VLDB 2026 Research / reviewers in the wild / expert
Sara Ricci
dblp:167/5638
· DBLP profile ↗
23ranked-venue papers
6as first author
14since 2021 · last 2024
0000-0003-0842-4951ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 19 · 5 first-author · 14 since 2021Artificial intelligence and machine learning · 2 · 1 first-authorDatabases, data management, data science and information retrieval · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Enhancing Cybersecurity Curriculum Development: AI-Driven Mapping and Optimization TechniquesabstractCybersecurity has become important, especially during the last decade. The significant growth of information technologies, internet of things, and digitalization in general, increased the interest in cybersecurity professionals significantly. While the demand for cybersecurity professionals is high, there is a significant shortage of these professionals due to the very diverse landscape of knowledge and the complex curriculum accreditation process. In this article, we introduce a novel AI-driven mapping and optimization solution enabling cybersecurity curriculum development. Our solution leverages machine learning and integer linear programming optimization, offering an automated, intuitive, and user-friendly approach. It is designed to align with the European Cybersecurity Skills Framework (ECSF) released by the European Union Agency for Cybersecurity (ENISA) in 2022. Notably, our innovative mapping methodology enables the seamless adaptation of ECSF to existing curricula and addresses evolving industry needs and trend. We conduct a case study using the university curriculum from Brno University of Technology in the Czech Republic to showcase the efficacy of our approach. The results demonstrate the extent of curriculum coverage according to ECSF profiles and the optimization progress achieved through our methodology. Petr Dzurenda, Sara Ricci, Marek Sikora, Michal Stejskal, Imre Lendak, Pedro Adão |
ARES | 2 |
| 2024 | Lattice-based Multisignature Optimization for RAM Constrained DevicesabstractIn the era of growing threats posed by the development of quantum computers, ensuring the security of electronic services has become fundamental. The ongoing standardization process led by the National Institute of Standards and Technology (NIST) emphasizes the necessity for quantum-resistant security measures. However, the implementation of Post-Quantum Cryptographic (PQC) schemes, including advanced schemes such as threshold signatures, faces challenges due to their large key sizes and high computational complexity, particularly on constrained devices. This paper introduces two microcontroller-tailored optimization approaches, focusing on enhancing the DS2 threshold signature scheme. These optimizations aim to reduce memory consumption while maintaining security strength, specifically enabling the implementation of DS2 on microcontrollers with only 192 KB of RAM. Experimental results and security analysis demonstrate the efficacy and practicality of our solution, facilitating the deployment of DS2 threshold signatures on resource-constrained microcontrollers. Sara Ricci, Vladyslav Shapoval, Petr Dzurenda, Peter B. Rønne, Jan Oupický, Lukas Malina |
ARES | 1 |
| 2023 | DJM-CYBER: A Joint Master in Advanced CybersecurityabstractVarious publicly available studies show that millions of cybersecurity experts are missing worldwide. One possible way to tackle the workforce gap is with tailored higher education programmes. The goal of this paper is to present the relevant projects and frameworks of the European Union which can guide the development of novel cybersecurity education offerings. We describe the most relevant and freely available tools and test them in the development of a joint Master study programme to be offered by a consortium of five European universities. We show that these tools allow educators and study programme developers to map their outputs to the European Cybersecurity Framework developed by the ENISA and other similar frameworks. We complete our work with a detailed analysis of a joint cybersecurity master programme consisting of four innovative and distinctly different tracks. Yianna Danidou, Sara Ricci, Antonio F. Skarmeta, Jiri Hosek, Stefano Zanero, Imre Lendak |
ARES | 2 |
