VLDB 2026 Research / reviewers in the wild / expert
Gianpiero Costantino
dblp:23/7643
· DBLP profile ↗
39ranked-venue papers
22as first author
7since 2021 · last 2023
0000-0002-2900-262XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 6 first-author · 2 since 2021Computer networks · 9 · 7 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 4 first-author · 1 since 2021Artificial intelligence and machine learning · 2 · 2 first-authorSystems, architecture and hardware · 2 · 1 first-authorHuman-computer interaction and ubiquitous computing · 2Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Vehicle Data Collection: A Privacy Policy Analysis and ComparisonabstractIn recent years, data can be considered the new fuel for road vehicle functionalities like driver-assistance systems or customized services. Therefore, the carmakers with their phone apps, synced with the infotainment system, can collect information from the drivers and vehicles to be processed inside or outside the car. In this context, we analyze different carmakers’ privacy policies to define their readability and compliance with the EU General Data Protection Regulation, and provide analysis of carmakers’ data collection. Besides, for the first time, we compare the most significant privacy regulations in automotive. Finally, we create an interactive dashboard to compare the different carmakers’ policies and provide users with an efficient instrument to understand some relevant privacy aspects like which data the carmakers declare to collect. We find that carmakers could collect a large number of users and vehicle data, but, in some cases, the privacy policies seem to be quite challenging to read and do not provide some information like how collected data are protected or stored. Chiara Bodei, Gianpiero Costantino, Marco De Vincenzi 0001, Ilaria Matteucci, Anna Monreale |
ICISSP | 2 |
| 2023 | Electric Vehicle Security and Privacy: A Comparative Analysis of Charging MethodsabstractIn the next decade, electric road vehicles have the potential to reduce climate change and improve mobility. However, not all charging methods are equally secure and private, so this work provides a comprehensive analysis of the security and privacy of various EV charging methods and highlights the importance of addressing vulnerabilities to meet homologation standards. Five charging methods are described in terms of physical components, communication protocols, and standards. This research identifies weaknesses in each method and determines which are less prone to cyber attacks or privacy disclosures. The impact of different charging methods on vehicle homologation is also discussed, as required by the cybersecurity regulation UNECE R155. A mapping is provided between vulnerabilities and suggested mitigations from the regulation. The evidence suggests that different charging methods result in different security and privacy levels, with conductive methods being more vulnerable to security attacks and privacy disclosure, while methods with fewer components may reduce security and privacy risks. Gianpiero Costantino, Marco De Vincenzi 0001, Fabio Martinelli, Ilaria Matteucci |
VTC2023-Spring | 1 |
| 2023 | A Privacy-Preserving Solution for Intelligent Transportation Systems: Private Driver DNAabstractThe rising connection of vehicles with the road infrastructure enables the creation of data-driven applications to offer drivers customized services. At the same time, these opportunities require innovative solutions to protect the drivers’ privacy in a complex environment like an Intelligent Transportation System (ITS). This need is even more relevant when data are used to retrieve personal behaviors or attitudes. In our work, we propose a privacy-preserving solution, called Private Driver DNA, which designs a possible architecture, allowing drivers of an ITS to receive customized services. The proposed solution is based on the concept of Driver DNA as characterization of driver’s driving style. To assure privacy, we perform the operations directly on sanitized data, using the Order Revealing Encryption (ORE) method. Besides, the proposed solution is integrated with ITS architecture defined in the European project E-Corridor. The result is an effective privacy-preserving architecture for ITS to offer customized products, which can be used to address drivers’ behaviors, for example, to environmental-friendly attitudes or a more safe driving style. We test Private Driver DNA using a synthetic dataset generated with the vehicle simulator CARLA. We compare ORE with another encryption method like Homomorphic Encryption (HE) and some other privacy-preserving schemas. Besides, we quantify privacy gain and data loss utility after the data sanitization process. Gianpiero Costantino, Marco De Vincenzi 0001, Fabio Martinelli, Ilaria Matteucci |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2022 | SECPAT: Security Patterns for Resilient Automotive E / E ArchitecturesabstractAutomated driving requires increasing networking of vehicles, which in turn broadens