, only hash and XOR computations are adopted because of the computability and power constraints of the wearable sensors. The proposed scheme has been validated by BAN logic and AVISPA, and the results show the scheme has been proven as secure.
Yuwen Chen 0002, José-Fernán Martínez, Pedro Castillejo, Lourdes López-Santidrián
Wirel. Commun. Mob. Comput.2
2011 Bringing pervasive embedded networks to the service cloud: A lightweight middleware approach
Iván Corredor, José-Fernán Martínez, Miguel S. Familiar
J. Syst. Archit.2
2007 Exhaustif: a fault injection tool for distributed heterogeneous embedded systems
abstract
This paper presents Exhaustif®, a SWIFI fault injection tool for fault tolerance verification and the validation of embedded software in distributed heterogeneous systems. Exhaustif® mainly consists of two parts: EEM and FIK. Exhaustif® Executive Manager (EEM) is a GUI Java application to define the fault injection campaign that uses a SQL database to save the test results obtained from the System under Test (SUT) in order to carry out a post injection data analysis. FIK is under the command of EEM to cary out fault injections in applications running under diverse operating systems using pure SWIFI techniques. Exhaustif® carries out floating point register and memory corruptions using temporary triggers and uses an optimized routine interception mechanism to carry out argument and return value corruption with a minimal time overhead. Two experimental Fault Injector Kernels (FIK) under the RTEMS operating system for an EADS-Astrium SPARC ERC32-based MCM processor board and i386 standard PC mainboard have been developed.
Antonio da Silva 0001, José-Fernán Martínez, Lourdes López-Santidrián, Ana Belén García, Luis Redondo
EATIS2
2007 ASA: advanced secure architecture for preventing unauthorized access in personal computer platforms and BIOS
abstract
This paper proposes an architecture for Personal Computers (PC) to avoid BIOS alteration and unauthorized access to resources. This proposal is based on results obtained from study of most popular PC platforms security mechanisms. Authentication controls which are established in PC platform in order to grant operating system booting or BIOS integrity of code mechanism incorporated to secure and avoid executing disallowed code are quite easy to break. The architecture described in the present work (Advanced Secure Architecture - ASA) increase the overall information and system security since prevents an unauthorized platform booting and it provides procedures for BIOS code authentication. On the other hand, ASA overcomes the users' authentication challenge in a corporative environment as well as it offers a very flexible way to specify the Personal Computers Corporation set that a user is allowed to access.
Lourdes López-Santidrián, José-Fernán Martínez, Alfonso Muñoz, Vicente Hernández, Antonio da Silva 0001, Ana Belén García
EATIS2
2007 QoS in wireless sensor networks: survey and approach
abstract
A wireless sensor network (WSN) is a computer wireless network composed of spatially distributed and autonomous tiny nodes -- smart dust sensors, motes -, which cooperatively monitor physical or environmental conditions. Nowadays these kinds of networks support a wide range of applications, such as target tracking, security, environmental control, habitat monitoring, source detection, source localization, vehicular and traffic monitoring, health monitoring, building and industrial monitoring, etc. Many of these applications have strong requirements for end-to-end delay and losses during data transmissions. In this work we have classified the main mechanisms that have been proposed to provide Quality of Service (QoS) in WSN at Medium Access Control (MAC) and network layers. Finally, taking into account some particularities of the studied MAC- and network-layer protocols, we have selected a real application scenario in order to show how to choose an appropriate approach for guaranteeing performance in a WSN deployed application.
José-Fernán Martínez, Ana Belén García, Iván Corredor, Lourdes López-Santidrián, Vicente Hernández, Antonio da Silva 0001
EATIS1
2007 An approach for applying multi-agent technology into wireless sensor networks
abstract
The present work describes how the concepts and foundations defined for multi-agent system technology can be applied in to a Wireless Sensor Network (WSN), specifically it is focused on how multi-agent system technology's mechanisms and implementations could facilitate the development of systems based on WSN. In this respect, an architectural model where the above mentioned concepts, foundations and mechanisms come together is proposed, in order to define applications and services on WSN. Validation of the proposed architecture is made by means of its use in a perimeter security scenario (tracking). It is important to mention, that partial results of this work have been developed in the project PROPSI (Perimeter Protection by means of Wireless Sensor Networks).
José-Fernán Martínez, Ana Belén García, Antonia-M. Sanz, Lourdes López-Santidrián, Vicente Hernández, Antonio da Silva 0001
EATIS1
2007 Security services provision for telematic services at the knowledge and information society
abstract
The Knowledge and Information Society development has promoted the evolution of telematic services, such as those for e-government and e-health, which aim to offer feasible solutions to social and citizens problems that will strengthen the democracy, foster citizens equal opportunities and ease their participation in the processes of the public administration and the help to the needy. Though the different telematic services are internally constituted for similar or even identical subservices, the interoperability is not possible among them and components sharing either.
José-Fernán Martínez, Vicente Hernández, Miguel Valero, Ana Gómez Oliva, Emilia Pérez Belleboni, Iván Pau, Hugo Álvarez, Laura Vadillo
EATIS1