VLDB 2026 Research / reviewers in the wild / expert
Etienne Rivière
dblp:01/6018
· DBLP profile ↗
76ranked-venue papers
0as first author
25since 2021 · last 2027
0000-0002-4133-394XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 19 · 8 since 2021Systems, architecture and hardware · 18 · 5 since 2021Computer networks · 11 · 4 since 2021Software engineering, systems software and programming languages · 11 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Databases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2027 | Justin: Integration of heterogeneous CPU/memory scaling in Apache Flink and its Kubernetes support
Donatien Schmitz, Guillaume Rosinosky, Etienne Rivière |
Sci. Comput. Program. | 3 |
| 2026 | TriHaRd: Higher Resilience for TEE Trusted TimeabstractAccurately measuring time passing is critical for many applications. However, in Trusted Execution Environments (TEEs) such as Intel SGX, the time source is outside the Trusted Computing Base: a malicious host can manipulate the TEE’s notion of time, jumping in time or affecting perceived time speed. Previous work (Triad) proposes protocols for TEEs to maintain a trustworthy time source by building a cluster of TEEs that collaborate with each other and with a remote Time Authority to maintain a continuous notion of passing time. However, such approaches still allow an attacker to control the operating system and arbitrarily manipulate their own TEE’s perceived clock speed. An attacker can even propagate faster passage of time to honest machines participating in Triad’s trusted time protocol, causing them to skip to timestamps arbitrarily far in the future. We propose TriHaRd, a TEE trusted time protocol achieving high resilience against clock speed and offset manipulations, notably through Byzantine-resilient clock updates and consistency checks. We empirically show that TriHaRd mitigates known attacks against Triad. This repository contains the source code, as well as deployment and analysis scripts, for the "TriHaRd: Higher Resilience for TEE Trusted Time" paper, accepted for publication at the INFOCOM'26 conference. Matthieu Bettinger, Sonia Ben Mokhtar, Pascal Felber, Etienne Rivière, Valerio Schiavoni, Anthony Simonet |
INFOCOM | 4 |
| 2026 | Scylla: Scheduling Multiple Latency-Sensitive Applications in the Edge-Cloud Continuum
Yinan Cao, Etienne Rivière, Ramin Sadre |
IWQoS | 2 |
| 2025 | Cool-Tee: Client-Tee Collaboration for Resilient Distributed SearchabstractCurrent marketplaces rely on search mechanisms with distributed systems but centralized governance, making them vulnerable to attacks, failures, censorship and biases. While search mechanisms with more decentralized governance (e.g., DeSearch) have been recently proposed, these are still exposed to information head-start attacks (IHS) despite the use of Trusted Execution Environments (TEEs). These attacks allow malicious users to gain a head-start over other users for the discovery of new assets in the market, which give them an unfair advantage in asset acquisition. We propose COoL-TEE, a TEE-based provider selection mechanism for distributed search, running in single-or multi-datacenter environments, that is resilient to information head-start attacks. COoL-TEE relies on a Client-TEE collaboration, which enables clients to distinguish between slow providers and malicious ones. Performance evaluations in single-and multidatacenter environments show that, using COoL-TEE, malicious users respectively gain only up to 2 % and 7 % of assets more than without IHS, while they can claim 20 % or more on top of their fair share in the same conditions with DeSearch. Matthieu Bettinger, Etienne Rivière, Sonia Ben Mokhtar, Anthony Simonet |
CCGrid | 2 |
| 2025 | LASSY: A Latency-Aware SLOs-Sufficing Scheduling System for the Cloud/Edge ContinuumabstractDespite the advancements in cloud computing, cloud-hosted applications face significant network latency challenges, particularly for users distant from data centers. Edge computing has emerged as a solution to mitigate these issues by decentralizing processing, thereby reducing latency and enhancing user experience. However, the limited resources of edge data centers require careful scheduling of application instances to preserve the benefits of edge computing. This paper presents the Latency-Aware SLO-Sufficing Scheduling System (LASSY), a novel approach that considers network and queueing latencies in scheduling decisions for cloud/edge continuum environments. LASSY utilizes queueing theory to predict the tail latency experienced by users of latency-sensitive services such as Edge AI and optimizes service deployment across cloud and edge nodes to meet Service Level Objectives (SLOs). Our contributions include detailed latency modeling, an optimization algorithm that minimizes resource costs while ensuring SLO compliance, comprehensive experiments conducted on a testbed under realistic network emulation, and comparison with a state-of-the-art scheduling model. We evaluated LASSY under real-world latency conditions using two applications: a picture thumbnailing service and an Edge AI OCR service. We demonstrate LASSY's ability to achieve the desired service quality by effectively managing latency and resource allocation. Yinan Cao, Etienne Rivière, Ramin Sadre |
CCGrid | 2 |
| 2025 | Justin: Hybrid CPU/Memory Elastic Scaling for Distributed Stream Processing
Donatien Schmitz, Guillaume Rosinosky, Etienne Rivière |
DAIS | 3 |
| 2025 | PANDAS: Peer-to-peer, Adaptive Networking Allowing Data Availability Sampling within Ethereum Consensus TimeboundsabstractLayer-2 protocols such as rollups can help address Ethereum's throughput limits. An efficient data availability layer is key for layer-2 support in Ethereum, but broadcast methods do not scale. A promising approach is the selective distribution of layer-2 data and its verification by data availability sampling (DAS). Integrating DAS with Ethereum consensus is, however, a challenge, as data must be shared and sampled within 4 seconds of each consensus slot. Matthieu Pigaglio, Onur Ascigil, Michal Król, Kaleem Peeroo, Sergi Rene, Ramin Sadre, Vladimir Stankovic 0002, Etienne Rivière |
Middleware | 9 |
| 2025 | PAMO: Pattern Matching Offload for Intrusion Detection SystemsabstractIntrusion Detection Systems (IDS) play a crucial role in network security. An IDS recognizes malicious activity in network traffic by matching it against patterns defined in a set of rules. The complexity and size of rule sets lead to substantial computational load. In a state-of-the-art IDS, such as Suricata, a single CPU core processes a few hundred MB to a few GB of network traffic per second, and rule evaluation accounts for over 60% of CPU consumption. Scaling IDS to today's high-speed networks is, therefore, a significant challenge. Lukás Sismis, Colin Evrard, Etienne Rivière, Tom Barbette |
Middleware | 3 |
| 2025 | Where to Place Your TEE? In Search of a Censorship-Resilient Design for Rollup Sequencers
Andrei Arusoaie, Claudiu-Nicu Barbieru, Oana-Otilia Captarencu, Pascal Felber, Corentin Libert, Emanuel Onica, Etienne Rivière, Valerio Schiavoni, Peterson Yuhala |
OPODIS | 7 |
| 2025 | Evaluating Behavior Graph Reduction Strategies for Machine Learning-Based Malware DetectionabstractGraph-based representations of program behavior are a powerful foundation for machine learning-based malware detection. However, the large size and complexity of these behavior graphs pose scalability challenges. This paper presents a systematic evaluation of five graph reduction strategies—covering both coarsening and sparsification—designed to simplify graphs while preserving meaningful behavioral features. Using dynamic analysis data from Windows PE32 binaries, we analyze the impact of these reductions on computational efficiency, detection performance, and model robustness against adversarial mimicry attacks. Our results show that several strategies substantially reduce graph size and extraction time without significant accuracy loss. We also find that coarsening based on API calls’ action maintains stronger robustness to adversarial manipulation. Samy Bettaieb, Serena Lucca, Charles-Henry Bertrand Van Ouytsel, Etienne Rivière |
TrustCom | 4 |
| 2024 | DISC-NG: Robust Service Discovery in the Ethereum Global NetworkabstractThe Ethereum Global Network (EGN) hosts a complete ecosystem of decentralized services, including blockchains such as Ethereum mainnet but also exchange markets, content delivery networks, and many more. Service discovery is a fundamental mechanism in the EGN, allowing new nodes to look up and connect to other nodes already participating in one of these services. The current service discovery of the EGN, DISCv5, is not scalable and efficient enough to support the current and future needs of the ecosystem. We present DISC-NG, a novel service discovery protocol for the EGN that is scalable, efficient, and secure. DISC-NG leverages the EGN-wide DHT to allow service participation advertisements to meet service discovery requests. DISC-NG compensates the unbalance in service popularity and minimizes the potential for abuse by malicious nodes. We implement DISC-NG in devp2p, the network stack used by the majority of clients connecting to the EGN, as well as in a large-scale simulator. DISC-NG can discover services in the EGN faster than DISCv5 while being more robust to malicious nodes. DISC-NG is now in a staging phase and scheduled for deployment as an improvement to DISCv5. Michal Król, Onur Ascigil, Sergi Rene, Alberto Sonnino, Matthieu Pigaglio, Ramin Sadre, Etienne Rivière |