their attack surface. In this paper, we describe several security design patterns that target critical steps in automotive attack chains and mitigate their con-sequences. These patterns enable the detection of anomalies in the firmware when booting, detect anomalies in the communication in the vehicle, prevent unauthorized control units from successfully transmitting messages, offer a way of transmitting security-related events within a vehicle network and reporting them to units external to the vehicle, and ensure that communication in the vehicle is secure. Using the example of a future high-level Electrical / Electronic (E / E) architecture, we also describe how these security design patterns can be used to become aware of the current attack situation and how to react to it. Christian Plappert, Florian Fenzl, Roland Rieke, Ilaria Matteucci, Gianpiero Costantino, Marco De Vincenzi 0001 |
PDP | 5 |
| 2022 | CAHOOT: a Context-Aware veHicular intrusiOn detectiOn sysTemabstractSoftware in modern vehicles is becoming increasingly complex and subject to vulnerabilities that an intruder can exploit to alter the functionality of vehicles. To this purpose, we introduce CAHOOT, a novel context-aware Intrusion Detection System (IDS) capable of detecting potential intrusions in both human and autonomous driving modes. In CAHOOT, context information consists of data collected at run-time by vehicle’s sensors and engine. Such information is used to determine drivers’ habits and information related to the environment, like traffic conditions. In this paper, we create and use a dataset by using a customised version of the MetaDrive simulator capable of collecting both human and AI driving data. Then we simulate several types of intrusions while driving: denial of service, spoofing and replay attacks. As a final step, we use the generated dataset to evaluate the CAHOOT algorithm by using several machine learning methods. The results show that CAHOOT is extremely reliable in detecting intrusions. Davide Micale, Gianpiero Costantino, Ilaria Matteucci, Florian Fenzl, Roland Rieke, Giuseppe Patanè 0002 |
TrustCom | 2 |
| 2022 | Full-protocol safety analysis of CINNAMONabstractThe gap between safety and security solutions in the automotive domain is still far from being filled. Till now, the automotive industries have been mainly devoted to provide safety relevant solution. The increasing adoption of electronic solutions to regulate vehicles’ functionalities moves the attention also to cyber-security issues. In this paper, we present a full-protocol analysis of the CINNAMON intra-vehicle communication protocol, showing how it is able to satisfy both security and safety AUTOSAR requirements. In particular, we include in the analysis the synchronization messages, which were previously excluded. Luca Dariz, Gianpiero Costantino, Ilaria Matteucci |
VTC Spring | 2 |
| 2022 | Designing and implementing an AUTOSAR-based Basic Software Module for enhanced securityabstractElectronic Control Units (ECUs) communicate with each other to accomplish the functionalities of modern vehicles. ECUs form an in-vehicle network that is precisely regulated and must be adequately protected from malicious activity, which has had several outbreaks in recent years. Therefore, we present CINNAMON, an AUTOSAR-based Basic Software Module that aims at confidentiality, integrity and authentication, all at the same time, for the traffic exchanged over the bus protocols that AUTOSAR supports. CINNAMON in fact stands for Confidential, INtegral aNd Authentic onboard coMmunicatiON. This article introduces the requirements and specification of CINNAMON in a differential fashion with respect to the existing Secure Onboard Communication Basic Software Module, which does not include confidentiality. As a result, CINNAMON exceeds SecOC at least against information gathering attacks. The article then defines three security profiles, regulating also the freshness attribute appropriately. Most importantly, CINNAMON is not a simple academic exercise because it is implemented in a laboratory environment on commercial ECUs, thus reaching the level of TRL 4, “Component and/or breadboard validation in laboratory environment”. The runtimes obtained on inexpensive devices are reassuring, paving the way for a possible large-scale application. Giampaolo Bella, Pietro Biondi, Gianpiero Costantino, Ilaria Matteucci |
Comput. Networks | 3 |
| 2020 | Analysis of Functional Safety in a secure implementation of CAN ProtocolabstractIn modern vehicles, functionalities are typically managed by Electronic Control Units (ECUs). They communicate each other by using the CAN bus protocol, standardized as ISO 11898-1:2015. However, the CAN protocol was not meant to be secure: messages are sent in clear. In the last decade, several attempts to secure the CAN protocol have been implemented. Here, we focus on TOUCAN [1], [2] and we propose and study a revised version of TOUCAN protocol enhanced from a functional safety prospective and compliant with AUTOSAR safety and security guidelines. In particular, we analyse and simulate the communication robustness of the new version of TOUCAN against transmission errors. Gianpiero Costantino, Luca Dariz, Ilaria Matteucci |
