VLDB 2026 Research / reviewers in the wild / expert
Ruben Rios
dblp:21/11139
· DBLP profile ↗
20ranked-venue papers
8as first author
5since 2021 · last 2026
0000-0002-6251-4897ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 5 first-author · 2 since 2021Computer networks · 4 · 1 first-author · 1 since 2021Systems, architecture and hardware · 2 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Comparative analysis of post-quantum handshake performance in QUIC and TLS protocolsabstractThe rapid advancement of quantum computing threatens the security foundations of today’s communication protocols. On the web, the traditional approach to securing web traffic has been to couple HTTP with TLS over TCP, but QUIC over UDP has recently emerged as an alternative to reduce latency and improve performance over unreliable networks. The need for an urgent transition to quantum-resistant web protocols demands further examination of both stacks. Consequently, in this work we evaluate their performance when combined with post-quantum primitives. To this end, we devise a practical evaluation framework that integrates the cryptographic primitives into TLS and QUIC implementations. Our analysis focuses on comparing the impact of hybrid and post-quantum primitives on TLS and QUIC under both ideal and realistic network conditions, providing quantitative insights into the performance cost and feasibility of transitioning toward a post-quantum web. Our results indicate that hybrid KEMs incur the highest handshake latency and bandwidth overhead, while pure post-quantum KEMs offer a favorable trade-off between security and performance, with only moderate costs. Moreover, QUIC consistently reduces the performance penalty of post-quantum primitives compared to TLS, especially in lossy network environments. José A. Montenegro, Ruben Rios, Javier Bonilla |
Comput. Networks | 2 |
| 2026 | A performance evaluation framework for post-quantum TLSabstractQuantum computers pose a significant threat to widely used cryptographic schemes, making it crucial to urgently shift to post-quantum protocols that ensure the long-term security of communications. This paper presents a framework for facilitating the transition to a quantum-resistant web by enabling the evaluation of the impact of integrating post-quantum and hybrid cryptographic primitives in the TLS protocol. By leveraging the OpenSSL library, the framework enables the seamless evaluation and comparison of key encapsulation mechanisms (KEMs) and signature schemes provided by the Open Quantum Safe project. The proposed framework is used to analyze different TLS configurations involving classic, hybrid and post-quantum primitives, with a focus on those selected by NIST. The study concentrates on evaluating the performance impact and the data overhead introduced by configurations involving primitives at different security levels. It starts by benchmarking standalone cryptographic primitives and continues with the evaluation of TLS configurations with hybrid and post-quantum KEMs under controlled network conditions, as this is the first natural step for a transition to a quantum-safe TLS. An impact analysis on real-world scenarios follows. Finally, our evaluation concentrates on providing insight into the cost of shifting to TLS configurations involving only hybrid or post-quantum primitives. José A. Montenegro, Ruben Rios, Javier Lopez-Cerezo |
Future Gener. Comput. Syst. | 2 |
| 2023 | An empirical evaluation of BLE for ITS scenariosabstractTraditional intelligent transportation systems (ITS) network layers have not yet reach a massive adoption. These protocols require costly equipment that will unlikely be embedded into commodity devices or personal mobility vehicles, such as electric scooters. However, there are low-cost communication protocols widely deployed in personal devices, such as Bluetooth Low Energy (BLE), that would allow extending the scope of ITS to all types of vehicles and pedestrians. As such, in this paper, we adapt an existing ITS stack to run over BLE in a compact-size development embedded platform and run a series of experiments. Although our results suggest that BLE is only suitable for some ITS scenarios, we discuss possible countermeasures that could help to alleviate some of the limitations found. Elena Molina, Ruben Rios, Isaac Agudo |
VTC Fall | 2 |
