VLDB 2026 Research / reviewers in the wild / expert
Eduardo Jacob
dblp:07/6968 · also Eduardo Jacob Taquet
· DBLP profile ↗
24ranked-venue papers
2as first author
6since 2021 · last 2026
0000-0001-7093-0586ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 9 · 4 since 2021Security and privacy · 2Software engineering, systems software and programming languages · 2Systems, architecture and hardware · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Privacy enhanced QKD networks: Zero trust relay architecture based on homomorphic encryptionabstract• Zero-trust relay for QKD networks using homomorphic encryption on conventional hardware • External QRNG integration to enhance crypto-agility in embedded random key generation • An extra confidentiality layer through the integration of cryptographic hardware Quantum key distribution (QKD) enables unconditionally secure symmetric key exchange between parties. However, terrestrial fibre-optic links face inherent distance constraints due to quantum signal degradation. Traditional solutions to overcome these limits rely on trusted relay nodes, which perform intermediate re-encryption of keys using one-time pad (OTP) encryption. This approach, however, exposes keys as plaintext at each relay, requiring significant trust and stringent security controls at every intermediate node. These “trusted” relays become a security liability if compromised. To address this issue, we propose a zero-trust relay design that applies fully homomorphic encryption (FHE) to perform intermediate OTP re-encryption without exposing plaintext keys, effectively mitigating the risks associated with potentially compromised or malicious relay nodes. Additionally, the architecture enhances crypto-agility by incorporating external quantum random number generators, thus decoupling key generation from specific QKD hardware and reducing vulnerabilities tied to embedded key-generation modules. The solution is designed with the existing European Telecommunication Standards Institute (ETSI) QKD standards in mind, enabling straightforward integration into current infrastructures. Its feasibility has been successfully demonstrated through a hybrid network setup combining simulated and commercially available QKD equipment. The proposed zero-trust architecture thus significantly advances the scalability and practical security of large-scale QKD networks, greatly reducing reliance on fully trusted infrastructure. Aitor Brazaola-Vicario, Oscar Lage, Julen Bernabé-Rodríguez, Eduardo Jacob, Jasone Astorga |
Comput. Networks | 4 |
| 2026 | Secure the Core: A novel approach for secure and efficient communication in Service-Based Architectures and beyond 5G networksabstractSecurity in Service-Based Architectures (SBA) is often overlooked, as it is an optional feature within Public Land Mobile Networks (PLMN) and Non-Public Networks (NPNs). Nonetheless, one of the primary objectives of upcoming mobile networks is to establish secure communications using APIs, TLS authentication, and OAuth 2.0 authorization, even though these might be seen as heavy protocols involving numerous messages between Network Functions (NFs) and the Network Repository Function (NRF). This paper presents an innovative technique, compatible with current standards, for authenticating the consumer NF and performing the service request while reducing the authentication time by more than 30%. The proposed mechanism builds on the TLS session resumption mechanism (0-RTT resumption for TLS 1.3), resuming a previously established session to improve performance. It proposes employing the NRF as both an authentication server and a storage for TLS sessions with each NF, which are then delegated to consumers. Results show that the service discovery and service request times can be 20.25% and 47.63% faster respectively, demonstrating the clear enhancement to the performance of the security mechanisms in SBA and core networks. • Secure session delegation allows 0-RTT TLS in 5G core network communication. • NRF stores and delegates PSKs to enable session resumption across NFs. • TLS offloading reduces handshake latency and overhead in 5G SBA. • OAuth 2.0 authorization integrated with TLS PSK delegation by NRF. • Framework enhances SBA performance while maintaining 3GPP security compliance. Asier Atutxa, Jasone Astorga, Ane Sanz, Eduardo Jacob |
J. Netw. Comput. Appl. | 4 |