INDIN | 1 |
| 2020 | A cloud-edge based data security architecture for sharing and analysing cyber threat informationabstractCyber-attacks affect every aspect of our lives. These attacks have serious consequences, not only for cyber-security, but also for safety, as the cyber and physical worlds are increasingly linked. Providing effective cyber-security requires cooperation and collaboration among all the entities involved. Increasing the amount of cyber threat information (CTI) available for analysis allows better prediction, prevention and mitigation of cyber-attacks. However, organizations are deterred from sharing their CTI over concerns that sensitive and confidential information may be revealed to others. We address this concern by providing a flexible framework that allows the confidential sharing of CTI for analysis between collaborators. We propose a five-level trust model for a cloud-edge based data sharing infrastructure. The data owner can choose an appropriate trust level and CTI data sanitization approach, ranging from plain text, through anonymization/pseudonymization to homomorphic encryption, in order to manipulate the CTI data prior to sharing it for analysis. Furthermore, this sanitization can be performed by either an edge device or by the cloud service provider, depending upon the level of trust the organization has in the latter. We describe our trust model, our cloud-edge infrastructure, and its deployment model, which are designed to satisfy the broadest range of requirements for confidential CTI data sharing. Finally we briefly describe our implementation and the testing that has been carried out so far by four pilot projects that are validating our infrastructure. David W. Chadwick, Wenjun Fan, Gianpiero Costantino, Rogério de Lemos, Francesco Di Cerbo, Ian Herwono, Mirko Manea, Paolo Mori, Ali Sajjad, Xiao-Si Wang |
Future Gener. Comput. Syst. | 3 |
| 2020 | LoSeRO: A Locality Sensitive Routing Protocol in Opportunistic Networks with Contact ProfilesabstractMobility trajectories of users contain personal information that when analyzed may reveal relevant data usable as message-sharing condition, e.g., interests in common or similar mobility patterns. In particular, leveraging on mobility patterns, in [12] we designed and presented a Geo-casting routing protocol called LoSeRO for opportunistic networks, which uses knowledge of the locations most frequently visited by a user to route messages. LoSeRO forwards messages-in a multi-casting way-to all users who have a mobility profile that intersects the packet's destination zone. LoSeRO presented a relative good performance value, however, to improve its performances, in this paper our contribution is to propose an upgraded version of our earlier proposed protocol, termed as LoSeRO v2. In particular, it upgrades the traditional working fashion of LoSeRO by extending the knowledge of the most frequented locations to those users not only directly met, i.e., two-hops away. With this purpose, through simulations, we compare the performance of LoSeRO v2, with LoSeRO and other existing routing geo-casting protocols, and we illustrate how LoSeRO v2 achieves enhanced performances comparing precision, coverage and additional metrics. Gianpiero Costantino, Rajib Ranjan Maiti, Fabio Martinelli, Paolo Santi |
IEEE Trans. Mob. Comput. | 1 |
| 2019 | Implementing CAN bus security by TOUCANabstractModern vehicles embed a lot of software that turns them into Cyper-Physical Systems (CPS). Electronic Control Units (ECUs) communicate through the CAN bus protocol, which was not designed to be secure. This paper presents a proof-of-concept of TOUCAN, a new security protocol designed to secure CAN bus communications following the AUTOSAR standard. The presentation introduces design, implementation and performance of TOUCAN on a test-bed composed by two inexpensive boards that can be demonstrated to exchange secure TOUCAN frames. Pietro Biondi, Giampaolo Bella, Gianpiero Costantino, Ilaria Matteucci |
MobiHoc | 3 |
| 2019 | Are you secure in your car?: posterabstractModern vehicles abound with Electronic Control Units (ECUs) that need to speak with each other. They adopt a binary language and form an in-vehicle network that must be precisely regulated. This was the aim for the inception of "Controller Area Network" protocol, also known as CAN bus [1] and is widespread today. It is standardised in ISO 11898-1:2015 [4] as a simple protocol based on two bus lines. However, it is not meant to be secure. Giampaolo Bella, Pietro Biondi, Gianpiero Costantino, Ilaria Matteucci |
WiSec | 3 |
