VLDB 2026 Research / reviewers in the wild / expert
Felipe Boeira
dblp:198/9723
· DBLP profile ↗
8ranked-venue papers
5as first author
5since 2021 · last 2024
0000-0003-2707-8089ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-author · 4 since 2021Computer networks · 2 · 2 first-authorSoftware engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Provably Secure Communication Protocols for Remote AttestationabstractRemote Attestation is emerging as a promising technique to ensure that some remote device is in a trustworthy state. This can for example be an IoT device that is attested by a cloud service before allowing the device to connect. However, flaws in the communication protocols associated with the remote attestation mechanism can introduce vulnerabilities into the system design and potentially nullify the added security. Formal verification of protocol security can help to prevent such flaws. In this work we provide a detailed analysis of the necessary security properties for remote attestation focusing on the authenticity of the involved agents. We extend beyond existing work by considering the possibility of an attestation server (making the attestation process involve three parties) as well as requiring verifier authentication. We demonstrate that some security properties are not met by a state-of-the-art commercial protocol for remote attestation for our strong adversary model. Moreover, we design two new communication protocols for remote attestation that we formally prove fulfil all of the considered authentication properties. Johannes Wilson, Mikael Asplund, Niklas Johansson, Felipe Boeira |
ARES | 4 |
| 2023 | Provable Non-Frameability for 5G Lawful InterceptionabstractMobile networks have grown in size and relevance, with novel applications in areas including transportation, finance, and health. The wide use of mobile networks generates rich data about users, raising interest in using such data for law enforcement and antiterrorism through Lawful Interception (LI). Countries worldwide have established legal frameworks to conduct LI, and technical standards have been created for its implementation and deployment, but without sufficient (and rigorous) security controls. While LI originated for benign purposes, we show in this paper that malicious entities could exploit it to frame users into suspicion of criminal activity. Further, we propose a solution for non-frameability, which we formally prove uphold desired properties even in scenarios where attackers completely infiltrate the operator networks. To perform the formal verification, we extend prior work with a more complete model of the fifth generation (5G) of mobile networks in the Tamarin prover. Felipe Boeira, Mikael Asplund, Marinho P. Barcellos |
WISEC | 1 |
| 2022 | Exploiting Partial Order of Keys to Verify Security of a Vehicular Group ProtocolabstractVehicular networks will enable a range of novel applications to enhance road traffic efficiency, safety, and reduce fuel consumption. As for other cyber-physical systems, security is essential to the deployment of these applications and standardisation efforts are ongoing. In this paper, we perform a systematic security evaluation of a vehicular platooning protocol through a thorough analysis of the protocol and security standards. We tackle the complexity of the resulting model with a proof strategy based on a relation on keys. The key relation forms a partial order, which encapsulates both secrecy and authenticity dependencies. We show that our order-aware approach makes the verification feasible and proves authenticity properties along with secrecy of all keys used throughout the protocol. Felipe Boeira, Mikael Asplund |
CSF | 1 |
| 2022 | Evaluation of an SDN-based Microservice ArchitectureabstractMicroservice architectures decompose applications into individual components for enhanced maintainability and horizontal scaling, but also comes with an increased cost for orchestrating the services. Software-Defined Networks (SDNs) enables the dynamic configuration of network switches using controllers. In this paper we propose a microservice architecture that leverages SDN to orchestrate the microservices with the goal of reducing the orchestration latency cost. We perform a set of experiments using Mininet in which we implement a tailor-made microservice application that uses SDN for orchestration in combination with a set of different controllers and load balancers. Our results show that our proposed architecture performs in the same order of magnitude as a corresponding monolithic system. Anton Hölscher, Mikael Asplund, Felipe Boeira |
NetSoft | 3 |
| 2022 | No Doppelgänger: Advancing Mobile Networks Against Impersonation in Adversarial ScenariosabstractThe expansion of mobile network capabilities throughout the decades has increased people's exposure to the digital world, and the next generations of communication networks are expected to achieve ubiquitous connectivity and immersive use cases. Security and privacy concerns have arisen and are continuously taken into account in the design of mobile networks. However, a relevant limitation currently lies in the use of shared secrets for providing security and privacy to users. Ideally, we believe that users' identities should be immune to impersonation as long as their own devices remain secure, notwithstanding the network operators and other entities potentially being compromised. In this paper, we develop this idea with the objective of providing the non-repudiation property, which represents a mitigation to its dual, impersonation. Felipe Boeira, Mikael Asplund, Marinho P. Barcellos |
WISEC | 1 |
| 2019 | Decentralized proof of location in vehicular Ad Hoc networks
Felipe Boeira, Mikael Asplund, Marinho P. Barcellos |
Comput. Commun. | 1 |
| 2018 | Vouch: A Secure Proof-of-Location Scheme for VANETsabstractIn Vehicular Ad Hoc Networks (VANETs), nodes periodically share beacons in order to convey information about identity, velocity, acceleration, and position. Truthful positioning of nodes is essential for the proper behavior of applications, including the formation of vehicular platoons. Incorrect position information can cause problems such as increased fuel consumption, reduced passenger comfort, and in some cases even accidents. In this paper, we design and evaluate Vouch: a secure proof-of-location scheme tailored for VANETs. The scheme leverages the node positioning capability of fifth generation (5G) wireless network roadside units. The key idea of Vouch is to disseminate periodic proofs of location, combined with plausibility checking of movement between proofs. We show that Vouch can detect position falsification attacks in high-speed scenarios without incurring a large overhead. Felipe Boeira, Mikael Asplund, Marinho P. Barcellos |
MSWiM | 1 |
| 2016 | Data leakage detection in Tizen Web applicationsabstractThe explosive growth in Internet of Things (IoT) devices like smartphones, tablets, smart TVs, and smartwatches has brought new challenges for software developers. Currently a single app can be created and executed on multiple target platforms. In this scenario, different programming languages such as HTML5 and JavaScript, and operational systems like Tizen and webOS promises easy multi-platform development. However, one of the biggest concerns from companies that develop applications to these IoT devices is the leakage or exposure of sensitive data. In this work we are addressing this problem by creating a modified version of Tizen, called TTizen, that modifies the Tizen Web Runtime to add dynamic taint tracking, with that we can track sensitive information that is being leaked, even if the information is obfuscated, and warn the users. From our knowledge this is the first prototype that adds this kind of technique to Tizen and tracks web applications in mobile devices. The results show that TTizen is a promising approach that can be improved and used to detect data leakage in IoT devices. Thiago S. Rocha, Eduardo Souto, Brandell Cassio, Diego Azulay, Alex Monteiro, Felipe Boeira, Pedro Minatel, Breno Silva |
PST | 6 |