Javier Jose Diaz Rivera

dblp:222/7814 · DBLP profile ↗
← Back
16ranked-venue papers
6as first author
11since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 12 · 4 first-author · 9 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Leveraging PQC and Blockchain for Secure and Verifiable SDN Controller Communication
abstract
In multi-domain Software Defined Networking (SDN) environments, inter-controller communication is essential for coordinated decision-making and consistent operation across administrative boundaries. These exchanges involve sensitive control-plane data requiring strong guarantees of authenticity and confidentiality. However, traditional cryptographic mechanisms such as RSA and ECC are increasingly vulnerable to quantum attacks, threatening the long-term security of SDN systems. Recent advances in Post-Quantum Cryptography (PQC) offer promising alternatives, with CRYSTALS-Dilithium and CRYSTALS-Kyber emerging as leading candidates for digital signatures and encryption, respectively. In parallel, permissioned blockchain technologies have gained traction as decentralized, tamper-proof ledgers for enforcing trust in SDN environments. Yet, the integration of PQC and blockchain for secure SDN communication remains largely unexplored. To address this gap, a novel system is proposed that combines PQC and blockchain to enable secure and verifiable communication between SDN controllers. Each controller uses a Dilithium-based signature keypair for authentication and a Kyber-based encryption keypair for confidentiality, with public keys stored on-chain to establish decentralized trust. SDN controller messages are encrypted using Kyber, signed with Dilithium, and recorded on the blockchain in an encrypted format. Key innovations of the design include the execution of Dilithium signature verification directly on-chain through smart contract logic, enabling decentralized and auditable validation, and a blockchain-based mechanism for securely distributing Kyber public keys, eliminating reliance on external key exchange infrastructure. The feasibility and performance of the proposed approach are evaluated, demonstrating its potential for implementation in SDN deployments facing quantum-era threats.
Javier Jose Diaz Rivera, Ricard Vilalta, Raul Muñoz 0001, Pol Alemany, Lluis Gifre
NetSoft1
2023 Blockchain and Intent-Based Networking: A Novel Approach to Secure and Accurate Network Policy Implementation
Javier Jose Diaz Rivera, Muhammad Afaq, Wang-Cheol Song
APNOMS1
2023 An Intent-Based Networking mechanism: A study case for efficient path selection using Graph Neural Networks
abstract
The recent advancements in network systems, including Software-Defined Networking (SDN), Network Functions Virtualization (NFV), and cloud networking, have revolutionized network management by increasing efficiency and reducing manual effort. This has led to improved agility in deploying new network services, enabling scaling of network resources, making it easier to handle sudden increases in demand, and efficiently accessing new solutions. However, the heterogeneous network infrastructure and the physical links’ capability still impact the performance of interconnected nodes. This work provides a solution to this problem which centers on the use of Intent-Based Networking (IBN) for a high-level definition of service requirements (QoS) tailored to the specifications of each particular node. Additionally, Graph Neural Network (GNN) is integrated into the proposed system to model the overlay topology and understand the behavior of nodes and links. This allows the defined intents to be translated into optimal paths between end-to-end nodes. The network QoS is constantly monitored, and the GNN model regularly updates the path selection to meet the QoS specified by intents. The solution has been implemented as an IBN system design consisting of a manager for intent definition, a GNN model for optimal path selection, an Off-Platform Application (OPA) for policy creation, and a real-time monitoring system for network state assurance.
Javier Jose Diaz Rivera, Mir Muhammad Suleman Sarwar, Sajid Alam, Muhammad Afaq, Wang-Cheol Song
NOMS1
2022 Software Defined Perimeter Monitoring and Blockchain-Based Verification of Policy Mapping
abstract
With the emergence of Zero Trust (ZT) Architecture, industry leaders have been drawn to the technology because of its potential to handle a high level of security threats. The Zero Trust Architecture (ZTA) is paving the path for a security industrial revolution by eliminating location-based implicant access and focusing on asset, user, and resource security. Software Defined Perimeter (SDP) is a secure overlay network technology that can be used to implement a Zero Trust framework. SDP is a next-generation network technology that allows network architecture to be hidden from the outside world. It also hides the overlay communication from the underlay network by employing encrypted communications. With encrypted information, detecting abnormal behavior of entities on an overlay network becomes exceedingly difficult. Therefore, an automated system is required. We proposed a method in this paper for understanding the normal behavior of deployed polices by mapping network usage behavior to the policy. An Apache Spark collects and processes the streaming overlay monitoring data generated by the built-in fabric API in order to do this mapping. It sends extracted metrics to Prometheus for storage, and then uses the data for machine learning training and prediction. The cluster-id of the link that it belongs to is predicted by the model, and the cluster-ids are mapped onto the policies. To validate the legitimacy of policy, the labeled polices hash is compared to the actual polices hash that is obtained from blockchain. Unverified policies are notified to the SDP controller for additional action, such as defining new policy behavior or marking uncertain policies.
