Jean-Philippe Wary

dblp:09/10596 · DBLP profile ↗
← Back
12ranked-venue papers
0as first author
6since 2021 · last 2025
0000-0002-6642-1452ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 1 since 2021Computer networks · 2 · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Artificial intelligence and machine learning · 1Theory of computation · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2025 A Continuous Certification Readiness Framework for Cloudification of IT/OT Platforms (Vision Paper)
abstract
Cloud-centric services are becoming the norm in modern IT and Operational Technology (OT) platforms, where cybersecurity risks are also on the rise. The evolving regulatory landscape within Europe, exemplified by the Network and Information Security 2 (NIS2) directive and the Cyber Resilience Act (CRA), further amplifies the necessity for rigorous compliance measures. The presumption of conformity for platforms certified under EU-recognized certification schemes, as outlined by the CRA, is anticipated to promote the certification of IT and OT platforms. Nevertheless, the certification process for these platforms is challenging due to the complexity of cloud architectures and the constantly evolving threats, which require continuous adaptation. Furthermore, both NIS2 and CRA introduce new mandates, including the obligation to manage risks, report incidents to relevant authorities, inform customers about vulnerabilities, and provide relevant mitigation strategies. Consequently, there exists an urgent demand for tools and frameworks that support sustained certification in the cloudification of IT/OT platforms. This paper introduces the Continuous Certification Readiness Framework (CCRF), which is engineered to automate tasks related to certification preparation and support ongoing compliance assessments, thereby enabling organizations to effectively manage risks and uphold a high level of assurance within their cloud environments.
Chrystel Gaber, Nicolas Dejon, Ndeye Gagnessiry Ndiaye, Karl Waedt, Vincent Lefebvre, Gürkan Gür, Marc Rennhard, Achilleas Marinakis, Christos-Antonios Gizelis, Jean-Philippe Wary, Claire Loiseaux
IC2E10
2025 Liability and Trust Analysis Framework for Multi-Actor Dynamic Microservices
abstract
Microservices architecture has become an increasingly common approach for building complex software systems. With the distributed nature of microservices, multiple actors can contribute to a service, hence affecting the dynamics of the environment and making the management of liabilities and trust more challenging. Service-Level Agreements (SLAs) are critical in that regard and any SLA violation or breach can result in significant financial damages. One major challenge is the lack of indicators to handle the liability and trust in such architectures. To address this issue, in this paper we propose a liability and trust analysis framework, namely the LASM Analysis Service (LAS), for multi-actor dynamic microservices that employs Machine Learning (ML) techniques.
Yacine Anser, Chrystel Gaber, Jean-Philippe Wary, Samia Bouzefrane 0001, Méziane Yacoub, Onur Kalinagac, Gürkan Gür
IEEE Trans. Netw. Serv. Manag.3
2023 Demonstrating Liability and Trust Metrics for Multi-Actor, Dynamic Edge and Cloud Microservices
abstract
Transitioning edge and cloud computing in 5G networks towards service-based architecture increases their complexity as they become even more dynamic and intertwine more actors or delegation levels. In this paper, we demonstrate the Liability-aware security manager Analysis Service (LAS), a framework that uses machine learning techniques to compute liability and trust indicators for service-based architectures such as cloud microservices. Based on the commitments of Service Providers (SPs) and real-time observations collected by a Root Cause Analysis (RCA) tool GRALAF, the LAS computes three categories of liability and trust indicators, specifically, a Commitment Trust Score, Financial Exposure, and Commitment Trends.
Yacine Anser, Chrystel Gaber, Romain Cajeat, Jean-Philippe Wary, Samia Bouzefrane 0001, Méziane Yacoub, Onur Kalinagac, Gürkan Gür
MobiCom4
2023 Connectivity in Mobile Device-to-Device Networks in Urban Environments
abstract
In this article we setup a dynamic device-to-device communication system where devices, given as a Poisson point process, move in an environment, given by a street system of random planar-tessellation type, via a random-waypoint model. Every device independently picks a target location on the street system using a general waypoint kernel, and travels to the target along the shortest path on the streets with an individual velocity. Then, any pair of devices becomes connected whenever they are on the same street in sufficiently close proximity, for a sufficiently long time. In our main results we isolate regimes for the almost-sure absence of percolation if, for example, the device intensity is too small, or the connectivity time is too large. On the other hand, we exhibit parameter regimes of sufficiently large intensities of devices, under favorable choices of the other parameters, such that percolation is possible with positive probability. Most interestingly, we also show an in-and-out of percolation as the velocity increases. The rigorous analysis of the system mainly rests on comparison arguments with simplified models via spatial coarse graining and thinning approaches. Here we also make contact to geostatistical percolation models with infinite-range dependencies.