| 2025 | PRoT-FL: A privacy-preserving and robust Training Manager for Federated LearningabstractFederated Learning emerged as a promising solution to enable collaborative training between organizations while avoiding centralization. However, it remains vulnerable to privacy breaches and attacks that compromise model robustness, such as data and model poisoning. This work presents PRoT-FL, a privacy-preserving and robust Training Manager capable of coordinating different training sessions at the same time. PRoT-FL conducts each training session through a Federated Learning scheme that is resistant to privacy attacks while ensuring robustness. To do so, the model exchange is conducted by a “Private Training Protocol” through secure channels and the protocol is combined with a public blockchain network to provide auditability, integrity and transparency. The original contribution of this work includes: (i) the proposal of a “Private Training Protocol” that breaks the link between a model and its generator, (ii) the integration of this protocol into a complete system, PRoT-FL, which acts as an orchestrator and manages multiple trainings and (iii) a privacy, robustness and performance evaluation. The theoretical analysis shows that PRoT-FL is suitable for a wide range of scenarios, being capable of dealing with multiple privacy attacks while maintaining a flexible selection of methods against attacks that compromise robustness. The experimental results are conducted using three benchmark datasets and compared with traditional Federated Learning using different robust aggregation rules. The results show that those rules still apply to PRoT-FL and that the accuracy of the final model is not degraded while maintaining data privacy. Idoia Gamiz, Cristina Regueiro, Eduardo Jacob, Oscar Lage, Maria Victoria Higuero |
Inf. Process. Manag. | 3 |
| 2024 | Towards a quantum-safe 5G: Quantum Key Distribution in core networksabstractThe Service-Based Architecture (SBA) of the fifth generation (5G) of cellular networks introduced great advancements in flexibility, efficiency, and performance of modern networks, thanks to the distribution and softwarization of core network entities called Network Functions (NFs). Due to the distributed nature of 5G systems, these NFs are usually located in different sites to provide better Quality of Service (QoS) or specific services, which poses a great challenge regarding security. However, even though the 3GPP standard identifies security requirements by leveraging Transport Layer Security (TLS) authentication and OAuth2.0 authorization, current experimental and commercial deployments often disregard these aspects for the sake of simplicity and performance. In fact, even though data and communication protection is crucial, the implementation of security protocols and mechanisms complicates the deployments and may reduce the efficiency of 5G systems. This paper presents a novel solution that implements TLS for authentication and encryption leveraging entanglement-based Quantum Key Distribution (QKD), ensuring that all the communications between NFs in the 5G core network are secured by QKD keys, and are therefore quantum-safe. Additionally, this paper presents a QKD key repository using the Network Repository Function (NRF), which stores and relays TLS session keys to authenticated consumer NFs to access producer NFs in a fast but quantum-safe process. The solution was validated in a real hardware environment, and obtained results demonstrate that the proposed solution enhances the security of the SBA communications in an efficient way, reducing an 85% the service request time compared to the traditional TLS-based procedure, as well as 29.96% fewer bytes transmitted throughout the process. Asier Atutxa, Ane Sanz, Jorge Sasiain, Jasone Astorga, Eduardo Jacob |
Comput. Commun. | 5 |
| 2024 | A comprehensive latency profiling study of the Tofino P4 programmable ASIC-based hardwareabstractNetwork softwarization has significantly evolved since programmable data planes became topical in academia and industry. Programming Protocol-Independent Packet Processors (P4) is a language to define packet forwarding behavior. Forwarding devices that are programmed with the P4 language support a flexible way to define headers, parse graphs, and data plane logic. However, extending the data plane with additional functionalities has an impact on packet data plane latency. For this reason, this paper analyzes the key factors that affect data pane latency to packets processed by the Tofino-based target (Tofino Native Architecture (TNA)), which can be considered the de facto production-ready and P4-programmable Application-Specific Integrated Circuit (ASIC). Our work first provides an extensive set of latency measurements and, afterwards, it includes a set of data plane latency predictions using the model derived from the latency results and machine learning (ML) algorithms. We demonstrate that the PCA-lasso polynomial (PLP) obtains the best results among the algorithms tested. The best-case results show that PLP obtained an accuracy of 98.22% prediction accuracy when considering the parser, deparser, and the control block for traffic running at 10G/s (SFP+) and 100G/s (QSFP28). To the best of our knowledge, this is the first work that provides such a comprehensive profiling, including a method to predict data plane latency in production-grade Tofino ASIC-based switching hardware, which could be leveraged to yield accurate latency values prior to investment and deployment. David Franco, Eder Ollora Zaballa, Mingyuan Zang, Asier Atutxa, Jorge Sasiain, Aleksander Pruski, Elisa Rojas, Maria Victoria Higuero, Eduardo Jacob |