| 2018 | Getmewhere: A Location-Based Privacy-Preserving Information ServiceabstractMobile users have got used to getting useful information while they are literally on the move. An implication of this habit is that certain live information, such as that for navigation, for dating and for handling emergencies, should be tailored to the user's current location. While this is technically feasible with the current technology, it raises concerns on the user's location privacy. To address the delicate tradeoff between user's location privacy and appropriateness of the information for that location, this paper discusses three information delivery protocols. One is the widely adopted Android's protocol, the other two are the authors' novel ones, termed AL protocol and LBPP protocol respectively. The former conceals the user's location within a geographical area, the latter employs secure two-party computation. Privacy of all protocols is analysed, motivating the choice to implement the LBPP protocol. It is made available as the "Getmewhere" service for the reader to download. Giampaolo Bella, Francesco Marino 0002, Gianpiero Costantino, Fabio Martinelli |
PDP | 3 |
| 2018 | CARS: Context Aware Reputation Systems to Evaluate Vehicles' BehaviourabstractThe introduction of new generation ICT systems into vehicles makes them highly connected with the external World. As drawback, vehicle becomes potentially vulnerable to security attacks. Here, we consider a scenario in which Vehicular Networks and a Urban Network work together to realize a defence mechanism based on Reputation Systems. In this way, we are able to identify and isolate possible malicious vehicles acting that could send messages with the aim of reducing the availability of the network. We propose Context Aware Reputation Systems, CARS, able to identify insider attackers and isolate them taking into account contextual conditions derived from sensors spread along the entire urban network. Then, we experimentally evaluate CARS on a real data-set of mobility traces of taxis in Rome to compare the proposed systems with existing ones that do not consider contextual conditions. The preliminary results obtained are promising and show the feasibility and potentiality of CARS. Gianpiero Costantino, Fabio Martinelli, Ilaria Matteucci, Antonia Bertolino, Antonello Calabrò, Eda Marchetti |
PDP | 1 |
| 2018 | Improving Vehicle Safety Through a Fog Collaborative InfrastructureabstractThe introduction of Information and Communication Technology in modern cities enhances quality, performance, and interactivity of urban services. The ultimate goal is twofold: the reduction of costs and of resource consumption and the increasing number of services offered to citizens. As drawback, smart cities become more vulnerable from the point of view of safety, security, and preservation of citizen privacy. In this paper, we propose a fog-computing based infrastructure to manage the sharing of information among vehicles and smart traffic lights in a urban network, with the aim of improving the safety of end-users of the network. For this purpose, our infrastructure provides to drivers several services to retrieve information in a private and secure way. The services we consider, are mainly four and are oriented to the traffic prediction, incident prevention, managing of emergency, and driver recognition. Gianpiero Costantino, Fabio Martinelli, Ilaria Matteucci, Francesco Mercaldo |
SMARTCOMP | 1 |
| 2018 | Privacy Preserving Distributed Computation of Private Attributes for Collaborative Privacy Aware Usage Control SystemsabstractCollaborative smart services provide functionalities which exploit data collected from different sources to provide benefits to a community of users. Such data, however, might be privacy sensitive and their disclosure has to be avoided. In this paper, we present a distributed multi-tier framework intended for smart-environment management, based on usage control for policy evaluation and enforcement on devices belonging to different collaborating entities. The proposed framework exploits secure multi-party computation to evaluate policy conditions without disclosing actual value of evaluated attributes, to preserve privacy. As reference example, a smart-grid use case is presented. Gianpiero Costantino, Antonio La Marra, Fabio Martinelli, Paolo Mori, Andrea Saracino |
SMARTCOMP | 1 |
| 2018 | CANDY: A Social Engineering Attack to Leak Information from Infotainment SystemabstractThe introduction of Information and Communications Technologies (ICT) systems into vehicles make them more prone to cyber-security attacks that may impact of vehicles capability and, consequently, on the safety of drivers, passengers. In this paper, we focus on how to exploit security vulnerabilities affecting user-to-vehicle and intra- vehicle communications to hack the infotainment system to retrieve information about both vehicle and driver. Indeed, we designed and developed CANDY, a set of malicious APP injecting in a genuine Android APP, acting as a Trojan-horse on the Android In-Vehicle infotainment system. It opens a back-door that allows an attacker to remotely access to the infotainment system. We use this back-door to hit the privacy of the driver by recording her voice and collect information circulating on the CAN bus about the vehicle. CANDY is distributed by using social engineering techniques. Gianpiero Costantino, Antonio La Marra, Fabio Martinelli, Ilaria Matteucci |