Waleed Akbar, Javier Jose Diaz Rivera, Muhammad Afaq, Wang-Cheol Song
APNOMS2
2022 Secure enrollment token delivery for Zero Trust networks using blockchain
abstract
Zero Trust Networking (ZTN) is a security model where no entity in a network infrastructure is trusted. The first bastion of security for achieving ZTN is to have strong identity verification. Several standard methods for assuring a robust identity exist (E.g., OAuth2.0, OpenID Connect). These standards employ the use of JSON Web Tokens (JWT) during the authentication process. However, the use of JWT for One Time Token (OTT) enrollment has a latent security issue. A JWT can be intercepted by a third party and the information of the payload can be exposed, revealing the details of the enrollment server. Furthermore, an intercepted JWT could be used for enrollment by an impersonator as long as the JWT remains active. Our proposed mechanism aims to secure the ownership of the OTT by including the JWT as encrypted metadata into a Non-Fungible Token (NFT). The mechanism uses the blockchain Public Key of the intended owner for encrypting the JWT, and the blockchain assures the JWT ownership by mapping it to the intended owner's blockchain public address. Our proposed mechanism is applied to an emerging Zero Trust framework (OpenZiti) alongside a permissioned Ethereum blockchain using Hyperledger Besu. The Zero Trust Framework provides the enrollment functionality, while our proposed mechanism based on blockchain and NFT assures the secure distribution of OTTs that is used for the enrollment of identities.
Javier Jose Diaz Rivera, Waleed Akbar, Muhammad Afaq, Wang-Cheol Song
APNOMS1
2022 GENEVE@TEIN: A Sophisticated Tunneling Technique for Communication between OpenStack-based Multiple Clouds at TEIN
abstract
Multiple clouds need to share resources as a service for various reasons, such as overcoming single points of failure or reducing latency. Tunneling serves as the mechanism for multiple clouds to share their resources. Generic Network Virtualization Encapsulation (GENEVE) tunnel has the advantage of a flexible header over other L2 tunnels such as GRE or VXLAN. This enables the GENEVE tunnel to transfer a larger payload in case of smaller header size. The service must be acquired from an optimal Cloud and Instance. An optimal Cloud has the best network performance forecasted. An optimal Instance is forecasted not to be overutilized during resource sharing. For this purpose, monitoring tools must be deployed for metering Instances and network links. Data obtained from monitoring tools can be utilized by Machine Learning for Instances and network performance forecasting. Initially, two clouds are deployed at Trans-Eurasia Internetworking (TEIN), one in Malaysia and the other in South Korea. Monitoring tools are deployed for network and Instance performance monitoring. GENEVE tunnel is then deployed on OVS bridges, after which Instances of a cloud can access Instances of the other Cloud for resource sharing.
Mir Muhammad Suleman Sarwar, Javier Jose Diaz Rivera, Muhammad Afaq, Wang-Cheol Song
APNOMS2
2022 Automation of network anomaly detection and mitigation with the use of IBN: A deployment case on KOREN
abstract
Network ecosystems have grown to encompass multiple application domains. SDN and NFV technologies have helped pave the road for the evolution of the core and edge networking systems, allowing for numerous services to be served by the same physical infrastructure. Guaranteeing the operability of the network has become an ever-increasing requirement in order to sustain the underlying services deployed on the network. For this, Intent-Based Networking (IBN) aims to abstract network management by introducing high-level rules/policies that are translated to network configurations per service requirements. By following this principle, we proposed an anomaly detection and mitigation mechanism that exploits the characteristics of IBN for collecting and analyzing flows, using Machine Learning for interpreting traffic patterns, and automatic deployment of high-level policies for corrective actions related to anomalous traffic occurrences. The complete system is deployed on the Korea Advanced Research Network (KOREN), where the abstraction provided by IBN for network anomaly detection and mitigation is a key factor in closing the gap to achieve complete network automation.