| 2023 | A survey on the (in)security of trusted execution environmentsabstractAs the number of security and privacy attacks continue to grow around the world, there is an ever increasing need to protect our personal devices. As a matter of fact, more and more manufactures are relying on Trusted Execution Environments (TEEs) to shield their devices. In particular, ARM TrustZone (TZ) is being widely used in numerous embedded devices, especially smartphones, and this technology is the basis for secure solutions both in industry and academia. However, as shown in this paper, TEE is not bullet-proof and it has been successfully attacked numerous times and in very different ways. To raise awareness among potential stakeholders interested in this technology, this paper provides an extensive analysis and categorization of existing vulnerabilities in TEEs and highlights the design flaws that led to them. The presented vulnerabilities, which are not only extracted from existing literature but also from publicly available exploits and databases, are accompanied by some effective countermeasures to reduce the likelihood of new attacks. The paper ends with some appealing challenges and open issues. Antonio Muñoz 0001, Ruben Rios, Rodrigo Roman, Javier López 0001 |
Comput. Secur. | 2 |
| 2022 | Constrained Proximity Attacks on Mobile TargetsabstractProximity attacks allow an adversary to uncover the location of a victim by repeatedly issuing queries with fake location data. These attacks have been mostly studied in scenarios where victims remain static and there are no constraints that limit the actions of the attacker. In such a setting, it is not difficult for the attacker to locate a particular victim and quantifying the effort for doing so is straightforward. However, it is far more realistic to consider scenarios where potential victims present a particular mobility pattern. In this article, we consider abstract (constrained and unconstrained) attacks on services that provide location information on other users in the proximity. We derive strategies for constrained and unconstrained attackers, and show that when unconstrained they can practically achieve success with theoretically optimal effort. We then propose a simple yet effective constraint that may be employed by a proximity service (for example, running in the cloud or using a suitable two-party protocol) as a countermeasure to increase the effort for the attacker several orders of magnitude both in simulated and real-world cases. Xueou Wang, Xiaolu Hou, Ruben Rios, Nils Ole Tippenhauer, Martín Ochoa |
ACM Trans. Priv. Secur. | 3 |
| 2020 | Distributed Detection of APTs: Consensus vs. Clustering
Juan E. Rubio, Cristina Alcaraz, Ruben Rios, Rodrigo Roman, Javier López 0001 |
ESORICS (1) | 3 |
| 2019 | Edge-Assisted Vehicular Networks SecurityabstractEdge computing paradigms are expected to solve some major problems affecting current application scenarios that rely on cloud computing resources to operate. These novel paradigms will bring computational resources closer to the users and by doing so they will not only reduce network latency and bandwidth utilization but will also introduce some attractive context-awareness features to these systems. In this paper we show how the enticing features introduced by edge computing paradigms can be exploited to improve security and privacy in the critical scenario of vehicular networks (VNs), especially existing authentication and revocation issues. In particular, we analyze the security challenges in VN and describe three deployment models for vehicular edge computing, which refrain from using vehicular-to-vehicular communications. The result is that the burden imposed to vehicles is considerably reduced without sacrificing the security or functional features expected in vehicular scenarios. Jose Antonio Onieva, Ruben Rios, Rodrigo Roman, Javier López 0001 |
IEEE Internet Things J. | 2 |