VTC Spring | 1 |
| 2017 | Reputation Systems to Mitigate DoS Attack in Vehicular Network
Gianpiero Costantino, Fabio Martinelli, Ilaria Matteucci |
CRITIS | 1 |
| 2017 | Analysis of Data Sharing Agreements
Gianpiero Costantino, Fabio Martinelli, Ilaria Matteucci, Marinella Petrocchi |
ICISSP | 1 |
| 2017 | Privacy-preserving text mining as a serviceabstractText mining is the process to automatically infer relevant information from semantically related text documents. This technique, which has applications from business intelligence to homeland security, terrorism and crime fight, might bring noticeable privacy issues when analyzed documents contain privacy sensitive information. In this paper, we propose a framework for privacy-preserving text analysis, which exploits Homomorphic Encryption, to analyze text documents in a privacy preserving manner. The proposed framework is designed to ensure that there is no disclosure of privacy sensitive information contained in the document to any party, including the analysis engine itself. Furthermore, we present two use cases of analysis based on bag-of-words classification, where the proposed framework manages to obtain good classification results without information disclosure. In particular the two different settings that are considered are: tweet analysis for detection of terrorist Twitter accounts, and out-box email analysis for detection of bot infected devices. Accuracy results with different classifiers, performances and a security analysis of our approach are presented and discussed. Gianpiero Costantino, Antonio La Marra, Fabio Martinelli, Andrea Saracino, Mina Alishahi |
ISCC | 1 |
| 2017 | Private mobility-cast for opportunistic networks
Gianpiero Costantino, Rajib Ranjan Maiti, Fabio Martinelli, Paolo Santi |
Comput. Networks | 1 |
| 2016 | Practical Privacy-Preserving Medical Diagnosis Using Homomorphic EncryptionabstractThe use of remote services offered by cloud providers have been popular in the last lustrum. Services allow users to store remote files, or to analyze data for several purposes, like health-care or message analysis. However, when personal data are sent to the Cloud, users may lose privacy on the data-content, and on the other side cloud providers may use those data for their own businesses. In this paper, we present our solution to analyze users health-data directly into the Cloud while preserving users privacy. Our solution makes use of homomorphic encryption to protect users data during the analysis. In particular, we developed a mobile application that offloads users data into the Cloud, and a homomorphic encryption algorithm that processes those data without leaking any information to the Cloud provider. Performed empirical tests show that our HE algorithm is able to evaluate users data in reasonable time proving the feasibility of this emerging way of private-data evaluation. Sergiu Carpov, Renaud Sirdey, Gianpiero Costantino, Fabio Martinelli |
CLOUD | 4 |
| 2016 | Towards a Usage Control Based Video Surveillance FrameworkabstractThe increasing need for physical security in critical environment has led to a widespread of video surveillance systems. Effective video surveillance systems should be able to detect the presence of unauthorized people in the monitored environments while preserving the privacy of authorized ones. To this aim, our paper proposes the adoption of the usage control model in the video surveillance scenario to enforce security policies that continuously control whether a person holds the right to stay in a give space (e.g., a room) from the moment when this person enters that space. In some scenarios, a person is allowed to stay in the room only under some circumstances, which are described by the usage control policy. When the policy is violated an action is taken, e.g., the video camera placed in the room enables the registration. This paper presents the architecture of the proposed framework, provides an example of usage control policy in a real scenario, and describes the main details of our prototype implementation. Enrico Carniani, Gianpiero Costantino, Francesco Marino 0002, Fabio Martinelli, Paolo Mori |
PDP | 2 |
| 2015 | Privacy-Preserving Energy-Reading for Smart MeterabstractSmart Meters belong to the Advanced Metering Infrastructure (AMI) and allow customers to monitor locally and remotely the current usage of energy. Providers query Smart Meters for billing purpose or to establish the amount of energy needed by houses. However, reading details sent from smart meters to the energy provider can be used to violate customers’ privacy. In this paper, our contribution is two-fold: first, we present an architecture to turn traditional energy meters into Smart Meters, and then we illustrate a privacy-preserving solution, which uses Secure Two-party Computation, to preserve customers’ privacy during energy-readings. In particular, we deployed a Smart Meter built upon an existing energy meter available in Italy. Then, we collected and analysed an energy trace of two months, and we tag customers hourly/daily/monthly habits by observing their consumes. Finally, we provide the feasibility of our solution to protect customers’ privacy. Gianpiero Costantino, Fabio Martinelli |
