VLDB 2026 Research / reviewers in the wild / expert
Nikos Fotiou
dblp:02/8484
· DBLP profile ↗
28ranked-venue papers
15as first author
12since 2021 · last 2026
0000-0001-9100-1081ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 17 · 8 first-author · 7 since 2021Security and privacy · 3 · 2 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Relationship-based Access Control for Data SpacesabstractData spaces are an emerging concept with significant potential to enable a data-centric economy by fostering seamless and secure data sharing across diverse stakeholders. These environments are designed to unlock the value of data by ensuring interoperability and collaboration, which are essential for innovation and informed decision-making. However, managing access control in data spaces poses unique challenges, as it must account for complex relationships not only among stakeholders but also among data items themselves, requiring a flexible and context-aware approach. To this end, in this paper we present the design, implementation, and evaluation of an access control solution tailored for data spaces. Our solution leverages the paradigm of Relationship-Based Access Control (ReBAC), enabling the definition and enforcement of access control policies that consider the relationships between entities within the data space, as well as data consumer organisational structures. Furthermore, we propose a distributed version of our solution to facilitate the segregation of access control management across different administrative domains. Our approach supports fine-grained, continuous access control by dynamically evaluating the context of both the protected data items and the consumers of the data space. To ensure compatibility with existing data-sharing standards, we have integrated our solution with ETSI NGSI-LD API, a standardised interface for interacting with data spaces. Nikos Fotiou, Chalima Dimitra Nassar Kyriakidou, Athanasia Maria Papathanasiou, Vasilios A. Siris, George C. Polyzos |
Data Sci. Eng. | 1 |
| 2025 | Secure and Efficient Data Spaces over Named Data Networking
Yannis Thomas, Nikos Fotiou, Iakovos Pittaras, George Xylomenos |
Networking | 2 |
| 2024 | Certificate Management for Cloud-Hosted Digital TwinsabstractA key enabler for the digitization of physical devices is digital twining technology. A digital twin is a virtual representation of a physical object (or a collection of physical objects) that allows their integration into cyber systems. Digital twins are usually hosted in cloud environments, which provide high availability and resilience to failures. This integration creates new opportunities and enables new capabilities, but it also raises security concerns. In this paper, we design a digital certificate management solution that allows building trust on digital twins independently of their network location. Our solution allows digital twins to securely receive certificates, which can be used to digitally sign data at the application layer. Our scheme does not depend on the certificate infrastructure used to secure the communication between end-users and the (cloud-hosted) digital twins. Our solution is feasible, realistic and resilient against key breaches, with a marginal communication overhead. Finally, our scheme automates the process of certificate issuance for digital twins, thus enabling very fast key and certificate rotation. Nikos Fotiou, Chalima Dimitra Nassar Kyriakidou, Athanasia Maria Papathanasiou, Iakovos Pittaras, Yannis Thomas, George Xylomenos |
ISCC | 1 |
| 2024 | Poster: Named Data Networking for Data SpacesabstractThe Secure Named Data Sharing (SNDS) architecture is a content brokering service built on top of Named-Data Networking (NDN), leveraging its native support for multicast, multisource and caching. SNDS transparently supports IP-based content providers and consumers via a gateway that implements ETSI’s NGSI-LD data spaces API, translating HTTP requests to and from the appropriate NDN messages. To fully support the query-based NGSI-LD API, we build appropriate protocols over NDN. We present a prototype implementation of the SNDS architecture and a preliminary evaluation of its features. Yannis Thomas, Nikos Fotiou, Iakovos Pittaras, George Xylomenos |
ISCC | 2 |
| 2024 | Secure smart contract-based digital twins for the Internet of ThingsabstractThe proliferation of Internet of Things (IoT) devices that operate unattended providing a multitude of important and often sensitive services highlights the need for seamless interoperability and increased security. We argue that digital twins of IoT devices, with the right design, can enhance the security, reliability, auditability, and interoperability of IoT systems. The salient features of digital twins have made them key elements for the IoT and Industry 4.0. In this paper, we leverage advances in W3C's Web of Things (WoT) standards and Distributed Ledger Technologies (DLTs) to present a novel design of smart contract-based digital twins with enhanced security, transparency, interoperabilty, and reliability. We provide two different variations of that general design using two different blockchains (one public and one private, permissioned blockchain), and we present design trade-offs. Furthermore, we introduce an architecture for accessing and controlling IoT devices securely, reliably, providing full auditability, while at the same time using the proposed digital twins as an indirection mechanism (proxy). The proposed architecture leverages the blockchain to offer notable properties, namely, decentralization, immutability, auditability, non-repudiation, availability, and reliability. Moreover, it introduces mass actuation, easier management of IoT devices, enhanced security to the IoT gateways, it enables new business models, and it makes consumer devices (vendor-)agnostic. Iakovos Pittaras, Nikos Fotiou, Christos Karapapas, Vasilios A. Siris, George C. Polyzos |