Elie Cali, Alexander Hinsen, Benedikt Jahnel, Jean-Philippe Wary
IEEE Trans. Inf. Theory4
2022 The Owner, the Provider and the Subcontractors: How to Handle Accountability and Liability Management for 5G End to End Service
abstract
The adoption of 5G services depends on the capacity to provide high-value services. In addition to enhanced performance, the capacity to deliver Security Service Level Agreements (SSLAs) and demonstrate their fulfillment would be a great incentive for the adoption of 5G services for critical 5G Verticals (e.g., service suppliers like Energy or Intelligent Transportation Systems) subject to specific industrial safety, security or service level rules and regulations (e.g., NIS or SEVESO Directives). Yet, responsibilities may be difficult to track and demonstrate because 5G infrastructures are interconnected and complex, which is a challenge anticipated to be exacerbated in future 6G networks. This paper describes a demonstrator and a use case that shows how 5G Service Providers can deliver SSLAs to their customers (Service Owners) by leveraging a set of network enablers developed in the INSPIRE-5Gplus project to manage their accountability, liability and trust placed in subcomponents of a service (subcontractors). The elaborated enablers are in particular a novel sTakeholder Responsibility, AccountabIity and Liability deScriptor (TRAILS), a Liability-Aware Service Management Referencing Service (LASM-RS), an anomaly detection tool (IoT-MMT), a Root Cause Analysis tool (IoT-RCA), two Remote Attestation mechanisms (Systemic and Deep Attestation), and two Security-by-Orchestration enablers (one for the 5G Core and one for the MEC).
Chrystel Gaber, Ghada Arfaoui, Yannick Carlinet, Nancy Perrot, Laurent Valeyre, Marc Lacoste, Jean-Philippe Wary, Yacine Anser, Rafal Artych, Aleksandra Podlasek, Edgardo Montes de Oca, Vinh Hoa La, Vincent Lefebvre, Gürkan Gür
ARES7
2022 TRAILS: Extending TOSCA NFV profiles for liability management in the Cloud-to-IoT continuum
abstract
To address the growing amount of data generated by the Internet of Things (IoT), Network Functions Virtualization (NFV), 5G, Fog and Edge computing converge to form a Cloud-to-IoT continuum. This complex multi-layer architecture involves several actors among which responsibilities may be blurred. Existing profiles mostly describe deployment aspects and elude responsibility, accountability or liability characteristics. Moreover, the multiplicity of component profiles prevents uniform service management. This paper proposes TRAILS (sTakeholder Responsibility, AccountabIity and Liability deScriptor), an extension of the TOSCA NFV profile that merges the existing profiles and adds a description of the responsibilities and accountabilities of supply chain actors. This allows a uniform and liability-aware management of services involving IoT devices, fog, edge and cloud nodes. To show the usability of our model, we discuss the ecosystem around the generation of the proposed extension as well as its application in an ontology-based referencing module of a liability-aware service manager that we designed.
Yacine Anser, Chrystel Gaber, Jean-Philippe Wary, Sara Nieves Matheu-García, Samia Bouzefrane 0001
NetSoft3
2020 INSPIRE-5Gplus: intelligent security and pervasive trust for 5G and beyond networks
abstract
The promise of disparate features envisioned by the 3GPP for 5G, such as offering enhanced Mobile Broadband connectivity while providing massive Machine Type Communications likely with very low data rates and maintaining Ultra Reliable Low Latency Communications requirements, create a very challenging environment for protecting the 5G networks themselves and associated assets. To overcome such complexity, future 5G networks must employ a very high degree of network and service management automation, which is a security challenge by itself as well as an opportunity for smarter and more efficient security functions. In this paper, we present the smart, trustworthy and liable 5G security platform being designed and developed in the INSPIRE-5Gplus1 project. This platform takes advantage of new techniques such as Machine Learning (ML), Artificial Intelligence (AI), Distributed Ledger Technologies (DLT), network softwarization and Trusted Execution Environment (TEE) for closed-loop and end-to-end security management following a zero-touch model in 5G and Beyond 5G networks. To this end, we specifically elaborate on two key aspects of our platform, namely security management with Security Service Level Agreements (SSLAs) and liability management, in addition to the description of the overall architecture.