ICOST | 1 |
| 2015 | Location-Based Routing for Opportunistic NetworksabstractWe tackle the problem of locality-aware message spreading in a network composed of smart mobile devices, without resorting to any backbone communication infrastructure. The motivations for our work are two-fold. First, recent smart mobile devices are capable of capturing and storing location information (at a significant granularity) by using, e.g., GPS service and storage capacity available in the devices. Second, recent studies have shown that mobility is positively correlated with the building of new social relationships, which are relatively more likely to occur for people who have visited common places in the past [2], [4], [3]. These two factors together show the importance of building proximity based communication networks, and the need of messages spreading among a targeted set of users in a network. We assume that the participating users move in a large geographic area, and a location inside the area can be uniquely identified by any user, for example, using GPS coordinates. Each user independently builds her mobility profile, called Moby Zone, considering her own past mobility traces. The Moby Zone of a user is the set of her most visited places. Gianpiero Costantino, Rajib Ranjan Maiti, Fabio Martinelli, Paolo Santi |
MASS | 1 |
| 2015 | Design and Development of a Facebook Application to Raise Privacy AwarenessabstractEveryday people upload a large number of private pictures on online social networks (OSNs). Users trust OSNs to keep their pictures private, e.g. by making them available to their social friends only. Unfortunately, OSN security controls are not always strong enough and malicious people may exploit these weaknesses to potentially see any user's private pictures. It might even possible to access private photos posted on an OSN without circumventing its security policies. In fact, users sometimes add to their social circles acquaintances, recently met people, which might not be completely trusted. Furthermore, they occasionally allow third-party applications to access their pictures. These conditions imply that, to keep their photos private, users must trust all the security controls implemented by OSNs and all of their social friends (and how they interact with third-party applications). Actually, there are some situations in which these assumptions are not met and some data that users believed to be private might also be accessed by unknown people. The goal of this paper is to raise awareness on the problem of privacy of online pictures and to have OSN users think more carefully about how they use third-party applications and how they choose their friends online. To this end, we discuss a use-case of a Facebook application, which we have developed, that exploits some weaknesses and users' assumptions to gather a huge amount of private pictures. Gianpiero Costantino, Daniele Sgandurra |
PDP | 1 |
| 2015 | A quality model for social networks populated with web services
Noura Faci, Marinella Petrocchi, Gianpiero Costantino, Fabio Martinelli, Zakaria Maamar |
Serv. Oriented Comput. Appl. | 3 |
| 2014 | An Improved Role-Based Access to Android Applications with JCHRabstractIn this paper we show how deductive and abductive reasoning in distributed authorisation can be efficiently ported to Android. Such logical-inference processes prove to be important tools due to the intrinsic autonomic-nature of these mobile devices. Both deduction and abduction are represented by using Constraint Handling Rules (CHR), a high-level declarative constraint programming-language, and implemented in JCHR (CHR embedded into Java). To represent credentials we elaborate on RTW, a weighted Role-based Trust-management family of languages: CHR programs are developed after such languages. In general, having weights associated with credentials leads to a more informative reasoning, for instance, access can be granted only if the total uncertainty is less than 20%. Stefano Bistarelli, Gianpiero Costantino, Fabio Martinelli, Francesco Santini 0001 |
ARES | 2 |
| 2014 | Reputation-Based Composition of Social Web ServicesabstractSocial Web Services (SWSs) constitute a novel paradigm of service-oriented computing, where Web services, just like humans, sign up in social networks that guarantee, e.g., better service discovery for users and faster replacement in case of service failures. In past work, composition of SWSs was mainly supported by specialised social networks of competitor services and cooperating ones. In this work, we continue this line of research, by proposing a novel SWSs composition procedure driven by the SWSs reputation. Making use of a well-known formal language and associated tools, we specify the composition steps and we prove that such reputation-driven approach assures better results in terms of the overall quality of service of the compositions, with respect to randomly selecting SWSs. Alessandro Celestini, Gianpiero Costantino, Rocco De Nicola, Zakaria Maamar, Fabio Martinelli, Marinella Petrocchi, Francesco Tiezzi 0001 |