| 2019 | Immune System for the Internet of Things Using Edge TechnologiesabstractThe Internet of Things (IoT) and edge computing are starting to go hand in hand. By providing cloud services close to end-users, edge paradigms enhance the functionality of IoT deployments, and facilitate the creation of novel services such as augmented systems. Furthermore, the very nature of these paradigms also enables the creation of a proactive defense architecture, an immune system, which allows authorized immune cells (e.g., virtual machines) to traverse edge nodes and analyze the security and consistency of the underlying IoT infrastructure. In this paper, we analyze the requirements for the development of an immune system for the IoT, and propose a security architecture that satisfies these requirements. We also describe how such a system can be instantiated in edge computing infrastructures using existing technologies. Finally, we explore the potential application of immune systems to other scenarios and purposes. Rodrigo Roman, Ruben Rios, Jose Antonio Onieva, Javier López 0001 |
IEEE Internet Things J. | 2 |
| 2018 | Location Proximity Attacks Against Mobile Targets: Analytical Bounds and Attacker Strategies
Xueou Wang, Xiaolu Hou, Ruben Rios, Per A. Hallgren, Nils Ole Tippenhauer, Martín Ochoa |
ESORICS (2) | 3 |
| 2018 | Modelling privacy-aware trust negotiations
Ruben Rios, Carmen Fernández Gago, Javier López 0001 |
Comput. Secur. | 1 |
| 2017 | Query Privacy in Sensing-as-a-Service Platforms
Ruben Rios, David Nuñez 0001, Javier López 0001 |
SEC | 1 |
| 2017 | Evolving privacy: From sensors to the Internet of Things
Javier López 0001, Ruben Rios, Feng Bao 0001, Guilin Wang |
Future Gener. Comput. Syst. | 2 |
| 2015 | Probabilistic receiver-location privacy protection in wireless sensor networks
Ruben Rios, Jorge Cuéllar, Javier López 0001 |
Inf. Sci. | 1 |
| 2014 | Preserving Receiver-Location Privacy in Wireless Sensor Networks
Javier López 0001, Ruben Rios, Jorge Cuéllar |
ISPEC | 2 |
| 2013 | A privacy-aware continuous authentication scheme for proximity-based access control
Isaac Agudo, Ruben Rios, Javier López 0001 |
Comput. Secur. | 2 |
| 2013 | Covert communications through network configuration messages
Ruben Rios, Jose Antonio Onieva, Javier López 0001 |
Comput. Secur. | 1 |
| 2012 | Robust Probabilistic Fake Packet Injection for Receiver-Location Privacy in WSN
Ruben Rios, Jorge Cuéllar, Javier López 0001 |
ESORICS | 1 |
| 2012 | HIDE_DHCP: Covert Communications through Network Configuration Messages
Ruben Rios, Jose Antonio Onieva, Javier López 0001 |
SEC | 1 |
| 2011 | Exploiting Context-Awareness to Enhance Source-Location Privacy in Wireless Sensor NetworksabstractThe source-location privacy problem in Wireless Sensor Networks has been traditionally tackled by the creation of random routes for every packet transmitted from the source nodes to the base station. These schemes provide a considerable protection level at a high cost in terms of message delivery time and energy consumption. This overhead is due to the fact that the data routing process is done in a blind way, without knowledge about the location of the attacker. In this work, we propose the Context-Aware Location Privacy (CALP) approach, which takes advantage of the ability of sensor nodes to perceive the presence of a mobile adversary in their vicinity in order to transmit data packets in a more energy-efficient and privacy-preserving manner. In particular, we apply the concepts of CALP to the development of a shortest-path CALP routing algorithm. A permissive and a strict version of the protocol are studied for different adversarial models and the proposed schemes are evaluated through simulation experiments in terms of privacy protection and energy consumption. Finally, we present the conclusions of the paper as well as possible extensions of this work. Ruben Rios, Javier López 0001 |
Comput. J. | 1 |
| 2011 | Analysis of location privacy solutions in wireless sensor networksabstractExtensive work has been done on the protection of wireless sensor networks (WSNs) from the hardware to the application layer. However, only recently, the privacy preservation problem has drawn the attention of the research community because of its challenging nature. This problem is exacerbated in the domain of WSNs owing to the extreme resource limitation of sensor nodes. In this study the authors focus on the location privacy problem in WSNs, which allows an adversary to determine the location of nodes of interest to him. The authors provide a taxonomy of solutions based on the power of the adversary and the main techniques proposed by the various solutions. In addition, the authors describe and analyse the advantages and disadvantages of different approaches. Finally, they discuss some open challenges and future directions of research. Ruben Rios, Javier López 0001 |
IET Commun. | 1 |