EuroS&P | 8 |
| 2024 | Content Censorship in the InterPlanetary File System
Srivatsan Sridhar, Onur Ascigil, Navin V. Keizer, François Genon, Sébastien Pierre, Yiannis Psaras, Etienne Rivière, Michal Król |
NDSS | 7 |
| 2023 | Hector: A Framework to Design and Evaluate Scheduling Strategies in Persistent Key-Value StoresabstractKey-value stores distribute data across several storage nodes to handle large amounts of parallel requests. Proper scheduling of these requests impacts the quality of service, as measured by achievable throughput and (tail) latencies. In addition to scheduling, performance heavily depends on the nature of the workload and the deployment environment. It is, unfortunately, difficult to evaluate different scheduling strategies consistently under the same operational conditions. Moreover, such strategies are often hard-coded in the system, limiting flexibility. We present Hector, a modular framework for implementing and evaluating scheduling policies in Apache Cassandra. Hector enables users to select among several options for key components of the scheduling workflow, from the request propagation via replica selection to the local ordering of incoming requests at a storage node. We demonstrate the capabilities of Hector by comparing strategies in various settings. For example, we find that leveraging cache locality effects may be of particular interest: we propose a new replica selection strategy, called Popularity-Aware, that supports 6 times the maximum throughput of the default algorithm under specific key access patterns. We also show that local scheduling policies have a significant effect when parallelism at each storage node is limited. Louis-Claude Canon, Anthony Dugois, Loris Marchal, Etienne Rivière |
ICPP | 4 |
| 2022 | RAPTEE: Leveraging trusted execution environments for Byzantine-tolerant peer sampling servicesabstractPeer sampling is a first-class abstraction used in distributed systems for overlay management and information dissemination. The goal of peer sampling is to continuously build and refresh a partial and local view of the full membership of a dynamic, large-scale distributed system. Malicious nodes under the control of an adversary may aim at being over-represented in the views of correct nodes, increasing their impact on the proper operation of protocols built over peer sampling. State-of-the-art Byzantine resilient peer sampling protocols reduce this bias as long as Byzantines are not overly present. This paper studies the benefits brought to the resilience of peer sampling services when considering that a small portion of trusted nodes can run code whose authenticity and integrity can be assessed within a trusted execution environment, and specifically Intel’s software guard extensions technology (SGX). We present RAPTEE, a protocol that builds and leverages trusted gossip-based communications to hamper an adversary’s ability to increase its system-wide representation in the views of all nodes. We apply RAPTEE to BRAHMS, the most resilient peer sampling protocol to date. Experiments with 10,000 nodes show that with only 1% of SGX-capable devices, RAPTEE can reduce the proportion of identifiers of Byzantine nodes in the view of honest ones by up to 17%, when the system contains 10% of Byzantine nodes. In addition, the security guarantees of RAPTEE hold even in the presence of a powerful attacker attempting to identify trusted nodes and injecting view-poisoned trusted nodes. Matthieu Pigaglio, Joachim Bruneau-Queyreix, Yérom-David Bromberg, Davide Frey, Etienne Rivière, Laurent Réveillère |
ICDCS | 5 |
| 2022 | Donar: Anonymous VoIP over Tor
Yérom-David Bromberg, Quentin Dufour, Davide Frey, Etienne Rivière |
NSDI | 4 |
| 2022 | Engineering the Transition of Interactive Collaborative Software from Cloud Computing to Edge ComputingabstractThe "Software as a Service" (SaaS) model of cloud computing popularized online multiuser collaborative software. Two famous examples of this class of software are Office 365 from Microsoft and Google Workspace. Cloud technology removes the need to install and update the software on end users' computers and provides the necessary underlying infrastructure for online collaboration. However, to provide a good end-user experience, cloud services require an infrastructure able to scale up to the task and allow low-latency interactions with a variety of users worldwide. This is a limiting factor for actors that do not possess such infrastructure. Unlike cloud computing which forgets the computational and interactional capabilities of end users' devices, the edge computing paradigm promises to exploit them as much as possible. To investigate the potential of edge computing over cloud computing, this paper presents a method for engineering interactive collaborative software supported by edge devices for the replacement of cloud computing resources. Our method is able to handle user interface aspects such as connection, execution, migration, and disconnection differently depending on the available technology. We exemplify our approach by developing a distributed Pictionary game deployed in two scenarios: a nonshared scenario where each participant interacts only with their own device and a shared scenario where participants also share a common device, including a TV. After a theoretical comparative study of edge vs. cloud computing, an experiment compares the two implementations to determine their effect on the end user's perceived experience and latency vs. real latency. Guillaume Ortegat, Donatien Grolaux, Etienne Rivière, Jean Vanderdonckt |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2022 | SoK: Privacy-enhancing Smart Home HubsabstractSmart homes are IoT systems enabling the automation of household operation. The unrestricted collection and processing of data by smart home systems raises legitimate privacy concerns for their users. Over the past decade, there has been significant interest in privacy-enhancing technologies applied at the level of a local smart hub physically located in the home and acting as a gateway between sensors, applications, platform providers, and services in the cloud. The number and variety of projects and research proposals can, however, make their comparison a daunting and unnecessarily complex task. We systematize existing knowledge in this field through the analysis and categorization of 10 industrial and community-contributed systems and 37 research proposals from the literature of the past 11 years. Our results shed light on the diversity of system and trust models considered in the state-of-the-art and on the associated privacy-enhancing technologies. We further identify open research problems and promising approaches that would benefit the smart home hub model and the protection of smart home users’ privacy. Igor Zavalyshyn, Axel Legay, Annanda Thavymony Rath, Etienne Rivière |
Proc. Priv. Enhancing Technol. | 4 |
| 2021 | Shard scheduler: object placement and migration in sharded account-based blockchainsabstractWe propose Shard Scheduler, a system for object placement and migration in account-based sharded blockchains. Our system calculates optimal placement and decides on object migrations across shards. It supports complex multi-account transactions caused by smart contracts. Placement and migration decisions made by Shard Scheduler are fully deterministic, verifiable, and can be made part of the consensus protocol. Shard Scheduler reduces the number of costly cross-shard transactions, ensures balanced load distribution and maximizes the number of processed transactions for the blockchain as a whole. To this end, it leverages a novel incentive model motivating miners to maximize the global throughput of the entire blockchain rather than the throughput of a specific shard. In our simulations, Shard Scheduler can reduce the number of costly cross-shard transactions by half while ensuring equal load and increasing throughput more than 2 fold when using 60 shards. We also implement and evaluate Shard Scheduler on Chainspace, more than doubling its throughput and reducing user-perceived latency by 70% when using 10 shards. Michal Król, Onur Ascigil, Sergi Rene, Alberto Sonnino, Mustafa Al-Bassam, Etienne Rivière |
AFT | 6 |
| 2021 | A Methodology for Tenant Migration in Legacy Shared-Table Multi-tenant Applications
Guillaume Rosinosky, Samir Youcef, François Charoy, Etienne Rivière |
DAIS | 4 |
| 2021 | Taming Tail Latency in Key-Value Stores: A Scheduling Perspective
Sonia Ben Mokhtar, Louis-Claude Canon, Anthony Dugois, Loris Marchal, Etienne Rivière |
Euro-Par | 5 |