Comput. Commun. | 9 |
| 2021 | Automation of Modular and Programmable Control and Data Plane SDN NetworksabstractIn the last years, Software-Defined Networking (SDN) has provided a new approach to network programmability, first regarding the control plane and later the data plane. With the popularity of the data plane programming languages like P4, SDN network automation has extended from developing control plane applications and deploying controllers to integrating custom packet processing pipelines in this process. However, developing control and data plane applications can become burdensome since expertise in both fields is scarce. The process of automating SDN networks requires (among many tasks) inter-plane correlated application self-collection and assembly. As a result, the orchestrator presented in this paper, named P4click, provides high-level interfaces in order to transparently deploy modular control and data plane applications for SDN networks. This paper describes the architecture design of the orchestrator, outlines the deployment structure, and provides a general view of control plane application deployment and data plane pipeline assembly. Besides, P4click requires no previous knowledge of data plane programming and provides a simple interface for network operators that have to deploy new network functionalities. The results in this paper show which tasks in the network automation are most influential (timewise) in bringing a network up and running from the ground up. Eder Ollora Zaballa, David Franco, Eduardo Jacob, Maria Victoria Higuero, Michael S. Berger |
CNSM | 3 |
| 2020 | Cetratus: A framework for zero downtime secure software updates in safety-critical systemsabstractSummary Safety‐critical systems are evolving into complex, networked, and distributed systems. As a result of the high interconnectivity among all networked systems and of potential security threats, security countermeasures need to be incorporated. Nonetheless, albeit cutting‐edge security measures are adopted and incorporated during the system development, such as latest recommended encryption algorithms, these protection mechanisms may turn out obsolete because of the long operational periods. New security flaws and bugs are continuously detected. Software updates are then essential to restore the security level of the system. However, system shutdowns may not be acceptable when high availability is required. As expressed by the European Union Agency for Network and Information Security (ENISA) “the research in the area of patching and updating equipment without disruption of service and tools” is needed. In this article, a novel live updating approach for zero downtime safety‐critical systems named Cetratus is presented. Cetratus, which is based on a quarantine‐mode execution and monitoring, enables the update of non‐safety‐critical software components while running, without compromising the safety integrity level of the system. The focus of this work lies on the incorporation of leading‐edge security mechanisms while safety‐related software components will remain untouched. Other non‐safety‐related software components could also be updated. Imanol Mugarza, Jorge Parra, Eduardo Jacob |
Softw. Pract. Exp. | 3 |
| 2019 | Impact assessment of policy expressiveness of an optimised access control model for smart sensorsabstractIn the incoming internet of things (IoT) applications, smart sensors expose services to interact with them, to be parameterised, managed and maintained. Therefore, fine‐grained end‐to‐end access control enforcement is mandatory to tackle the derived security requirements. However, it is still not feasible in very constrained devices. There is an innovative access control model that conveys an expressive policy language and an optimised codification for tight and flexible access control enforcement in very constrained devices. Such tightness enabled by the expressiveness of the policy language leads to detailed policy instances that might impact on the performance and therefore, in the feasibility and further applicability. In this context, this study assesses how the policy length impacts the performance of the establishment of a security association through the protocol named Hidra proposed by such an adapted access control model. Consequently, the notable results of the performance evaluation prove the feasibility and adequacy of this access control model for the new smart IoT scenarios. Mikel Uriarte, Jasone Astorga, Eduardo Jacob, Maider Huarte, Óscar López |
IET Inf. Secur. | 3 |