Jordi Ortiz 0001, Ramon Sanchez-Iborra, Jorge Bernal Bernabé, Antonio F. Skarmeta, Chafika Benzaid, Tarik Taleb, Pol Alemany, Raul Muñoz 0001, Ricard Vilalta, Chrystel Gaber, Jean-Philippe Wary, Dhouha Ayed, Pascal Bisson, Maria Christopoulou, Georgios Xilouris, Edgardo Montes de Oca, Gürkan Gür, Gianni Santinelli, Vincent Lefebvre, Antonio Pastor 0001, Diego R. López
ARES11
2020 Malware propagation in urban D2D networks
Alexander Hinsen, Benedikt Jahnel, Elie Cali, Jean-Philippe Wary
WiOpt4
2018 Towards constructive approach to end-to-end slice isolation in 5G networks
abstract
Although 5G (fifth generation) networks are still in the realm of ideas, their architecture can be considered as reaching a forming phase. There are several reports and white papers which attempt to precise 5G architectural requirements presenting them from different points of view, including techno-socio-economic impacts and technological constraints. Most of them deal with network slicing aspects as a central point, often strengthening slices with slice isolation. The idea of isolation in the network is not new. However, currently considered technologies give new capabilities that can bring added value in this field. The goal of this paper is to present and examine the isolation capabilities and selected approaches to its realization in network slicing context. As the 5G architecture is still evolving, the specification of isolated slices operation and management brings new requirements that need to be addressed, especially in a context of end-to-end (E2E) security. Thus, an outline of recent trends in slice isolation and a set of challenges are presented. The challenges, if properly addressed, could be a step from the concept of 5G networks to proof-of-concept solutions which provide E2E user’s security based on slices isolation. Among other things, the key features are proper slice design and establishment, security at interfaces, suitable access protocols, correct virtual resources sharing, and an adaptable management and orchestration architecture (MANO). In conclusion of the paper, short outlines of two of the main secure isolation challenges are given: a proper definition of isolation parameters and designing suitable MANO system.
Zbigniew Kotulski, Tomasz Wojciech Nowak, Mariusz Sepczuk, Marcin Alan Tunia, Rafal Artych, Krzysztof Bocianiak, Tomasz Osko, Jean-Philippe Wary
EURASIP J. Inf. Secur.8
2017 On end-to-end approach for slice isolation in 5G networks. Fundamental challenges
abstract
There are several reports and white papers which attempt to precise 5G architectural requirements presenting them from different points of view, including techno-socio-economic impacts and technological constraints.Most of them deal with network slicing aspects as a central point, often strengthening slices with slice isolation.The goal of this paper is to present and examine the isolation capabilities and selected approaches for its realization in network slicing context.As the 5G architecture is still evolving, the specification of isolated slices operation and management brings new requirements that need to be addressed, especially in a context of End-to-End (E2E) security.Thus, an outline of recent trends in slice isolation and a set of challenges are proposed, which (if properly addressed) could be a step to E2E user's security based on slices isolation.
Zbigniew Kotulski, Tomasz Wojciech Nowak, Mariusz Sepczuk, Marcin Alan Tunia, Rafal Artych, Krzysztof Bocianiak, Tomasz Osko, Jean-Philippe Wary
FedCSIS8
2017 Diet-ESP: IP layer security for IoT
abstract
The number of devices connected through the Internet of Things (IoT) will significantly grow in the next few years while security of their interconnections is going to be a major challenge. For many devices in IoT scenarios, the necessary resources to send and receive bytes are extremely high and when such devices are powered with battery the amount of exchanged bytes directly impacts their life time. As a result, compression of existing protocols is a widely accepted technique to make IoT benefit from the protocols developed over the last decades. This paper presents ESP Header Compression (EHC), a framework that enables compression of packets protected with Encapsulating Security Payload (ESP). EHC is composed of EHC Rules, targeting the compression of a specific field and organized according to EHC Strategies. Further, the paper presents Diet-ESP, an EHC Strategy that highly reduces the networking overhead of ESP packets to address the IoT security and bandwidth requirements. Diet-ESP results in sending fewer bytes which in turn reduces the number of required radio frames and thus battery consumption. The measurements showed that sending 10 byte application data on IEEE 802.15.4 radio networks secured with the standard ESP requires sending an additional frame. This results into a 95% energy overhead compared to the unprotected data, while Diet-ESP results only in a 3% overhead compared to unprotected data. This small overhead is achievable with some compressions being performed within the ESP stack which requires altering the same. Nevertheless, Diet-ESP remains fully security compliant to ESP and performs better than any other compression framework as far as ESP is considered.
Daniel Migault, Tobias Guggemos, Sylvain Killian, Maryline Laurent, Guy Pujolle, Jean-Philippe Wary
J. Comput. Secur.6
2011 Evaluation of the Ability to Transform SIM Applications into Hostile Applications
Guillaume Bouffard, Jean-Louis Lanet, Jean-Baptiste Machemie, Jean-Yves Poichotte, Jean-Philippe Wary
CARDIS5