| 2021 | PProx: efficient privacy for recommendation-as-a-serviceabstractWe present PProx, a system preventing recommendation-as-a-service (RaaS) providers from accessing sensitive data about the users of applications leveraging their services. PProx does not impact recommendations accuracy, is compatible with arbitrary recommendation algorithms, and has minimal deployment requirements. Its design combines two proxying layers directly running inside SGX enclaves at the RaaS provider side. These layers transparently pseudonymize users and items and hide links between the two, and PProx privacy guarantees are robust even to the corruption of one of these enclaves. We integrated PProx with Harness's Universal Recommender and evaluated it on a 27-node cluster. Our results indicate its ability to withstand a high number of requests with low end-to-end latency, horizontally scaling up to match increasing workloads of recommendations. Guillaume Rosinosky, Simon Da Silva, Sonia Ben Mokhtar, Daniel Négru, Laurent Réveillère, Etienne Rivière |
Middleware | 6 |
| 2021 | Active replication for latency-sensitive stream processing in Apache FlinkabstractStream processing frameworks allow processing massive amounts of data shortly after it is produced, and enable a fast reaction to events in scenarios such as data center monitoring, smart transportation, or telecommunication networks. Many scenarios depend on the fast and reliable processing of incoming data, requiring low end-to-end latencies from the ingest of a new event to the corresponding output. The occurrence of faults jeopardizes these guarantees: Currently-leading high-availability solutions for stream processing such as Spark Streaming or Apache Flink's implement passive replication through snapshotting, requiring a stop-the-world operation to recover from a failure. Active replication, while incurring higher deployment costs, can overcome these limitations and allow to mask the impact of faults and match stringent end-to-end latency requirements. We present the design, implementation, and evaluation of active replication in the popular Apache Flink platform. Our study explores two alternative designs, a leader-based approach leveraging external services (Kafka and ZooKeeper) and a leaderless implementation leveraging a novel deterministic merging algorithm. Our evaluation using a series of microbenchmarks and a SaaS cloud monitoring scenario on a 37-server cluster show that the actively-replicated Flink can fully mask the impact of faults on end-to-end latency. Guillaume Rosinosky, Florian Schmidt 0009, Oleh Bodunov, Christof Fetzer, André Martin, Etienne Rivière |
SRDS | 6 |
| 2021 | Chaos Duck: A Tool for Automatic IoT Software Fault-Tolerance AnalysisabstractInternet of Things (IoT) device software frequently handles sensitive data. This software has to be resistant to faults to prevent leakage and ensure data privacy and security. Source code hardening is a common way to make software fault-tolerant. However, the effectiveness and performance impact of a chosen hardening technique are not always obvious. Moreover, it becomes increasingly difficult to predict potential attack vectors and implement proper countermeasures. To assist in this task, we developed Chaos Duck, an automatic tool for IoT software fault-tolerance analysis. Chaos Duck emulates various fault types and provides statistics on their impact on software security and stability. We present a case study in which we use Chaos Duck to compare five software hardening techniques applied to the PRESENT block cipher implementation. We show that some simple hardening techniques may improve fault-tolerance, while others can instead reduce overall security and introduce new vulnerabilities. Our contributions are twofold: we offer a software fault-tolerance analysis tool to IoT developers seeking to make their software secure and robust, and we shed light on the efficiency of various hardening techniques. Igor Zavalyshyn, Thomas Given-Wilson, Axel Legay, Ramin Sadre, Etienne Rivière |
SRDS | 5 |
| 2021 | EL PASSO: Efficient and Lightweight Privacy-preserving Single Sign OnabstractAbstract Anonymous credentials are a solid foundation for privacy-preserving Single Sign-On (SSO). They enable unlinkable authentication across domains and allow users to prove their identity without revealing more than necessary. Unfortunately, anonymous credentials schemes remain difficult to use and complex to deploy. They require installation and use of complex software at the user side, suffer from poor performance, and do not support security features that are now common, such as two-factor authentication, secret recovery, or support for multiple devices. In contrast, Open ID Connect (OIDC), the de facto standard for SSO is widely deployed and used despite its lack of concern for users’ privacy. We present EL PASSO, a privacy-preserving SSO system based on anonymous credentials that does not trade security for usability, and can be incrementally deployed at scale alongside Open ID Connect with no significant changes to end-user operations. EL PASSO client-side operations leverage a WebAssembly module that can be downloaded on the fly and cached by users’ browsers, requiring no prior software installation or specific hardware. We develop automated procedures for managing cryptographic material, supporting multi-device support, secret recovery, and privacy-preserving two-factor authentication using only the built-in features of common Web browsers. Our implementation using PS Signatures achieves 39x to 180x lower computational cost than previous anonymous credentials schemes, similar or lower sign-on latency than Open ID Connect and is amenable for use on mobile devices. Zhiyi Zhang 0001, Michal Król, Alberto Sonnino, Lixia Zhang 0001, Etienne Rivière |
Proc. Priv. Enhancing Technol. | 5 |
| 2021 | Proof-of-Prestige: A Useful Work Reward System for Unverifiable Tasks
Michal Król, Alberto Sonnino, Mustafa Al-Bassam, Argyrios G. Tasiopoulos, Etienne Rivière, Ioannis Psaras |
ACM Trans. Internet Techn. | 5 |
| 2020 | TailX: Scheduling Heterogeneous Multiget Queries to Improve Tail Latencies in Key-Value Stores
Vikas Jaiman, Sonia Ben Mokhtar, Etienne Rivière |
DAIS | 3 |
| 2020 | Fair and Efficient Gossip in Hyperledger FabricabstractPermissioned blockchains are supported by identified but individually untrustworthy nodes, collectively maintaining a replicated ledger whose content is trusted. The Hyperledger Fabric permissioned blockchain system targets high-throughput transaction processing. Fabric uses a set of nodes tasked with the ordering of transactions using consensus. Additional peers endorse and validate transactions, and maintain a copy of the ledger. The ability to quickly disseminate new transaction blocks from ordering nodes to all peers is critical for both performance and consistency. Broadcast is handled by a gossip protocol, using randomized exchanges of blocks between peers.We show that the current implementation of gossip in Fabric leads to heavy tail distributions of block propagation latencies, impacting performance, consistency, and fairness. We contribute a novel design for gossip in Fabric that simultaneously optimizes propagation time, tail latency and bandwidth consumption. Using a 100-node cluster, we show that our enhanced gossip allows the dissemination of blocks to all peers more than 10 times faster than with the original implementation, while decreasing the overall network bandwidth consumption by more than 40%. With a high throughput and concurrent application, this results in 17% to 36% fewer invalidated transactions for different block sizes. Nicolae Berendea, Hugues Mercier, Emanuel Onica, Etienne Rivière |
ICDCS | 4 |
| 2020 | Practical Active RevocationabstractWe propose Knob, a practical active revocation scheme allowing to efficiently revoke users' access to encrypted data banks stored in public clouds. Knob leverages Trusted Execution Environments and All-or-Nothing Data Transforms in order to re-encrypt only small portions of the content directly in the cloud, using a scalable swarm of re-encryption workers. It prevents malicious users from being able to predict which portions of the files will be re-encrypted upon a revocation, effectively disabling pre-provisioning attacks. Our evaluation using industry workloads shows that Knob outperforms active revocation using full re-encryption by up to 3 orders of magnitude while being on average 3 to 7 times faster than state-of-the-art partial re-encryption. Stefan Contiu, Laurent Réveillère, Etienne Rivière |
Middleware | 3 |
| 2020 | PASTRAMI: Privacy-preserving, Auditable, Scalable & Trustworthy Auctions for Multiple ItemsabstractDecentralised cloud computing platforms enable individuals to offer and rent resources in a peer-to-peer fashion. They must assign resources from multiple sellers to multiple buyers and derive prices that match the interests and capacities of both parties. The assignment process must be decentralised, fair and transparent, but also protect the privacy of buyers. Michal Król, Alberto Sonnino, Argyrios G. Tasiopoulos, Ioannis Psaras, Etienne Rivière |
Middleware | 5 |
| 2019 | From Confidential kNN Queries to Confidential Content-based Publish/Subscribe
Emanuel Onica, Hugues Mercier, Etienne Rivière |
ICSOFT | 3 |