| 2018 | Innovating at the Connected Industry: SDN and NFV Experiences and Lessons LearnedabstractThe aim of this poster is to present the SN4I (Smart Networks for Industry) infrastructure, which will be used to interconnect real machine tools among them and with research laboratories in order to allow experimentation in Industry 4.0 services based on NFV (Network Function Virtualization) and SDN (Software Defined Networking) technologies. In this poster, we present the insights of the SN4I infrastructure as well as the challenges faced during its deployment and the main outcomes achieved so far. Jasone Astorga, Eduardo Jacob |
ICNP | 3 |
| 2016 | An architecture for dynamic QoS management at Layer 2 for DOCSIS access networks using OpenFlow
Alaitz Mendiola, Victor Fuentes, Jon Matías, Jasone Astorga, Nerea Toledo, Eduardo Jacob, Maider Huarte |
Comput. Networks | 6 |
| 2015 | Managing path diversity in layer 2 critical networks by using OpenFlowabstractCritical environments demand redundant networks to achieve high availability. Also, many industrial applications have stringent latency requirements that must be met by the Ethernet mesh networks in which they are supported. However, redundant resources are usually used as backup solutions, being underutilized most of the time. This paper analyzes the relation between the network meshing and load balancing with the latency. As a representative example, it is shown that network management in modern substation automation systems can be improved through the Software-Defined Networking (SDN) paradigm. In contrast to spanning tree-based networks, this paper describes how the OpenFlow technology is used to control Local Area Networks (LANs) to make the most of redundant topologies. Thus, an external controller provides flow-aware load balancing that impacts directly latency reduction, meeting the IEC 61850 requirements. Through emulation it is studied how data flows in IEC 61850-based substation communication systems are balanced as required. Elias Molina, Jon Matías, Armando Astarloa, Eduardo Jacob |
CNSM | 4 |
| 2015 | Self-deploying Service Graphs over ELwUD (EHU-OEF Lightweight UNIFY Domain)abstractThe service delivery has evolved during the last years. The introduction of Software Defined Networking (SDN) and Network Functions Virtualisation (NFV) has driven network programmability to foster the innovation in the provisioning of new services. The orchestration and dynamic deployment of resources for service delivery are relevant topics covered by this demonstration. Jokin Garay, Jon Matías, Alaitz Mendiola, Jasone Astorga, Eduardo Jacob |
NetSoft | 5 |
| 2015 | A lossy channel aware parameterisation of a novel security protocol for wireless IP-enabled sensors
Jasone Astorga, Eduardo Jacob, Nerea Toledo, Marina Aguado, Maria Victoria Higuero |
Wirel. Networks | 2 |
| 2014 | Enhancing secure access to sensor data with user privacy support
Jasone Astorga, Eduardo Jacob, Nerea Toledo, Juanjo Unzilla |
Comput. Networks | 2 |
| 2014 | The EHU-OEF: An OpenFlow-based Layer-2 experimental facility
Jon Matías, Alaitz Mendiola, Nerea Toledo, Borja Tornero, Eduardo Jacob |
Comput. Networks | 5 |
| 2012 | Ladon1: end-to-end authorisation support for resource-deprived environmentsabstractThe authors present Ladon, an enhanced version of Kerberos which extends the original protocol with authorisation capacity and relaxes the necessity of clock synchronisation by adding to the protocol special limited-lifetime nonces. This way, although all entities need timers, only the clocks of the two servers that constitute the key distribution centre must be synchronised with each other. The design of this protocol is motivated by the emergence of a new trend of applications in which sensors and low-capacity devices become tiny information or application servers directly addressable by any Internet-connected entity. Despite the huge potential of these environments, security is probably the greatest barrier to their long-term success. To address this issue, Ladon allows for end-to-end pair-wise key establishment in an authenticated and authorised manner, while keeping the introduced storage, computational and communication overhead very low. The security analysis with the AVISPA formal validation tool shows that the protocol meets the stated security goals, whereas the performance analysis shows that the overhead of the protocol is bounded and comparable to that of other security protocols which provide even less functionalities. Jasone Astorga, Eduardo Jacob, Maider Huarte, Maria Victoria Higuero |
IET Inf. Secur. | 2 |
| 2011 | Fundamentals of NeMHIP: An enhanced HIP based NEMO protocolabstractThe provision of NEMO support based on an end-to-end protocol presents manageability challenges that are usually overcome delegating the signaling rights to the MR. In addition, whether the protocol is focused on establishing security associations, how these are rekeyed through a proxy-based process with no security threats should be solved. In this work we focus on the HIP protocol and analyze existing HIP based NEMO solutions. Based on found limitations, we outline the fundamentals of our protocol, NeMHIP. Nerea Toledo, Jean-Marie Bonnin, Maria Victoria Higuero, Eduardo Jacob |