AINA | 2 |
| 2014 | Privacy-preserving mobility-casting in opportunistic networksabstractIn this paper, we introduce the notion of mobility-cast in opportunistic networks, according to which a message sent by a node S is delivered to nodes with a mobility pattern similar to that of S - collectively named place-friends. The motivation for delivering a message to place-friends stems from the fact that current social acquaintances are likely to be place-friends. Most importantly, it has been recently found that a large fraction of new social contacts comes from place-friends. Gianpiero Costantino, Fabio Martinelli, Paolo Santi |
PST | 1 |
| 2014 | Investigating the Privacy versus Forwarding Accuracy Tradeoff in OpportunisticInterest-CastingabstractMany mobile social networking applications are based on a “friend proximity detection” step, according to which two mobile users try to jointly estimate whether they have friends in common, or share similar interests, etc. Performing “friend proximity detection” in a privacy-preserving way is fundamental to achieve widespread acceptance of mobile social networking applications. However, the need of privacy preservation is often at odds with application-level performance of the mobile social networking application, since only obfuscated information about the other user's profile is available for optimizing performance. In this paper, we study for the first time the fundamental tradeoff between privacy preservation and application-level performance in mobile social networks. More specifically, we consider a mobile social networking application for opportunistic networks called interest-casting. In the interest-casting model, a user wants to deliver a piece of information to other users sharing similar interests (“friends”), possibly through multi-hop forwarding. In this paper, we propose a privacy-preserving friend proximity detection scheme based on a protocol for solving the Yao's “Millionaire's Problem”, and we introduce three interest-casting protocols achieving different tradeoffs between privacy and accuracy of the information forwarding process. The privacy versus accuracy tradeoff is analyzed both theoretically, and through simulations based on a real-world mobility trace. The results of our study demonstrate for the first time that privacy preservation is at odds with forwarding accuracy, and that the best tradeoff between these two conflicting goals should be identified based on the application-level requirements. Gianpiero Costantino, Fabio Martinelli, Paolo Santi |
IEEE Trans. Mob. Comput. | 1 |
| 2013 | How to grant less permissions to facebook applicationsabstractSingle Sign-On (SSO) is an authentication procedure that allows users to adopt the same credentials to access multiple services. On the other hand, OAuth 2.0 is a protocol that enables authorized applications to access data that are stored in a resource server. A practical example of the adoption of SSO with OAuth 2.0 is given by all the websites or applications that use the “Log in with Facebook” procedure to authenticate users already registered with Facebook. In this paper, we propose a mechanism that exploits a weakness of OAuth 2.0 and a missing control of the website to show how it is possible to register a user by reducing the number of scopes that the website requires with the “Log in with Facebook” procedure. Finally, we illustrate two examples that exploit the proposed mechanism and provide a solution to address the problem. Gianpiero Costantino, Fabio Martinelli, Daniele Sgandurra |
IAS | 1 |
| 2013 | Towards enforcing on-the-fly policies in BYOD environmentsabstractThe Bring Your Own Device (BYOD) paradigm is becoming extremely popular across all kind of organizations. In fact, employees are continually trying to incorporate their personal devices, e.g. smartphones and tablets, into the office to perform some of their work or simply to access the Internet with a device they trust or they are more familiar with. Unfortunately, several security issues may arise from all these external devices accessing the corporate network. To address these issues, in this paper we propose a framework that enforces on-the-fly instantiated policies inside organizations using trusted BYOD technologies. The proposed framework implements a role-based access control system based upon user identity and her current context. To this end, each user receives a specific policy from a server based upon the current role and context. The effective user identity is confirmed using OAuth 2.0, while the device integrity and policy enforcement is ensured by means of a on-device root-of-trust and an enforcer running on each device. Gianpiero Costantino, Fabio Martinelli, Andrea Saracino, Daniele Sgandurra |