| 2019 | PrivaTube: Privacy-Preserving Edge-Assisted Video StreamingabstractVideo on Demand (VoD) streaming is the largest source of Internet traffic. Efficient and scalable VoD requires Content Delivery Networks (CDNs) whose cost are prohibitive for many providers. An alternative is to cache and serve video content using end-users devices. Direct connections between these devices complement the resources of core VoD servers with an edge-assisted collaborative CDN. Simon Da Silva, Sonia Ben Mokhtar, Stefan Contiu, Daniel Négru, Laurent Réveillère, Etienne Rivière |
Middleware | 6 |
| 2019 | Split and Migrate: Resource-Driven Placement and Discovery of Microservices at the EdgeabstractMicroservices architectures combine the use of fine-grained and independently-scalable services with lightweight communication protocols, such as REST calls over HTTP. Microservices bring flexibility to the development and deployment of application back-ends in the cloud. Applications such as collaborative editing tools require frequent interactions between the front-end running on users' machines and a back-end formed of multiple microservices. User-perceived latencies depend on their connection to microservices, but also on the interaction patterns between these services and their databases. Placing services at the edge of the network, closer to the users, is necessary to reduce user-perceived latencies. It is however difficult to decide on the placement of complete stateful microservices at one specific core or edge location without trading between a latency reduction for some users and a latency increase for the others. We present how to dynamically deploy microservices on a combination of core and edge resources to systematically reduce user-perceived latencies. Our approach enables the split of stateful microservices, and the placement of the resulting splits on appropriate core and edge sites. Koala, a decentralized and resource-driven service discovery middleware, enables REST calls to reach and use the appropriate split, with only minimal changes to a legacy microservices application. Locality awareness using network coordinates further enables to automatically migrate services split and follow the location of the users. We confirm the effectiveness of our approach with a full prototype and an application to ShareLatex, a microservices-based collaborative editing application. Genc Tato, Marin Bertier, Etienne Rivière, Cédric Tedeschi |
OPODIS | 3 |
| 2019 | Emergent Overlays for Adaptive MANET BroadcastabstractMobile Ad-Hoc Networks (MANETs) allow distributed applications where no fixed network infrastructure is available. MANETs use wireless communication subject to faults and uncertainty, and must support efficient broadcast. Controlled flooding is suitable for highly-dynamic networks, while overlay-based broadcast is suitable for dense and more static ones. Density and mobility vary significantly over a MANET deployment area. We present the design and implementation of emergent overlays for efficient and reliable broadcast in heterogeneous MANETs. This adaptation technique allows nodes to automatically switch from controlled flooding to the use of an overlay. Interoperability protocols support the integration of both protocols in a single heterogeneous system. Coordinated adaptation policies allow regions of nodes to autonomously and collectively emerge and dissolve overlays. Our simulation of the full network stack of 600 mobile nodes shows that emergent overlays reduce energy consumption, and improve reliability and coverage compared to single protocols and to two previously-proposed adaptation techniques. Raziel Carvajal-Gomez, Yehia El-khatib, Laurent Réveillère, Etienne Rivière, Yérom-David Bromberg |
SRDS | 4 |
| 2018 | Mind the Gap: Autonomous Detection of Partitioned MANET Systems using Opportunistic AggregationabstractMobile Ad-hoc Networks (MANETs) use limited-range wireless communications and are thus exposed to partitions when nodes fail or move out of reach of each other. Detecting partitions in MANETs is unfortunately a nontrivial task due to their inherently decentralized design and limited resources such as power or bandwidth. In this paper, we propose a novel and fully decentralized approach to detect partitions (and other large membership changes) in MANETs that is both accurate and resource efficient. We monitor the current composition of a MANET using the lightweight aggregation of compact membership-encoding filters. Changes in these filters allow us to infer the likelihood of a partition with a quantifiable level of confidence. We first present an analysis of our approach, and show that it can detect close to 100% of partitions under realistic settings, while at the same time being robust to false positives due to churn or dropped packets. We perform a series of simulations that compare against alternative approaches and confirm our theoretical results, including above 90% accurate detection even under a 40% message loss rate. Simon Bouget, Yérom-David Bromberg, Hugues Mercier, Etienne Rivière, François Taïani |
SRDS | 4 |
| 2018 | Héron: Taming Tail Latencies in Key-Value Stores Under Heterogeneous WorkloadsabstractAvoiding latency variability in distributed storage systems is challenging. Even in well-provisioned systems, factors such as the contention on shared resources or the unbalanced load between servers affect the latencies of requests and in particular the tail (95th and 99th percentile) of their distribution. One effective counter measure for reducing tail latency in key-value stores is to provide efficient replica selection algorithms. However, existing solutions are based on the assumption that all requests have almost the same execution time. This is not true for real workloads. This mismatch leads to increased latencies for requests with short execution time that get scheduled behind requests with large execution times. We propose Héron, a replica selection algorithm that supports workloads with heterogeneous request execution times. We evaluate Héron in a cluster of machines using a synthetic dataset inspired from the Facebook dataset as well as two real datasets from Flickr and WikiMedia. Our results show that Héron outperforms state-of-the-art algorithms by reducing both median and tail latency by up to 41%. Vikas Jaiman, Sonia Ben Mokhtar, Vivien Quéma, Lydia Y. Chen, Etienne Rivière |
SRDS | 5 |
| 2017 | Density and Mobility-Driven Evaluation of Broadcast Algorithms for MANETsabstractBroadcast is a fundamental operation in Mobile Ad-Hoc Networks (MANETs). A large variety of broadcast algorithms have been proposed. They differ in the way message forwarding between nodes is controlled, and in the level of information about the topology that this control requires. Deployment scenarios for MANETs vary widely, in particular in terms of nodes density and mobility. The choice of an algorithm depends on its expected coverage and energy cost, which are both impacted by the deployment context. In this work, we are interested in the comprehensive comparison of the costs and effectiveness of broadcast algorithms for MANETs depending on target environmental conditions. We describe the results of an experimental study of five algorithms, representative of the main design alternatives. Our study reveals that the best algorithm for a given situation, such as a high density and a stable network, is not necessarily the most appropriate for a different situation such as a sparse and mobile network. We identify the algorithms characteristics that are correlated with these differences and discuss the pros and cons of each design. Raziel Carvajal-Gomez, Inti Y. Gonzalez-Herrera, Yérom-David Bromberg, Laurent Réveillère, Etienne Rivière |
ICDCS | 5 |
| 2017 | CRESON: Callable and Replicated Shared Objects over NoSQLabstractIn a Cloud environment, the ability to share and persist objects simplifies the design of applications. Storing objects in a NoSQL database ensures their availability and provides scalability to applications. When Object-NoSQL Mapping is performed at the client side, objects that are accessed by several clients are repeatedly converted between their in-memory and serialized representations. This negatively impacts performance and increases replication costs. In this paper, we describe the design of CRESON, a system supporting callable objects over NoSQL, in which application objects are mapped and instantiated directly on the storage nodes. CRESON supports composition by reference and ensures strong consistency. Objects are replicated and maintained coherent using State Machine Replication. The implementation of CRESON leverages the support of a listenable key-value store (LKVS), a novel NoSQL storage abstraction that we introduce in this paper. We discuss the performance and complexity of CRESON with the example of the portage of a personal cloud storage service, initially developed using an object-relational mapping over a sharded PostgreSQL database. Our results show that CRESON offers a simpler programming experience both in terms of learning time and lines of code, while performing better on average and being more scalable. Pierre Sutra, Etienne Rivière, Cristian Cotes, Marc Sánchez Artigas, Pedro García López, Emmanuel Bernard, William Burns, Galder Zamarreno |
ICDCS | 2 |