| 2023 | Enhancing Cybersecurity Education in Europe: The REWIRE's Course Selection MethodologyabstractThe European Cybersecurity Skills Framework (ECSF) was introduced by the European Union Agency for Cybersecurity (ENISA) to identify the necessary competencies, knowledge, and skills required for European cybersecurity professionals. The ECSF condenses all cybersecurity-related positions into 12 role profiles, aiming to establish a mutual understanding of essential roles and support the creation of cybersecurity training programs. In order to address the shortage of cybersecurity experts, a multi-criteria selection method is developed to increase the availability, accessibility, and quality of cybersecurity courses and certifications. This Course Selection methodology ensures high-quality training materials that meet the current and future needs of the cybersecurity industry and benefit a wide range of participants. The methodology considers six criteria and provides a scoring system to rank the occupational profiles and select the most relevant profiles for the course design. Our final score formula identifies Chief Information Security Officer (CISO), Cyber Incident Responder, Cyber Threat Intelligence Specialist, and Penetration Tester for the Course creation. Alan Briones, Sara Ricci, Argyro Chatzopoulou, Jakub Cegan, Petr Dzurenda, Ioannis Koutoudis |
ARES | 2 |
| 2023 | Lattice-Based Threshold Signature Implementation for Constrained DevicesabstractThreshold signatures have gained increased attention especially due to their recent applications in blockchain technologies. In fact, current cryptocurrencies such as Bitcoin, and Cardano started to support multi-signature transactions. Even if the Schnorr-based threshold signatures improve the blockchain's privacy and scalability, these schemes do not provide post-quantum security. In this paper, we propose the optimization of the DS2 lattice-based $(n,n)$-threshold signature scheme and present its practical implementation. Moreover, we evaluate our optimized implementation of the DS2 scheme on different platforms. The results demonstrate that our implementation is easily portable and executable on constrained devices based on ARM Cortex-A53, ARM Cortex-M3, and ESP32 architectures. Patrik Dobias, Sara Ricci, Petr Dzurenda, Lukas Malina, Nikita Snetkov |
SECRYPT | 2 |
| 2022 | Job Adverts Analyzer for Cybersecurity Skills Needs EvaluationabstractThis article presents a new free web-based application, the Cybersecurity Job Ads Analyzer, which has been created to collect and analyse job adverts using a machine learning algorithm. This algorithm enables the detection of the skills required in advertised cybersecurity work positions. The application is both interactive and dynamic allowing for automated analyses and for the underlying database of job adverts to be easily updated. Through the Cybersecurity Job Ads Analyzer, it is possible to explore the skills required over time, and thereby enable academia and other training providers to better understand and address the needs of the industry. We will describe in detail the user interface and technical background of the application, as well as highlight the preliminary statistical results we have obtained from analysing the current database of job adverts. Sara Ricci, Marek Sikora, Simon Parker, Imre Lendak, Yianna Danidou, Argyro Chatzopoulou, Rémi Badonnel, Donatas Alksnys |
ARES | 1 |
| 2022 | On the Efficiency and Security of Quantum-resistant Key Establishment Mechanisms on FPGA Platforms
Lukas Malina, Sara Ricci, Patrik Dobias, Petr Jedlicka, Jan Hajny, Kim-Kwang Raymond Choo |
SECRYPT | 2 |
| 2021 | Privacy-Preserving Online Parking Based on Smart ContractsabstractThis work presents a complex privacy-preserving solution based on attribute-based credentials and smart contract techniques for emerging parking services in city zones. Our system provides the full set of privacy-enhancing features such as anonymity, untraceability, and unlinkability of user parking registrations. Thanks to that it prevents the city and service providers from profiling and tracking the users (e.g., their movement). Furthermore, we involved smart contracts and the underlying decentralized Blockchain technology in payment and verification phases to prevent the presence of a single point of failure in those processes which can endanger the system’s security and availability. We provide the full cryptographic specification of the system, its security analysis, and the implementation results in this paper. Petr Dzurenda, Carles Angles-Tafalla, Sara Ricci, Lukas Malina |
ARES | 3 |