CCNC | 4 |
| 2011 | An OpenFlow Based Network Virtualization Framework for the CloudabstractThe Cloud computing paradigm entails a challenging networking scenario. Due to the economy of scale, the Cloud is mainly supported by Data Center infrastructures. Therefore, virtualized environment manageability, seamless migration of virtual machines, inter-domain communication issues and scalability problems are some of the main concerns that should be addressed. A recently proposed abstract model is used as a reference for the Cloud computing architecture. This paper introduces a network virtualization framework for the Cloud based on this model. Accordingly, a proper abstraction of network elements (vhost, vnode and vlink) is defined in order to virtualize the physical infrastructure. Moreover, a novel Layer 2 network virtualization approach based on a new MAC addressing scheme is presented: we propose to build locally administered MAC addresses that hold context information, such as virtual operator, domain, node and host identifiers. In addition, implementation details are suggested, describing how the Open Flow technology can lead to an implementation of the proposed approach. Jon Matías, Eduardo Jacob, Yuri Demchenko |
CloudCom | 2 |
| 2011 | Host Identity Protocol Based NEMO Solutions: An Evaluation of the Signaling OverheadabstractWith the goal of solving shortcomings of MIPv6, alternative protocols such as HIP have been proposed by the research community. In the same way as for MIPv6, solutions to cover NEMO scenarios based on HIP have been worked out. However, there is little agreement on which the best way is to handle NEMO scenarios when using HIP. In this work we analyze different HIP based NEMO solutions and define mathematical models for their analysis. These models are utilized for evaluating the signaling overhead of HIP based NEMO protocols in order to provide insight in the specification of the features a HIP based NEMO solution should fulfill. Nerea Toledo, Jean-Marie Bonnin, Maria Victoria Higuero, Eduardo Jacob |
VTC Spring | 4 |
| 2010 | A Privacy Enhancing Architecture for Collaborative Working Environments
Jasone Astorga, Purificación Sáiz, Eduardo Jacob, Jon Matías |
PRO-VE | 3 |
| 2008 | The WiMAX ASN Network in the V2I ScenarioabstractThis article presents a mobile WiMAX network deployment as a candidate for broadband and low latency V2I communication architecture. Firstly, it looks over the current state of development of the standards involved, outlining the newest trends (i.e. 802.16m support for 500 km/h). Secondly, the opportunities and the main characteristics that this technology offers are highlighted. Thirdly, by stressing this network in two highly demanding scenarios, the challenges that this WiMAX network deployment faces are also identified. Network simulation modeling techniques have been used to carry out the corresponding performance analysis. The inter ASN handover is identified as the critical point to be tackled, so that, the proposed mobile WiMAX architecture meets the WiMAX radio system profile release 1.0 and RNM (reference network model) requirements when the class 2 group real time applications (VoIP & video conference) are deployed. Marina Aguado, Jon Matías, Eduardo Jacob, Marion Berbineau |
VTC Fall | 3 |
| 2005 | A Dual (IP4/IPv6) "Durable Storage" Commercial ServiceabstractIn this article we describe a commercial service that will use distributed resources, such as storage or bandwidth, in a cooperative effort. We name this service "durable storage". This service is able to guarantee the existence of the data it contains in "any circumstance" at "any time". Although the solution is based on a P2P paradigm, we use a centralized approach that matches the commercial side of the service. We have designed the system with anonymity, confidentiality and security in mind. The ISP, or service provider, will not only assure several of the main junctions, such as authentication or directory maintenance, but constitutes as well the only billing point for every user. We describe the architecture or the service and the implementation of the prototype which is a dual stack IPv4/IPv6 application. Finally we point out that the solution is not only IPv6 compatible, but it could clearly benefit from an IPv6 only version. Eduardo Jacob, Juanjo Unzilla, Maria Victoria Higuero, Purificación Sáiz, Marina Aguado, Christian Pinedo |
AINA | 1 |
| 2003 | PKIX-based certification infrastructure implementation adapted to non-personal end entities
Eduardo Jacob, Fidel Liberal, Juanjo Unzilla |
Future Gener. Comput. Syst. | 1 |
| 1999 | A Bew Watermarking Method Using High Frequency Components to Guide the Insertion Process in the Spatial Domain
Iñaki Goirizelaia, Juanjo Unzilla, Eduardo Jacob, Javier Andiano |
CAIP | 3 |