| 2017 | On the impact of indirect WAN routing on geo-replicated storageabstractMicro-clouds infrastructures allow supporting applications on local and energy-efficient resources. Communication between micro-clouds takes place on shared and non-dedicated Internet links. Network control and optimization can only happen at the edge. For availability and persistence, the storage of application data must be geo-replicated. Maintaining strong data consistency under concurrent accesses requires delay-sensitive coherence protocols, linking the performance of the storage to that of the network between micro-clouds. We evaluate if the use of network control at the edge of a European-wide multi-site testbed, together with appropriate network monitoring, can allow improving the performance of ZooKeeper, a strongly-consistent replicated store. Our approach leverages the indirect routing of coherence protocol traffic in the presence of network triangle equality violations. We analyze the impact on storage of variations in WAN performance, and show how the use of traffic redirection can help reducing it. Raziel Carvajal-Gomez, Eduard-Florentin Luchian, Iustin-Alexandru Ivanciu, Adrian Taut, Virgil Dobrota, Etienne Rivière |
LANMAN | 6 |
| 2017 | Efficient and Confidentiality-Preserving Content-Based Publish/Subscribe with PrefilteringabstractContent-based publish/subscribe provides a loosely-coupled and expressive form of communication for large-scale distributed systems. Confidentiality is a major challenge for publish/subscribe middleware deployed over multiple administrative domains. Encrypted matching allows confidentiality-preserving content-based filtering but has high performance overheads. It may also prevent the use of classical optimizations based on subscriptions containment. We propose a support mechanism that reduces the cost of encrypted matching, in the form of a prefiltering operator using Bloom filters and simple randomization techniques. This operator greatly reduces the amount of encrypted subscriptions that must be matched against incoming encrypted publications. It leverages subscription containment information when available, but also ensures that containment confidentiality is preserved otherwise. We propose containment obfuscation techniques and provide a rigorous security analysis of the information leaked by Bloom filters in this case. We conduct a thorough experimental evaluation of prefiltering under a large variety of workloads. Our results indicate that prefiltering is successful at reducing the space of subscriptions to be tested in all cases. We show that while there is a tradeoff between prefiltering efficiency and information leakage when using containment obfuscation, it is practically possible to obtain good prefiltering performance while securing the technique against potential leakages. Raphaël Barazzutti, Pascal Felber, Hugues Mercier, Emanuel Onica, Etienne Rivière |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2016 | Evaluating the Cost and Robustness of Self-organizing Distributed Hash TablesabstractSelf-organizing construction principles are a natural fit for large-scale distributed system in unpredictable deployment environments. These principles allow a system to systematically converge to a global state by means of simple, uncoordinated actions by individual peers. Indexing services based on the distributed hash table (DHT) abstraction have been established as a solid foundation for large-scale distributed applications. For most DHTs, the creation and maintenance of the overlay structure relies on the exploration and update of an already stabilized structure. We evaluate in this paper the practical interest of self-organizing principles, and in particular gossip-based overlay construction protocols, to bootstrap and maintain various DHT implementations. Based on the seminal work on T-Chord, a self-organizing version of Chord using the T-Man overlay construction service, we contribute three additional self-organizing DHTs: T-Pastry, T-Kademlia and T-Kelips. We conduct an experimental evaluation of the cost and performance of each of these designs using a prototype implementation. Our conclusion is that, while providing equivalent performance in a stabilized system, self-organizing DHTs are able to sustain and recover from higher level of churn than their explicitly-created counterparts, and should therefore be considered as a method of choice for deploying robust indexing layers in adverse environments. These keywords were added by machine and not by the authors. This process is experimental and the keywords may be updated as the learning algorithm improves. Sveta Krasikova, Raziel Carvajal-Gomez, Heverson B. Ribeiro, Etienne Rivière, Valerio Schiavoni |
DAIS | 4 |
| 2016 | OpenStack-based clouds as holons: A functional perspectiveabstractThe generalization of distributed systems-of-systems lead to increasing management and operation complexity. A sound approach to deal with this complexity is to leverage overlay networks and the higher level of abstraction they allow for distributed operations. In particular, the virtualization of underlying network resources allows providing a range of reusable network services and compose them with existing systems. Recently, the notion of holons as compositional systems entities was proposed as a general framework for the programming and deployment of complex systems of systems. We investigate if this abstract model can be applied to the complex process of real-time composition of OpenStack-based IaaS clouds. In this context, we also address issues related to the energy-performance tradeoff using techniques similar to those involving dynamic service consolidations. Our solution aims at simplifying the life of infrastructure and service providers, allowing them to face the dynamicity of new demands in Future Internet. Iustin-Alexandru Ivanciu, Eduard-Florentin Luchian, Virgil Dobrota, Etienne Rivière |
LANMAN | 4 |
| 2016 | GlobalFS: A Strongly Consistent Multi-site File SystemabstractThis paper introduces GlobalFS, a POSIX-compliant geographically distributed file system. GlobalFS builds on two fundamental building blocks, an atomic multicast group communication abstraction and multiple instances of a single-site data store. We define four execution modes and show how all file system operations can be implemented with these modes while ensuring strong consistency and tolerating failures. We describe the GlobalFS prototype in detail and report on an extensive performance assessment. We have deployed GlobalFS across all EC2 regions and show that the system scales geographically, providing performance comparable to other state-of-the-art distributed file systems for local commands and allowing for strongly consistent operations over the whole system. The code of GlobalFS is available as open source. Leandro Pacheco de Sousa, Raluca Halalai, Valerio Schiavoni, Fernando Pedone, Etienne Rivière, Pascal Felber |
SRDS | 5 |
| 2015 | UniCrawl: A Practical Geographically Distributed Web CrawlerabstractAs the wealth of information available on the web keeps growing, being able to harvest massive amounts of data has become a major challenge. Web crawlers are the core components to retrieve such vast collections of publicly available data. The key limiting factor of any crawler architecture is however its large infrastructure cost. To reduce this cost, and in particular the high upfront investments, we present in this paper a geo-distributed crawler solution, UniCrawl. UniCrawl orchestrates several geographically distributed sites. Each site operates an independent crawler and relies on well-established techniques for fetching and parsing the content of the web. UniCrawl splits the crawled domain space across the sites and federates their storage and computing resources, while minimizing thee inter-site communication cost. To assess our design choices, we evaluate UniCrawl in a controlled environment using the ClueWeb12 dataset, and in the wild when deployed over several remote locations. We conducted several experiments over 3 sites spread across Germany. When compared to a centralized architecture with a crawler simply stretched over several locations, UniCrawl shows a performance improvement of 93.6% in terms of network bandwidth consumption, and a speedup factor of 1.75. Do Le Quoc, Christof Fetzer, Pascal Felber, Etienne Rivière, Valerio Schiavoni, Pierre Sutra |
CLOUD | 4 |
| 2015 | Efficient Key Updates through Subscription Re-encryption for Privacy-Preserving Publish/SubscribeabstractContent-based publish/subscribe (pub/sub) is an appealing information dissemination paradigm for distributed systems. Consumers of data subscribe to a pub/sub service, typically offered through a distributed broker overlay, and indicate their interests as constraints over the information content. Publishers generate the information flow, which the brokers filter and route to the interested subscribers. Protecting the information confidentiality, and in particular the interests of subscribers, is an important concern when brokers are located in untrusted domains such as public clouds. Encrypted matching techniques allow untrusted brokers to store encrypted subscriptions and match them against encrypted publications. Updates of encryption keys regularly happen in such contexts due to changes in trust relations. These key updates cause the invalidation of stored encrypted subscriptions and force subscribers to re-encrypt and re-submit them. This long and costly operation impacts the pub/sub service continuity and performance. In this paper, we propose a novel technique that allows updating encrypted subscriptions directly at the brokers while maintaining privacy. We present an implementation of the technique for the ASPE encrypted matching scheme and prove the security of our extension. We evaluate its practical effectiveness through a prototype implementation including a dependable key distribution protocol. Our experiments show the ability to handle key updates while preserving service continuity and performance. Emanuel Onica, Pascal Felber, Hugues Mercier, Etienne Rivière |