Blockchain Res. Appl. | 2 |
| 2023 | Access control for interoperable energy management systems using Verifiable CredentialsabstractEmerging energy management systems (EMS) involve devices and services provided by multiple stakeholders. In order to improve the interoperability of these systems, state of the art efforts propose an interoperability middleware that mediates the communication between end-user applications and EMS components. The potential lack of trust between the different stakeholders raises the need for fine-grained access control mechanisms. However, extending the middleware to support access control in a secure and usable way is a challenging problem. In this paper, we present a solution that achieves fine-grained authorization using Verifiable Credentials (VCs). Our solution leverages VC properties to enable end-users to combine authorizations issued by different entities. Additionally, our solution integrates a cloud-based VC wallet that hides the authorization process from end-user applications, thus facilitating interoperability among EMSes and the development of new, secure applications. Nikos Fotiou, Spiros Chadoulos, Iordanis Koutsopoulos, Vasilios A. Siris, George C. Polyzos |
TrustCom | 1 |
| 2023 | Self-verifiable content using decentralized identifiers
Nikos Fotiou, Yannis Thomas, Vasilios A. Siris, George Xylomenos, George C. Polyzos |
Comput. Networks | 1 |
| 2022 | Secure, Mass Web of Things Actuation Using Smart Contracts-Based Digital TwinsabstractThe proliferation of Internet of Things (IoT) devices and applications that need to cooperate unattended highlights the need for seamless interoperability and intrinsic security. We argue that Distributed Ledger Technologies (DLTs), due to their decentralized nature, transparent operations, immutability, and availability, can enhance the security, reliability, and interoperability of such IoT systems. In this paper, we advance the integration of W3C's Web of Things (WoT) standards with DLTs and smart contracts, introducing smart contracts as “Digital Twins” of (physical) devices, or whole Cyber-Physical subsystems. Namely, we introduce a DLT-based architecture for controlling devices across federated IoT systems, securely, reliably, and with full auditability. The proposed architecture provides mass actuation and service composition with notable security properties, such as full auditability, transparency, and high availability. Specifically, a single request, with multiple action parameters and conditions, can trigger the reliable and secure actuation of a large number of possibly physically dispersed actuators. Iakovos Pittaras, Nikos Fotiou, Christos Karapapas, Vasilios A. Siris, George C. Polyzos |
ISCC | 2 |
| 2021 | Securing Named Data Networking routing using Decentralized IdentifiersabstractNamed Data Networking (NDN) is a realization of the Information-Centric Networking (ICN) paradigm, where routing is based on content identifiers rather than on network location identifiers. The routing state in NDN can grow exponentially, not only due to the huge number of content identifiers (as opposed to network addresses) but also because it is difficult to detect "fake" routing advertisements. For example, in contrast to IP-based routing, a potentially valid routing entry in NDN can be advertised from multiple network locations, making NDN susceptible to Denial-of-Service attacks at the routing layer. In this paper, we leverage Decentralized Identifiers (DIDs) to build self-verifiable "content advertisements." With our solution, any router can verify that a content advertisement originates from an "authorized" entity, without requiring any trusted third party. We implement our solution and we evaluate it in a scenario where filtering is implemented by the edge routers. We show that our solution reduces fake routing advertisements with minimal computational overhead. Nikos Fotiou, Yannis Thomas, Vasilios A. Siris, George Xylomenos, George C. Polyzos |
HPSR | 1 |
| 2021 | Capability-based access control for multi-tenant systems using OAuth 2.0 and Verifiable CredentialsabstractWe propose a capability-based access control technique for sharing Web resources, based on Verifiable Credentials (VCs) and OAuth 2.0. VCs are a secure means for expressing claims about a subject. Although VCs are ideal for encoding capabilities, the lack of standards for exchanging and using VCs impedes their adoption and limits their interoperability. We mitigate this problem by integrating VCs into the OAuth 2.0 authorization flow. To this end, we propose a new form of OAuth 2.0 access token based on VCs. Our approach leverages JSON Web Tokens (JWT) to encode VCs and takes advantage of JWT-based mechanisms for proving VC possession. Our solution not only requires minimum changes to existing OAuth 2.0 code bases, but it also removes some of the complexity of verifying VC claims by relying on JSON Web Signatures: a simple, standardized, and well supported signature format. Additionally, we fill the gap of VC generation processes by defining a new protocol that leverages the OAuth 2.0 “client credentials” grant. Nikos Fotiou, Vasilios A. Siris, George C. Polyzos |