| 2021 | Secret Sharing-based Authenticated Key Agreement ProtocolabstractIn this article, we present two novel authenticated key agreement (AKA) schemes that are easily implementable and efficient even on constrained devices. Both schemes are constructed over elliptic curves and extend Schonorr’s signature of knowledge protocol. To the best of our knowledge, we introduce a first AKA protocol based on the proof of knowledge concept. This concept allows a client to prove its identity to a server via secret information while the server can learn nothing about the secret. Furthermore, we extend our protocol via secret sharing to support client multi-device authentication and multi-factor authentication features. In particular, the secret of the client can be distributed among the client’s devices. Petr Dzurenda, Sara Ricci, Raúl Casanova Marqués, Jan Hajny, Petr Cika |
ARES | 2 |
| 2021 | Cybersecurity Curricula DesignerabstractThe paper aims at minimizing the skills gaps and skills shortages on the cybersecurity job market by empowering education and training institutions during the process of creation of new cybersecurity study programs. We provide a complex cybersecurity skills framework based on standardized definitions that helps with the identification of skills and knowledge necessary for cybersecurity work positions. Furthermore, we practically implement the framework in the form of an interactive web application for cybersecurity curricula design. The app, called Curricula Designer, is built upon the framework and allows intuitive design of higher-education curricula and their analysis with respect to requirements of work roles already defined in widely-accepted standards. Using the analytical functions, it is easy to identify missing content in the courses and precisely structure the study program so that the graduates are well-prepared to enter the job market. The Curricula Designer is described in details in this paper, including user interface and technical background, and a link for public free access is provided to serve all education and training institutions. Jan Hajny, Sara Ricci, Edmundas Piesarskas, Marek Sikora |
ARES | 2 |
| 2021 | PESTLE Analysis of Cybersecurity EducationabstractCybersecurity is a vital part of digital economies and digital governing but the discipline is suffering from a pronounced skills shortage. Nevertheless, the reasons for the inability of academia to produce enough graduates with the skills that reflect the needs of the cybersecurity industry are not well understood. Sara Ricci, Vladimir Janout, Simon Parker, Jan Jerabek, Jan Hajny, Argyro Chatzopoulou, Rémi Badonnel |
ARES | 1 |
| 2021 | Implementing CRYSTALS-Dilithium Signature Scheme on FPGAsabstractIn July 2020, the lattice-based CRYSTALS-Dilithium digital signature scheme has been chosen as one of the three third-round finalists in the post-quantum cryptography standardization process by the National Institute of Standards and Technology (NIST). In this work, we present the first Very High Speed Integrated Circuit Hardware Description Language (VHDL) implementation of the CRYSTALS-Dilithium signature scheme for Field-Programmable Gate Arrays (FPGAs). Due to our parallelization-based design requiring only low numbers of cycles, running at high frequency and using reasonable amount of hardware resources on FPGA, our implementation is able to sign 15832 messages per second and verify 10524 signatures per second. In particular, the signing algorithm requires 68461 Look-Up Tables (LUTs), 86295 Flip-Flops (FFs), and the verification algorithm takes 61738 LUTs and 34963 FFs on Virtex 7 UltraScale+ FPGAs. In this article, experimental results for each Dilithium security level are provided and our VHDL-based implementation is compared with related High-Level Synthesis (HLS)-based implementations. Our solution is ca 114 times faster (in the signing algorithm) and requires less hardware resources. Sara Ricci, Lukas Malina, Petr Jedlicka, David Smékal, Jan Hajny, Peter Cíbik, Petr Dzurenda, Patrik Dobias |
ARES | 1 |
| 2021 | Towards CRYSTALS-Kyber VHDL ImplementationabstractKyber is one of the three finalists of the National Institute of Standards and Technology (NIST) post-quantum cryptography competition. This article presents an optimized Very High Speed Integrated Circuit Hardware Description Language (VHDL)-based implementation of the main components of the Kyber scheme, namely Number-Theoretic Transform (NTT) and Keccak. We focus specifically on NTT, Keccak and their derivatives since they largely determine Kyber's performance due to their wide involvement in each step of the scheme. Our high-speed implementation also takes into account the trade-off between the degree of parallelization and the resources utilization. The NTT component is more than 27\% faster than the state-of-the-art implementations. Furthermore, the optimization helps the algorithm to achieve 1 572 839 NTT operations per second. Sara Ricci, Petr Jedlicka, Peter Cíbik, Petr Dzurenda, Lukas Malina, Jan Hajny |