Middleware | 4 |
| 2014 | Autonomous Multi-dimensional Slicing for Large-Scale Distributed Systems
Mathieu Pasquet, Francisco Maia 0001, Etienne Rivière, Valerio Schiavoni |
DAIS | 3 |
| 2014 | Elastic Scaling of a High-Throughput Content-Based Publish/Subscribe EngineabstractPublish/subscribe (pub/sub) infrastructures running as a service on cloud environments offer simplicity and flexibility for composing distributed applications. Provisioning them appropriately is however challenging. The amount of stored subscriptions and incoming publications varies over time, and the computational cost depends on the nature of the applications and in particular on the filtering operation they require (e.g., content-based vs. topic-based, encrypted vs. non-encrypted filtering). The ability to elastically adapt the amount of resources required to sustain given throughput and delay requirements is key to achieving cost-effectiveness for a pub/sub service running in a cloud environment. In this paper, we present the design and evaluation of an elastic content-based pub/sub system: E-STREAMHUB. Specific contributions of this paper include: (1) a mechanism for dynamic scaling, both out and in, of stateful and stateless pub/sub operators, (2) a local and global elasticity policy enforcer maintaining high system utilization and stable end-to-end latencies, and (3) an evaluation using real-world tick workload from the Frankfurt Stock Exchange and encrypted content-based filtering. Raphaël Barazzutti, Thomas Heinze 0001, André Martin, Emanuel Onica, Pascal Felber, Christof Fetzer, Zbigniew Jerzak, Marcelo Pasin, Etienne Rivière |
ICDCS | 9 |
| 2014 | A Practical Distributed Universal Construction with Unknown Participants
Pierre Sutra, Etienne Rivière, Pascal Felber |
OPODIS | 2 |
| 2014 | LAYSTREAM: Composing standard gossip protocols for live video streamingabstractGossip-based live streaming is a popular topic, as attested by the vast literature on the subject. Despite the particular merits of each proposal, all need to implement and deal with common challenges such as membership management, topology construction and video packets dissemination. Well-principled gossip-based protocols have been proposed in the literature for each of these aspects. Our goal is to assess the feasibility of building a live streaming system, LAYSTREAM, as a composition of these existing protocols, to deploy the resulting system on real testbeds, and report on lessons learned in the process. Unlike previous evaluations conducted by simulations and considering each protocol independently, we use real deployments. We evaluate protocols both independently and as a layered composition, and unearth specific problems and challenges associated with deployment and composition. We discuss and present solutions for these, such as a novel topology construction mechanism able to cope with the specificities of a large-scale and delay-sensitive environment, but also with requirements from the upper layer. Our implementation and data are openly available to support experimental reproducibility. Miguel Matos, Valerio Schiavoni, Etienne Rivière, Pascal Felber, Rui Oliveira 0001 |
P2P | 3 |
| 2014 | On the Support of Versioning in Distributed Key-Value StoresabstractThe ability to access and query data stored in multiple versions is an important asset for many applications, such as Web graph analysis, collaborative editing platforms, data forensics, or correlation mining. The storage and retrieval of versioned data requires a specific API and support from the storage layer. The choice of the data structures used to maintain versioned data has a fundamental impact on the performance of insertions and queries. The appropriate data structure also depends on the nature of the versioned data and the nature of the access patterns. In this paper we study the design and implementation space for providing versioning support on top of a distributed key-value store (KVS). We define an API for versioned data access supporting multiple writers and show that a plain KVS does not offer the necessary synchronization power for implementing this API. We leverage the support for listeners at the KVS level and propose a general construction for implementing arbitrary types of data structures for storing and querying versioned data. We explore the design space of versioned data storage ranging from a flat data structure to a distributed sharded index. The resulting system, ALEPH, is implemented on top of an industrial-grade open-source KVS, Infinispan. Our evaluation, based on real-world Wikipedia access logs, studies the performance of each versioning mechanisms in terms of load balancing, latency and storage overhead in the context of different access scenarios. Pascal Felber, Marcelo Pasin, Etienne Rivière, Valerio Schiavoni, Pierre Sutra, Fábio Coelho 0001, Rui Oliveira 0001, Miguel Matos, Ricardo Vilaça |
SRDS | 3 |
| 2014 | ZooFence: Principled Service Partitioning and Application to the ZooKeeper Coordination ServiceabstractCloud computing infrastructures leverage fault-tolerant and geographically distributed services in order to meet the requirements of modern applications. Each service deals with a large number of clients that compete for the resources it offers. When the load increases, the service needs to scale. In this paper, we investigate a scalability solution which consists in partitioning the service state. We formulate specific conditions under which a service is partitionable. Then, we present a general algorithm to build a dependable and consistent partitioned service. To assess the practicability of our approach, we implement and evaluate the ZooFence coordination service. ZooFence orchestrates several instances of ZooKeeper and presents the exact same API and semantics to its clients. It automatically splits the coordination service state among ZooKeeper instances while being transparent to the application. By reducing the convoy effect on operations and leveraging the workload locality, our approach allows proposing a coordination service with a greater scalability than with a single ZooKeeper instance. The evaluation of ZooFence assesses this claim for two benchmarks, a synthetic service of concurrent queues and the BookKeeper distributed logging engine. Raluca Halalai, Pierre Sutra, Etienne Rivière, Pascal Felber |
SRDS | 3 |
| 2014 | DATAFLASKS: Epidemic Store for Massive Scale SystemsabstractVery large scale distributed systems provide some of the most interesting research challenges while at the same time being increasingly required by nowadays applications. The escalation in the amount of connected devices and data being produced and exchanged, demands new data management systems. Although new data stores are continuously being proposed, they are not suitable for very large scale environments. The high levels of churn and constant dynamics found in very large scale systems demand robust, proactive and unstructured approaches to data management. In this paper we propose a novel data store solely based on epidemic (or gossip-based) protocols. It leverages the capacity of these protocols to provide data persistence guarantees even in highly dynamic, massive scale systems. We provide an open source prototype of the data store and correspondent evaluation. Francisco Maia 0001, Miguel Matos, Ricardo Vilaça, José Pereira 0001, Rui Oliveira 0001, Etienne Rivière |
SRDS | 6 |
| 2013 | Evaluating the Price of Consistency in Distributed File Storage Services
José Valerio, Pierre Sutra, Etienne Rivière, Pascal Felber |
DAIS | 3 |
| 2013 | DATAFLASKS: An epidemic dependable key-value substrateabstractRecently, tuple-stores have become pivotal structures in many information systems. Their ability to handle large datasets makes them important in an era with unprecedented amounts of data being produced and exchanged. However, these tuple-stores typically rely on structured peer-to-peer protocols which assume moderately stable environments. Such assumption does not always hold for very large scale systems sized in the scale of thousands of machines. In this paper we present a novel approach to the design of a tuple-store. Our approach follows a stratified design based on an unstructured substrate. We focus on this substrate and how the use of epidemic protocols allow reaching high dependability and scalability. Francisco Maia 0001, Miguel Matos, Ricardo Vilaça, José Pereira 0001, Rui Oliveira 0001, Etienne Rivière |
DSN | 6 |