Javier Jose Diaz Rivera, Waleed Akbar, Muhammad Afaq, Asif Mehmood, Wang-Cheol Song
WoWMoM1
2021 Network Data Analytics Function for IBN-based Network Slice Lifecycle Management
abstract
Networks slicing in 5G network enables the network operators to accommodate the different quality of service (QoS) to their customers. Moreover, the data analytics in 5G mobile network can be seen as a robust solution to transform the challenging features of 5G into a reality. So, for that, the Third Generation Partnership Project (3GPP) has been introduced a network data analytics function (NWDAF) in 5G service-based architecture (SBA). NWDAF collects the data from different core and management domains and performs analytics on that historical data. It also enables the network operators (NOs) to train their Machine Learning (ML) techniques and use various third-party solutions. On the other side, the automation and management of the end - to-end (e2e) network slicing in a multi -domain environment is a critical task. Therefore, in this manuscript, we have designed a closed-loop Intent-based Networking (IBN) platform, which automatically ensures the commissioning, activation, run-time monitoring, and decommissioning of the network slices. Moreover, we have integrated the newly introduced 3GPP NWDAF with the IBN platform for efficient e2e network slice lifecycle management. By implementing different ML models in the NWDAF function, we can predict the slice load, user mobility, traffic forecasts, and anomaly detection from the network slices.
Khizar Abbas, Muhammad Afaq, Javier Jose Diaz Rivera, Wang-Cheol Song
APNOMS4
2021 Machine Learning-based Cache Optimization on MEC Platform
abstract
The amount of data generation is exponentially increasing over the past decade due to the widespread use of multimedia applications and social media platforms. Advanced real-time applications such as virtual reality, augmented reality, automated vehicles, smart homes, and intelligent traffic control systems have increased the demand for low latency. Many of these applications are delay-sensitive and put enormous stress on the core network to respond in real-time. CDN (Content Delivery Network) brings storage service to end-users proximity to provide low latency, high data throughput, and low traffic pressure to handle the problems mentioned above. Due to the limited storage capacity of the edge, only in-demand content should cache. Therefore, to optimally utilized the cache space, an efficient content caching and replacement policy is needed. To this end, in this paper, we propose an optimal content replacement algorithm. In this algorithm, a video request pattern is first generated based on a publicly available dataset. After that, a machine learning model is trained on cache logs data. As a result, the predicted video is deleted from the edge to make space for new videos. A real-time testbed is built on KOREN to check the performance of our model. The results based on MAE, MSE, and R-2 show that our model performs well in real-time scenarios.
Waleed Akbar, Muhammad Afaq, Javier Jose Diaz Rivera, Wang-Cheol Song
APNOMS3
2021 Applying RouteNet and LSTM to Achieve Network Automation: An Intent-based Networking Approach
abstract
The expansion of infrastructure and services in the 5th generation networks resulted in complex configuration management throughout the network lifecycle. To this end, network automation replaces existing traditional manual administrative approaches with software-driven repetitive and reliable applications. Since network expansion is in multiple dimensions, including multi-services, domains, and platforms, it is challenging to resolve such a vast infrastructure through a single automation solution. Hence this paper proposed applying an intent-based solution for achieving automatic orchestration for vastly spreading network services. Intent-based solution not only considers network automation but also performs service assurance throughout the network service lifecycle. The proposed IBN (Intent-Based Networking) solution implements a closed-loop network lifecycle management using a single abstracted software platform. It translates high-level requirements to the infrastructure irrespective of the various underlying platforms and domains, and it includes intelligence-driven monitoring and updates for service assurance. A multi-model machine learning approach is proposed in this work to control the network infrastructure reliably. To this end LSTM (Long Short-Term Memory) algorithm is applied for compute-resource prediction and the Route-Net model for optimized service path routing. The infrastructure includes FlexRAN deployed as the access network controller, OSM (OpenSource MANO) resides at the core, and the KOREN network serves as a high-speed transport network.
Khizar Abbas, Javier Jose Diaz Rivera, Muhammad Afaq, Wang-Cheol Song
APNOMS3
2021 A Road-aware Approach for Hierarchical Routing in IoV based on Intents and Q-values
abstract
Nowadays, intelligence is paving its ways into the IoV domain. With the need of improvement in intelligence in this area, the need of self-organizing network management systems for providing V2X communication is also of vital importance, which current systems lack. Current routing solutions for IoV are complex and require intelligence embedded in the form of closed-loop systems. To this, an intent-based system is designed, which takes high level requirements for routing in IoV.The routing approach is road-aware and widens the scope of road-awareness to vehicles from multiple edge domains. Another problem with the current routing schemes in IoV is that their network management systems are not self-organizing. A self-organizing management system is of high importance and requires a closed-loop system. To this, an intent-based approach is followed integrated with a reinforcement learning model that supports the creation of a routing policy, which is further applied to the orchestrator and enables a road-aware and hierarchical routing approach. The proposed system is shown to be efficient in terms of data rate and the number of packet flows managed per unit time, in the management of vehicular networks.