ICCCN | 1 |
| 2021 | Enabling self-verifiable mutable content items in IPFS using Decentralized IdentifiersabstractIn IPFS content identifiers are constructed based on the item's data therefore the binding between an item's identifier and its data can be deterministically verified. Nevertheless, once an item is modified, its identifier also changes. Therefore when it comes to mutable content there is a need for keeping track of the “latest” IPFS identifier. This is achieved using naming protocols on top of IPFS, such as IPNS and DNSlink, that map a constant name to an IPFS identifier, allowing at the same time content owners to update these mappings. Nevertheless, IPNS relies on a cryptographic key pair that cannot be rotated, and DNSlink does not provide content authenticity protection. In this paper, we propose a naming protocol that combines DNSlink and decentralized identifiers to enable self-verifiable content items. Our protocol provides content authenticity without imposing any security requirement to DNSlink. Furthermore, our protocol prevent fake content even if attackers have access to the DNS server of the content owner or have access to the content owner secret keys. Our proof of concept implementation shows that our protocol is feasible and can be used with existing IPFS tools. Nikos Fotiou, Vasilios A. Siris, George C. Polyzos |
Networking | 1 |
| 2021 | A privacy-preserving statistics marketplace using local differential privacy and blockchain: An application to smart-grid measurements sharingabstractService providers usually require detailed statistics in order to improve their services. On the other hand, privacy concerns are intensifying and sensitive data is protected by legislation, such as GDPR (General Data Protection Regulation). In this paper, we present the design, implementation, and evaluation of a marketplace that allows “data consumers” to buy information from “data providers”, which can then be used for generating meaningful statistics. Additionally, our system enables “system operators” that can select which data providers are allowed to provide data, based on filtering criteria specified by the data consumer. We leverage local differential privacy to protect the data provider's privacy against data consumers, as well as against system operators, and we build a blockchain-based solution for ensuring fair exchange, and immutable data logs. Our design targets use cases that involve hundreds or even thousands of data providers. We prove the feasibility of our approach through a proof-of concept implementation of a measurement sharing application for smart-grid systems. Nikos Fotiou, Iakovos Pittaras, Vasilios A. Siris, George C. Polyzos, Priit Anton |
Blockchain Res. Appl. | 1 |
| 2020 | Decentralized authorization in constrained IoT environments exploiting interledger mechanisms
Vasilios A. Siris, Dimitris Dimopoulos, Nikos Fotiou, Spyros Voulgaris, George C. Polyzos |
Comput. Commun. | 3 |
| 2020 | Improving mobile ad hoc networks using hybrid IP-Information Centric Networking
Yannis Thomas, Nikos Fotiou, Stavros Toumpis, George C. Polyzos |
Comput. Commun. | 2 |
| 2020 | Enhancing Internet of Things Security using Software-Defined Networking
Bander A. Alzahrani, Nikos Fotiou |
J. Syst. Archit. | 2 |
| 2019 | Exploiting Satellite Broadcast Despite HTTPSabstractHTTPS enhances end-user privacy and is often preferred or enforced by over-the-top content providers, but renders inoperable all intermediate network functions operating above the transport layer, including caching, content/protocol optimization, and security filtering tools. These functions are crucial for the optimization of integrated satellite-terrestrial networks. Additionally, due to the use of end-to-end and per- session encryption keys, the advantages of a satellite's wide- area broadcasting capabilities are limited or even negated completely. This paper investigates two solutions for authorized TLS interception that involve TLS splitting. We present how these solutions can be incorporated into integrated satellite- terrestrial networks and we discuss their trade-offs in terms of deployment, performance, and privacy. Furthermore, we design a solution that leverages satellite broadcast transmission even in the presence of TLS (i.e. with the use of HTTPS) by exploiting application layer encryption in the path between the satellite terminal and the TLS server. Our findings indicate that even if no other operation than TLS splitting is performed, TLS handshake time, which involves roundtrips through possibly a Geosynchronous satellite, can be reduced by up to 94%. Moreover, by combining an application layer encryption solution with TLS splitting, broadcast transmissions can be exploited as well as proactive caching, content pushing, request aggregation, and other optimizations. Nikos Fotiou, Vasilios A. Siris, Mario Marchese, Franco Davoli, Luca Boero, George C. Polyzos |
GLOBECOM | 1 |