| 2013 | SplayNet: Distributed User-Space Topology Emulation
Valerio Schiavoni, Etienne Rivière, Pascal Felber |
Middleware | 2 |
| 2013 | FastLane: improving performance of software transactional memory for low thread countsabstractSoftware transactional memory (STM) can lead to scalable implementations of concurrent programs, as the relative performance of an application increases with the number of threads that support it. However, the absolute performance is typically impaired by the overheads of transaction management and instrumented accesses to shared memory. This often leads STM-based programs with low thread counts to perform worse than a sequential, non-instrumented version of the same application. Jons-Tobias Wamhoff, Christof Fetzer, Pascal Felber, Etienne Rivière, Gilles Muller |
PPoPP | 4 |
| 2013 | Performance/Security Tradeoffs for Content-Based Routing Supported by Bloom Filters
Hugues Mercier, Emanuel Onica, Etienne Rivière, Pascal Felber |
SIROCCO | 3 |
| 2013 | Lightweight, efficient, robust epidemic dissemination
Miguel Matos, Valerio Schiavoni, Pascal Felber, Rui Oliveira 0001, Etienne Rivière |
J. Parallel Distributed Comput. | 5 |
| 2013 | CoFeed: privacy-preserving Web search recommendation based on collaborative aggregation of interest feedbackabstractSUMMARY Search engines essentially rely on the structure of the graph of hyperlinks. Although accurate for the main trend, this is not effective when some query is ambiguous. Leveraging semantic information by the mean of interest matching allows proposing complementary results that are tailored to the user's expectations. This paper proposes a collaborative search companion system, CoFeed, that collects user search queries and that considers feedback to build user‐centric and document‐centric profiling information. Over time, the system constructs ranked collections of elements that maintain the required information diversity and enhance the user search experience by presenting additional results tailored to the user's interest space. This collaborative search companion requires a supporting architecture adapted to large user populations generating high request loads. To that end, it integrates mechanisms for ensuring scalability and load balancing of the service under varying loads and user interest distributions. Moreover, collecting the recommendation data poses the problem of users’ privacy, and the bias one peer can induce to the system by sending fake recommendations. To that end, CoFeed ensures both publisher anonymity and rate limitation. With the former, the origin of the data is never known by the server that processes it, even if several servers collude to spy on some user. The latter, combined with decoupled authentication, allows to minimize the influence of cheating peers sending fake recommendations. Experiments with a deployed prototype highlight the efficiency of the system by analyzing improvement in search relevance, computational cost, scalability and load balancing. Copyright © 2011 John Wiley & Sons, Ltd. Pascal Felber, Peter G. Kropf, Lorenzo Leonini, Toan Luu, Martin Rajman, Etienne Rivière, Valerio Schiavoni, José Valerio |
Softw. Pract. Exp. | 6 |
| 2013 | Scaling Up Publish/Subscribe Overlays Using Interest Correlation for Link SharingabstractTopic-based publish/subscribe is at the core of many distributed systems, ranging from application integration middleware to news dissemination. Therefore, much research was dedicated to publish/subscribe architectures and protocols, and in particular to the design of overlay networks for decentralized topic-based routing and efficient message dissemination. Nonetheless, existing systems fail to take full advantage of shared interests when disseminating information, hence suffering from high maintenance and traffic costs, or construct overlays that cope poorly with the scale and dynamism of large networks. In this paper, we present StaN, a decentralized protocol that optimizes the properties of gossip-based overlay networks for topic-based publish/subscribe by sharing a large number of physical connections without disrupting its logical properties. StaN relies only on local knowledge and operates by leveraging common interests among participants to improve global resource usage and promote topic and event scalability. The experimental evaluation under two real workloads, both via a real deployment and through simulation, shows that StaN provides an attractive infrastructure for scalable topic-based publish/subscribe. Miguel Matos, Pascal Felber, Rui Oliveira 0001, José Pereira 0001, Etienne Rivière |
IEEE Trans. Parallel Distributed Syst. | 5 |
| 2012 | Slead: Low-Memory, Steady Distributed Systems Slicing
Francisco Maia 0001, Miguel Matos, Etienne Rivière, Rui Oliveira 0001 |
DAIS | 3 |
| 2012 | BRISA: Combining Efficiency and Reliability in Epidemic Data DisseminationabstractThere is an increasing demand for efficient and robust systems able to cope with today's global needs for intensive data dissemination, e.g., media content or news feeds. Unfortunately, traditional approaches tend to focus on one end of the efficiency/robustness design spectrum, by either leveraging rigid structures such as trees to achieve efficient distribution, or using loosely-coupled epidemic protocols to obtain robustness. In this paper we present BRISA, a hybrid approach combining the robustness of epidemic-based dissemination with the efficiency of tree-based structured approaches. This is achieved by having dissemination structures such as trees implicitly emerge from an underlying epidemic substrate by a judicious selection of links. These links are chosen with local knowledge only and in such a way that the completeness of data dissemination is not compromised, i.e., the resulting structure covers all nodes. Failures are treated as an integral part of the system as the dissemination structures can be promptly compensated and repaired thanks to the underlying epidemic substrate. Besides presenting the protocol design, we conduct an extensive evaluation in a real environment, analyzing the effectiveness of the structure creation mechanism and its robustness under faults and churn. Results confirm BRISA as an efficient and robust approach to data dissemination in the large scale. Miguel Matos, Valerio Schiavoni, Pascal Felber, Rui Oliveira 0001, Etienne Rivière |
IPDPS | 5 |
| 2012 | Infrastructure Provisioning for Scalable Content-Based Routing: Framework and AnalysisabstractContent-based publish/subscribe is an attractive paradigm for designing large-scale systems, as it decouples producers of information from consumers. This provides extensive flexibility for applications, which can use a modular architecture. Using this architecture, each participant expresses its interest in events by means of filters on the content of those events instead of using pre-established communication channels. However, matching events against filters has a non-negligible processing cost. Scaling the infrastructure with the number of users or events requires appropriate provisioning of resources for each of the operations involved: routing and filtering. In this paper, we propose and describe a generic, modular, and scalable infrastructure for supporting high-performance content-based publish/subscribe. We analyze its properties and show how it dynamically scales in a realistic setting. Our results provide valuable insights into the design and deployment of scalable content-based routing infrastructures. Raphaël Barazzutti, Pascal Felber, Hugues Mercier, Emanuel Onica, Jean-Francois Pineau, Etienne Rivière, Christof Fetzer |
NCA | 6 |
| 2012 | Pulp: An adaptive gossip-based dissemination protocol for multi-source message streams
Pascal Felber, Anne-Marie Kermarrec, Lorenzo Leonini, Etienne Rivière, Spyros Voulgaris |
Peer-to-Peer Netw. Appl. | 4 |
| 2011 | Deadline-aware scheduling for Software Transactional MemoryabstractSoftware Transactional Memory (STM) is an optimistic concurrency control mechanism that simplifies the development of parallel programs. Still, the interest of STM has not yet been demonstrated for reactive applications that require bounded response time for some of their operations. We propose to support such applications by allowing the developer to annotate some transaction blocks with deadlines. Based on previous execution statistics, we adjust the transaction execution strategy by decreasing the level of optimism as the deadlines near through two modes of conservative execution, without overly limiting the progress of concurrent transactions. Our implementation comprises a STM extension for gathering statistics and implementing the execution mode strategies. We have also extended the Linux scheduler to disable preemption or migration of threads that are executing transactions with deadlines. Our experimental evaluation shows that our approach significantly improves the chance of a transaction meeting its deadline when its progress is hampered by conflicts. Walther Maldonado, Patrick Marlier, Pascal Felber, Julia Lawall, Gilles Muller, Etienne Rivière |
DSN | 6 |