SECRYPT | 1 |
| 2021 | Privacy-preserving data splitting: a combinatorial approach
Oriol Farràs, Jordi Ribes-González, Sara Ricci |
Des. Codes Cryptogr. | 3 |
| 2020 | Outsourcing analyses on privacy-protected multivariate categorical data stored in untrusted clouds
Josep Domingo-Ferrer, David Sánchez 0001, Sara Ricci, Mónica Muñoz-Batista |
Knowl. Inf. Syst. | 3 |
| 2019 | A Privacy-Enhancing Framework for Internet of Things Services
Lukas Malina, Gautam Srivastava 0001, Petr Dzurenda, Jan Hajny, Sara Ricci |
NSS | 5 |
| 2019 | Local bounds for the optimal information ratio of secret sharing schemes
Oriol Farràs, Jordi Ribes-González, Sara Ricci |
Des. Codes Cryptogr. | 3 |
| 2018 | Outsourcing scalar products and matrix products on privacy-protected unencrypted data stored in untrusted clouds
Josep Domingo-Ferrer, Sara Ricci, Carles Domingo-Enrich |
Inf. Sci. | 2 |
| 2017 | A Methodology to Compare Anonymization Methods Regarding Their Risk-Utility Trade-off
Josep Domingo-Ferrer, Sara Ricci, Jordi Soria-Comas |
MDAI | 2 |
| 2017 | Performance Analysis and Comparison of Different Elliptic Curves on Smart CardsabstractElliptic curves are very often used in the cryptographic protocol design due to their memory efficiency and useful features, such as the bilinear pairing support. However, in many cryptographic papers, elliptic curves are used as a black box, without deeper consideration of their mathematical properties and, even more importantly, without considering implementation implications. As a consequence, novel cryptographic schemes are being published without any real chance of implementation on constrained devices due to their lack of support of basic EC operations like point addition or scalar point multiplication. This paper provides the necessary theoretical overview of main forms of elliptic curves, in particular considering their computational and memory complexity. Next, all major platforms of programmable smart cards are evaluated with respect to EC support and the performance of basic arithmetic operations is assessed using benchmarks. Finally, the evaluation of the implementations of ECC schemes, such as ECDH and ECDSA, is presented. Petr Dzurenda, Sara Ricci, Jan Hajny, Lukas Malina |
PST | 2 |
| 2017 | Anonymous Credentials with Practical Revocation using Elliptic Curves
Petr Dzurenda, Jan Hajny, Lukas Malina, Sara Ricci |
SECRYPT | 4 |
| 2016 | Privacy-Preserving Cloud-Based Statistical Analyses on Sensitive Categorical Data
Sara Ricci, Josep Domingo-Ferrer, David Sánchez 0001 |
MDAI | 1 |
| 2015 | Disclosure risk assessment via record linkage by a maximum-knowledge attackerabstractBefore releasing an anonymized data set, the data protector must know how safe the data set is, that is, how much disclosure risk is incurred by the release. If no privacy model is used to select specific privacy guarantees prior to anonymization, posterior disclosure risk assessment must be performed based on the anonymized data set and, if the result is not satisfactory, anonymization must be repeated with stricter privacy parameters. Even if a privacy model is used, it may still be advisable to empirically evaluate disclosure on the anonymized data set, especially if the privacy model parameters have been relaxed to improve data utility. Record linkage is a general methodology to posterior disclosure risk assessment, whereby the data protector attempts to recreate the attacker's re-identification scenario. An important limitation of record linkage is that it usually requires the data protector to make restrictive assumptions on the attacker's background knowledge. To overcome this limitation, we present a maximum-knowledge attacker model and then we specify and compare several record linkage tests for such a worst-case attacker. Our tests are based on comparing the distribution of linkage distances between the original and the anonymized data set with the distribution of distances between one of the two previous data sets and one random data set. The more similar the distributions, the more plausibly deniable are record linkages claimed by an attacker. Because attaining zero disclosure risk for all records is too costly in terms of utility, a less demanding alternative is presented whose goal is to reduce the maximum per-record disclosure risk. Josep Domingo-Ferrer, Sara Ricci, Jordi Soria-Comas |
PST | 2 |