| 2019 | Secure IoT Access at Scale Using Blockchains and Smart ContractsabstractBlockchains and smart contracts are an emerging, promising technology, that has received considerable attention. We use the blockchain technology, and in particular Ethereum, to implement a large-scale event-based Internet of Things (IoT) control system. We argue that the distributed nature of the “ledger,” as well as, Ethereum's capability of parallel execution of replicated “smart contracts”, provide the sought after automation, generality, flexibility, resilience, and high availability. We design a realistic blockchain-based loT architecture, using existing technologies while by taking into consideration the characteristics and limitations of IoT devices and applications. Furthermore, we leverage blockchain's immutability and Ethereum's support for custom tokens to build a robust and efficient token-based access control mechanism. Our evaluation shows that our solution is viable and offers significant security and usability advantages. Nikos Fotiou, Iakovos Pittaras, Vasilios A. Siris, Spyros Voulgaris, George C. Polyzos |
WOWMOM | 1 |
| 2019 | Trusted D2D-Based IoT Resource Access Using Smart ContractsabstractWe present and evaluate models that allow clients to access IoT resources using secure and trusted device-to-device (D2D) communication, while utilizing smart contracts to obtain the benefits of blockchain technology. These benefits include decentralized trust, immutability, transparency, and high availability. The models consider different network connection capabilities of the clients and the IoT resources, namely continuous network connectivity and D2D-only connectivity. We describe two approaches for utilizing blockchains and smart contracts in the authorization process: in the first approach, only hashes of the authorization information are recorded on the blockchain. In the second approach, a smart contract handles authorization requests. We implement the approaches using the OAuth 2.0 delegated authorization framework and evaluate the implementations on the public Ethereum testnet Rinkeby, in terms of execution cost, contract creation cost, and delay. Our evaluation quantifies the tradeoffs of blockchain cost and smart contract functionality, such as blocking and non-blocking operation, and the reduction of the transaction cost that can be achieved when multiple authorization requests are concatenated in a single transaction. Vasilios A. Siris, Dimitris Dimopoulos, Nikos Fotiou, Spyros Voulgaris, George C. Polyzos |
WOWMOM | 3 |
| 2018 | QOE Performance Evaluation of Youtube Video Streaming in Mobile Broadband NetworksabstractIn this paper, a performance evaluation of the Quality-of-Experience (QoE) of YouTube video streaming in mobile broadband networks with active measurements is described. The measurements were collected from a field experiment campaign using the MONROE platform which provides probes in four European countries and enables the benchmarking of three mobile broadband operators. Firstly, we present a framework for the automated collection and processing of the measurements, and then, we analyze the results to identify the cache allocation policy per operator. Additionally, we examine whether the selected cache server has an effect on the delivered video quality and present the results using standardised objective methods for the estimation of the perceived quality. Savvas Argyropoulos, Nikos Fotiou, George C. Polyzos |
WOWMOM | 2 |
| 2018 | Smart IoT Data CollectionabstractWe present and experimentally evaluate procedures for efficient IoT data collection while achieving target requirements in terms of data accuracy and privacy protection. The procedures adjust the time period between consecutive measurements following an additive increase and multiplicative decrease (AIMD) scheme based on a target data accuracy and add noise to measurements using differential privacy techniques. The experimental evaluation involves real temperature and humidity measurements obtained from two testbeds through the FIESTA-IoT platform. Our results show that the AIMD adaptation of the measurement period is robust to different types of measurements from different testbeds, without having any tuning parameters, and the addition of noise to the sensor measurements using differential privacy has a negligible effect on the aggregate statistics. Nikos Fotiou, Vasilios A. Siris, Alexandros Mertzianis, George C. Polyzos |
WOWMOM | 1 |
| 2015 | H-Pastry: An inter-domain topology aware overlay for the support of name-resolution services in the future Internet
Nikos Fotiou, Konstantinos V. Katsaros, George Xylomenos, George C. Polyzos |
Comput. Commun. | 1 |
| 2014 | Fighting packet storms in mobile networks with information-centrismabstractMobile application development for smartphones is a trend in the telecommunications industry. However, their deployment is not seamless since many applications are not “mobile network-friendly.” A key problem that frequently arises is an excessive number of signaling messages, known as signaling storms. This leads to very high overhead and a decrease in operator income. We focus on this problem and propose an approach that is based on an information-centric networking deployment at the access network. We compute the number of signaling messages and derive the conditions under which our approach leads to fewer messages than the approach that is used in current networks. We also argue about the network and application layer modifications that are needed for the adoption of our method. Vaggelis G. Douros, Nikos Fotiou, George C. Polyzos |
QSHINE | 2 |