IAS | 1 |
| 2012 | An implementation of secure two-party computation for smartphones with application to privacy-preserving interest-castabstractFor this demo, we present an implementation of the FairPlay framework for secure two-party function computation on Android smartphones, which we call MobileFairPlay. MobileFairPlay allows high-level programming of several secure two-party protocols, including protocols for the Millionaire problem, set intersection, etc. All these functions are useful in the context of mobile social networks and opportunistic networks, where parties are often requested to exchange sensitive information (list of contacts, interest profiles, etc.) to optimise network operation. Gianpiero Costantino, Fabio Martinelli, Paolo Santi, Dario Amoruso |
MobiCom | 1 |
| 2012 | An implementation of secure two-party computation for smartphones with application to privacy-preserving interest-castabstractIn this paper, we present an implementation of the FairPlay framework for secure two-party function computation on Android smartphones, which we call MobileFairPlay. Mobile-FairPlay allows high-level programming of several secure two-party protocols, including protocols for the Millionaire problem, set intersection, computation of Jaccard similarity coefficient, etc. All these functions are useful in the context of mobile social networks and opportunistic networks, where parties are often requested to exchange sensitive information (list of contacts, interest profiles, etc.) to optimize network operation. To demonstrate the feasibility of MobileFairPlay, we present an application to privacy-preserving interest-casting in opportunistic networks, implementing a recently proposed protocol. We tested running times of the implemented protocol on several Android phones, obtaining very reasonable (up to 5sec) running times. These results clearly promote MobileFairPlay as a feasible security framework for mobile environments. Gianpiero Costantino, Fabio Martinelli, Paolo Santi, Dario Amoruso |
PST | 1 |
| 2012 | Privacy-preserving interest-casting in opportunistic networksabstractMessage forwarding is a fundamental brick to spread information among users in opportunistic networks. In this paper, we consider the recently proposed interest-casting networking primitive for opportunistic networks, according to which a packet generated by a sender should be delivered to all users in the network - potentially unknown to the sender - sharing similar interests. However, the current implementation of interest-casting assume users exchange their interest profiles to take forwarding decisions, thus revealing very sensitive information to strangers. In this work, we approach for the first time the problem of designing an interest-casting protocol while not revealing sensitive information during the forwarding and message delivery process. In particular, we present a privacy-preserving mechanism based on the well-known Millionaires' problem allowing users to discover whether they have similar interests without disclosing private information. Based on this mechanism, we propose four different privacy-preserving forwarding protocols to realise interest-casting in opportunistic networks, and we compare their performance on a real-world mobility trace. Gianpiero Costantino, Fabio Martinelli, Paolo Santi |
WCNC | 1 |
| 2011 | Remote Management of Face-to-face Written Authenticated Though Anonymous Exams
Giampaolo Bella, Gianpiero Costantino, Lizzie Coles-Kemp, Salvatore Riccobene |
CSEDU (2) | 2 |
| 2010 | WATA - A System for Written Authenticated though Anonymous Exams
Giampaolo Bella, Gianpiero Costantino, Salvatore Riccobene |
CSEDU (2) | 2 |
| 2008 | Managing Reputation over MANETsabstractThe use of small portables and mobile devices has made MANETs (mobile ad hoc networks) very popular. A MANET is a network composed by a group of mobile nodes without any fixed device or a central coordination. They work in an open net and their collaboration is the sole means to allow communications and the survival of the MANET itself. A critical issue is to assess the behaviour of the nodes that participate in the network, possibly identifying selfish conduct that can compromise the functioning of the system. This paper shows a method to evaluate the behaviour of all nodes by establishing a reputation value that represents the trustworthiness of each node. A protocol is presented to calculate the reputation of a node by locally observing the node from another one, and then tuning this intermediate value with additional observations from other participants. When the reputation value of a node is available, it is circulated and distributed uniformly over the network. This reputation protocol is viable. Each node can efficiently calculate the reputation values of its neighbours and then of all network nodes. A variety of simulations conducted using the network simulator NS-2 strongly support these claims. Giampaolo Bella, Gianpiero Costantino, Salvatore Riccobene |
IAS | 2 |