Asif Mehmood, Javier Jose Diaz Rivera, Muhammad Afaq, Wang-Cheol Song
APNOMS3
2020 Intent-Based Orchestration of Network Slices and Resource Assurance using Machine Learning
abstract
5G networks are aimed at provisioning of a wide range of sophisticated services with uninterrupted user experience. In addition, it is very challenging to manage all the services due the variety in the service requirement and a very large number of users causing dynamic changes in traffic streamed over the network. Currently, the networks are managed manually and requires experts to control the behavior of network. Due to increase in network domain it is an esteem requirement to manage and control network autonomously. In this paper we have introduced and Intent-Based networking approach which on one side abstracts and automates the network configuration also it assures the network resource state stability by using machine learning. We have used an IBN abstraction layer and M-CORD as an next generation testbed for the implementation of this work.
Asif Mehmood, Javier Jose Diaz Rivera, Muhammad Afaq, Khizar Abbas, Wang-Cheol Song
NOMS3
2019 Machine Learning Approach for Automatic Configuration and Management of 5G Platforms
abstract
The automatic control over the network platforms is an esteem requirement of the operators. Recently, 5G with its aim to attain the internet of everything, it challenged researchers for the achievement of automatic control over the network platform. Furthermore, the 5G system consists of multi-domain network applications and platforms which make it complex to control and configure the network. Hence, the focus of this research is to enable easy configuration through high-level instructions and the use of machine learning for automatic control over the network infrastructure. The overall system consists of Intent-Base application that includes a machine learning model and it configures and controls the M-CORD-based network slicing test-bed.
Asif Mehmood, Javier Jose Diaz Rivera, Wang-Cheol Song
APNOMS3
2019 Dynamic Auto-scaling of VNFs based on Task Execution Patterns
abstract
Investigation and collection of real-time data plays a very crucial part in the orchestration of network resources. Selection of the correct data is very important as it decides to auto-scale the resources. In cloud & SDN environments such as NFV, auto-scaling becomes more critical in terms of precision and accuracy. In our case, we propose a solution for auto-scaling the network resources based on the calculations made for every action's execution-time [1] of respective instances of a VNF. The instances for each VNF are auto-scaled on the basis of execution-times per time slot, and the number of cores that are assigned by the usage of weight factor [2] used for virtual/physical cores. Hence by using the proposed solution, we are able to enhance the proper resource provisioning to fulfill the dynamic demands [3] of future mobile networks.
Asif Mehmood, Javier Jose Diaz Rivera, Wang-Cheol Song
APNOMS3
2019 Network Slice Selection Function for Data Plane Slicing in a Mobile Network
abstract
Network Function Virtualization (VNF) is one of the main drivers for the next generation of mobile networks. It allows the creation of multiple and diverse functionalities over a single physical infrastructure thus fulfilling the main requirements for 5G mobile networks that focus on serving heterogeneous ecosystems. The research presented in this literature focuses on a Network Slice Selection Function (NSSF) for the selection of Data Plane network slices, which are created and configured with specific QoS that cater to the need of network users. As the complexity of managing multiple Virtual Network Functions (VNF) grows with the number of Data Plane Network Slices, a system that abstracts the configuration of the mobile network is needed. This paper positions the NSSF as part of a three-layer Virtual Mobile Network System that contains an Application Layer for Policy creation, a Management Layer for Orchestration of VNFs and a Physical Layer for the deployment of network functions.
Javier Jose Diaz Rivera, Asif Mehmood, Wang-Cheol Song
APNOMS1
2018 Introducing network slice management inside M-CORD-based-5G framework
abstract
Network slicing has been considered as one of the fundamental technologies in the fifth generation (5G) mobile networks. Slicing mechanism enables virtual networks while providing customized services on demand. There are several papers attempting to narrow down the architectural requirement for 5G networks. Many of them consider the aspect of slice creation as a central point, sometimes strengthening slices with slice isolation. The aim of this paper is to focus more on network slice management, slicing of transport network (TN) and challenges to elaborate technological options and enablers, irrespective of the slicing mechanism. Our proposed framework creates, manages and associates the slice to user equipment (UE) upon the request made by different applications. Proposed framework exploits the key features offered by CORD including OpenStack and ONOS as well as modules based on M-CORD such as vBBU, NSSF and vEPC for establishing a network slice scenario.
Muhammad Tahir Abbas, Javier Jose Diaz Rivera, Wang-Cheol Song
NOMS4