| 2011 | WHISPER: Middleware for Confidential Communication in Large-Scale NetworksabstractA wide range of distributed applications requires some form of confidential communication between groups of users. In particular, the messages exchanged between the users and the identity of group members should not be visible to external observers. Classical approaches to confidential group communication rely upon centralized servers, which limit scalability and represent single points of failure. In this paper, we present WHISPER, a fully decentralized middleware that supports confidential communications within groups of nodes in large-scale systems. It builds upon a peer sampling service that takes into account network limitations such as NAT and firewalls. WHISPER implements confidentiality in two ways: it protects the content of messages exchanged between the members of a group, and it keeps the group memberships secret to external observers. Using multi-hops paths allows these guarantees to hold even if attackers can observe the link between two nodes, or be used as content relays for NAT bypassing. Evaluation in real-world settings indicates that the price of confidentiality remains reasonable in terms of network load and processing costs. Valerio Schiavoni, Etienne Rivière, Pascal Felber |
ICDCS | 2 |
| 2010 | Learning to Find Interesting Connections in WikipediaabstractTo help users answer the question, what is the relation between (real world) entities or concepts, we might need to go well beyond the borders of traditional information retrieval systems. In this paper, we explore the possibility of exploiting the Wikipedia link graph as a knowledge base for finding interesting connections between two or more given concepts, described by Wikipedia articles.We use a modified Spreading Activation algorithm to identify connections between input concepts.The main challenge in our approach lies in assessing the strength of a relation defined by a link between articles. We propose two approaches for link weighting and evaluate their results with a user evaluation. Our results show a strong correlation between used weighting methods and user preferences; results indicate that the Wikipedia link graph can be used as valuable semantic resource. Marek Ciglan, Etienne Rivière, Kjetil Nørvåg |
APWeb | 2 |
| 2010 | Collaborative Ranking and Profiling: Exploiting the Wisdom of Crowds in Tailored Web Search
Pascal Felber, Peter G. Kropf, Lorenzo Leonini, Toan Luu, Martin Rajman, Etienne Rivière |
DAIS | 6 |
| 2010 | Evaluation of AMD's advanced synchronization facility within a complete transactional memory stackabstractAMD's Advanced Synchronization Facility (ASF) is an x86 instruction set extension proposal intended to simplify and speed up the synchronization of concurrent programs. In this paper, we report our experiences using ASF for implementing transactional memory. We have extended a C/C++ compiler to support language-level transactions and generate code that takes advantage of ASF. We use a software fallback mechanism for transactions that cannot be committed within ASF (e.g., because of hardware capacity limitations). Our evaluation uses a cycle-accurate x86 simulator that we have extended with ASF support. Building a complete ASF-based software stack allows us to evaluate the performance gains that a user-level program can obtain from ASF. Our measurements on a wide range of benchmarks indicate that the overheads traditionally associated with software transactional memories can be significantly reduced with the help of ASF. David Christie, Jae-Woong Chung, Stephan Diestelhorst, Michael Hohmuth, Martin Pohlack, Christof Fetzer, Martin Nowack, Torvald Riegel, Pascal Felber, Patrick Marlier, Etienne Rivière |
EuroSys | 11 |
| 2010 | SPADS: Publisher Anonymization for DHT StorageabstractMany distributed applications, such as collaborative Web mapping, collaborative feedback and ranking, or bug reporting systems, rely on the aggregation of privacy-sensitive information gathered from human users. This information is typically aggregated at servers and later used as the basis for some collaborative service. Expecting that clients trust that the user-centric information will not be used for malevolent purposes is not realistic in a fully distributed setting where nodes are not under the control of a single administrative domain. Moreover, most of the time the origin of the data is of small importance when computing the aggregation onto which these services are based. Trust problems can be evinced by ensuring that the identity of the user is dropped before the data can actually be used, a process called publisher anonymization. Such a property shall be guaranteed even if a set of servers is colluding to spy on some user. This also requires that malevolent users cannot harm the service by sending any number of items without being traceable due to publisher anonymization. Rate limitation and decoupled authentication are the two mechanisms that ensure that these cheating users have a limited impact on the system. This paper presents SPADS, a system that interfaces to any DHT and supports the three objectives of publisher anonymization, rate limitation and decoupled authentication. The evaluation of a deployed prototype on a cluster assesses its performance and small footprint. Pascal Felber, Martin Rajman, Etienne Rivière, Valerio Schiavoni, José Valerio |
Peer-to-Peer Computing | 3 |
| 2009 | SPLAY: Distributed Systems Evaluation Made Simple (or How to Turn Ideas into Live Systems in a Breeze)
Lorenzo Leonini, Etienne Rivière, Pascal Felber |
NSDI | 2 |
| 2009 | Network-Friendly Gossiping
Sabina Serbu, Etienne Rivière, Pascal Felber |
SSS | 2 |
| 2009 | Rappel: Exploiting interest and network locality to improve fairness in publish-subscribe systems
Jay A. Patel, Etienne Rivière, Indranil Gupta, Anne-Marie Kermarrec |
Comput. Networks | 2 |
| 2008 | P2P Experimentations with Splay: From Idea to Deployment Results in 30 minabstractSplay is an integrated system that facilitates the complete chain of distributed systems evaluation, from design and implementation to deployment and experiments control. Algorithms are expressed in a concise, yet very efficient, language based on Lua. Implementations in Splay are highly similar to the pseudo-code usually found in research papers. Splay eases the use of any kind of testbeds, e.g., PlanetLab, ModelNet clusters, or non-dedicated platforms such as networks of workstations. Using Splay and PlanetLab, this demonstration highlights a complete evaluation chain of an epidemic protocol and a churn-driven experiment using the Pastry DHT. Lorenzo Leonini, Etienne Rivière, Pascal Felber |
Peer-to-Peer Computing | 2 |
| 2007 | VoroNet: A scalable object network based on Voronoi tessellationsabstractIn this paper, we propose the design of VoroNet, an object-based peer to peer overlay network relying on Voronoi tessellations, along with its theoretical analysis and experimental evaluation. VoroNet differs from previous overlay networks in that peers are application objects themselves and get identifiers reflecting the semantics of the application instead of relying on hashing functions. This enables a scalable support for efficient search in large collections of data. In VoroNet, objects are organized in an attribute space according to a Voronoi diagram. VoroNet is inspired from the Kleinberg's small-world model where each peer gets connected to close neighbours and maintains an additional pointer to a long-range neighbour. VoroNet improves upon the original proposal as it deals with general object topologies and therefore copes with skewed data distributions. We show that VoroNet can be built and maintained in a fully decentralized way. The theoretical analysis of the system proves that routing in VoroNet can be achieved in a poly-logarithmic number of hops in the size of the system. The analysis is fully confirmed by our experimental evaluation by simulation. Olivier Beaumont, Anne-Marie Kermarrec, Loris Marchal, Etienne Rivière |
IPDPS | 4 |
| 2007 | Peer to Peer Multidimensional Overlays: Approximating Complex Structures
Olivier Beaumont, Anne-Marie Kermarrec, Etienne Rivière |
OPODIS | 3 |
| 2006 | GosSkip, an Efficient, Fault-Tolerant and Self Organizing Overlay Using Gossip-based Construction and Skip-Lists PrinciplesabstractThis paper presents GosSkip, a self organizing and fully distributed overlay that provides a scalable support to data storage and retrieval in dynamic environments. The structure of GosSkip, while initially possibly chaotic, eventually matches a perfect set of Skip-list-like structures, where no hash is used on data attributes, thus preserving semantic locality and permitting range queries. The use of epidemic-based protocols is the key to scalability, fairness and good behavior of the protocol under churn, while preserving the simplicity of the approach and maintaining O(log(N)) state per peer and O(log(N)) routing costs. In addition, we propose a simple and efficient mechanism to exploit the presence of multiple data items on a single physical node. GosSkip's behavior in both a static and a dynamic scenario is further conveyed by experiments with an actual implementation and real traces of a peer to peer workload Rachid Guerraoui, Sidath B. Handurukande, Kévin Huguenin, Anne-Marie Kermarrec, Fabrice Le Fessant, Etienne Rivière |
Peer-to-Peer Computing | 6 |