| 2014 | Realizing the Internet of Things using information-centric networkingabstractNowadays, the Internet connects more objects than people. These devices generate vast amounts of information. Furthermore, identification technologies - such as Radio Frequency Identification (RFID) - enable the association of information with identifiable objects, not necessarily connected to the Internet. All this information is organized into vertical silos. These silos usually belong to different administrative domains and use their own specific communication protocols. In this paper, we present our vision for a global, all-encompassing Internet of Things (IoT) realized through an integrating architecture relying on information and its identifiers/names. We envision the IoT as the architecture that will interconnect all these silos and will make the information generated by or associated with objects globally accessible. Moreover, we argue that the Information-Centric Networking (ICN) paradigm is the ideal candidate architecture for the realization of that IoT vision. In line with this premise, we propose a research agenda for the realization of a full-fledged ICN-based IoT architecture. Nikos Fotiou, George C. Polyzos |
QSHINE | 1 |
| 2014 | Enhancing information lookup privacy through homomorphic encryptionabstractABSTRACT Revealing one's interests in communication has been recognized as a growing problem in the Internet. We postulate that it is desirable for future information retrieval systems to provide privacy in both what information is requested and what information is received, without raising obstacles to the deployment of accounting and access control mechanisms. This paper outlines a solution that fulfills this requirement in the context of broker‐based systems, that is, systems in which brokers facilitate the communication between a consumer and a provider (of information). Broker‐assisted communication is a common paradigm used in many settings, including contemporary information‐centric networking approaches. We present the design and the evaluation of a solution that conceals consumers' interests, without hiding consumer identity or location. The developed solution is applied over a system of hierarchically organized brokers; similar systems are used in many information lookup services. Because in these systems, information is distributed in various locations, traditional private information retrieval (PIR) protocols exhibit significant communication overhead. Our solution achieves up to 97% less communication overhead compared with a PIR protocol, without additional computational overhead. Copyright © 2013 John Wiley & Sons, Ltd. Nikos Fotiou, Dirk Trossen, Giannis F. Marias, Alexandros Kostopoulos, George C. Polyzos |
Secur. Commun. Networks | 1 |
| 2014 | Analysis of the effect of InfoRanking on content pollution in peer-to-peer systemsabstractContent pollution is one of the most common attacks against peer-to-peer file-sharing systems. As such, systems are usually open to users, and the deployed security mechanisms merely examine the sanity of the downloaded files—content pollution attacks can be easily launched. InfoRanking is a mechanism that tries to mitigate this security risk by ranking content items. In this paper, we show through analysis, fluid modeling, and simulation that when InfoRanking is used, attackers can deceive users only when they share corrupted copies of legitimate file versions. Nevertheless, as corrupted files can be immediately detected after being downloaded, this attack is only effective when users enter the system at very low rate and leave relatively fast. Peiqing Zhang, Nikos Fotiou, Bjarne E. Helvik, Giannis F. Marias, George C. Polyzos |
Secur. Commun. Networks | 2 |
| 2012 | On Inter-Domain Name Resolution for Information-Centric Networks
Konstantinos V. Katsaros, Nikos Fotiou, Xenofon Vasilakos, Christopher N. Ververidis, Christos Tsilopoulos, George Xylomenos, George C. Polyzos |
Networking (1) | 2 |
| 2012 | Efficient information lookup for the Internet of ThingsabstractThe Internet of Things is an emerging paradigm that allows the association of information with objects. The information about an object is stored in databases, distributed around the globe, maintained by various stakeholders that participate in the object's supply chain. A Discovery Service (DS) is responsible for collecting all these database URIs and feeding them to clients that query about an object. DSs are usually centralized and are designed to effectively aggregate as many information sources as possible, rather than trying to respond optimally to unforeseen user queries. In this paper we propose a novel, Information-Centric Networking (ICN) inspired, architecture that eliminates the need for a separate DS, enabling at the same time multi-ownership and flexible management of information that is associated with an object. In our ICN approach, information about an object is organized in scopes. Each scope has its own access control rules allowing easy control of information dissemination. Moreover scopes can be hierarchically organized, creating complex access structures that can reflect business relationships. In our architecture companies provide information about an object to the appropriate scopes, but they never lose control of this information. To access information associated with an object,a user queries the scope that corresponds to the desired context, which will forward the query to a service that will respond with the appropriate data. The query will not reveal any extra information, not authorized to be retrieved. Giannis F. Marias, Nikos Fotiou, George C. Polyzos |
WOWMOM | 2 |
| 2010 | Developing Information Networking Further: From PSIRP to PURSUIT
Nikos Fotiou, Pekka Nikander, Dirk Trossen, George C. Polyzos |
BROADNETS | 1 |