VLDB 2026 Research / reviewers in the wild / expert
Vincenzo De Angelis
dblp:246/5602
· DBLP profile ↗
28ranked-venue papers
1as first author
25since 2021 · last 2026
0000-0001-9731-3641ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 8 since 2021Computer networks · 7 · 7 since 2021Human-computer interaction and ubiquitous computing · 4 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CallTrust: A federated system for call authentication in telephony networks
Francesco Buccafurri, Vincenzo De Angelis, Sara Lazzaro, Carmen Licciardi |
J. Inf. Secur. Appl. | 2 |
| 2025 | MQTT-E: E2E encryption in MQTT via proxy re-encryption avoiding broker overloadingabstractA smart traffic monitoring system in smart city surveillance requires publisher and subscriber MQTT-enabled vehicles to share sensitive vehicle and route data with semi-trusted RSU nodes as brokers. To ensure end-to-end confidentiality, we propose the use of an RSU broker as a proxy to perform re-encryption of the exchanged messages between publisher and subscriber vehicles. The RSU brokers are implemented as serverless edge devices with the proxy re-encryption functions designed as function-as-a-service. In peak traffic scenarios, the RSU proxy brokers can become overloaded and drop the re-encryption operations. Additionally, a malicious actor can send counterfeit re-encryption requests to overload the brokers leading to Denial-of-Service attacks. In this paper, we propose a novel solution to mitigate DoS attacks by balancing the re-encryption functions from overloaded brokers. This problem is modeled as an online optimization problem , solved using a greedy heuristic approach, and compared with a baseline approach. The objective function is to reallocate the minimum number of clients when brokers are overloaded since this operation brings additional overhead for clients. Our experimental analysis shows that the greedy approach manages to move up to 5 times fewer clients than the baseline approach, depending on the scenario considered. Francesco Buccafurri, Vincenzo De Angelis, Sara Lazzaro, Anusha Vangala |
Ad Hoc Networks | 2 |
| 2025 | Extending Tor to achieve recipient anonymityabstractAbstract Tor is a well-known routing protocol implementing the Onion multi-layered encryption to achieve communication anonymity. Among other possible attacks, Tor is vulnerable to passive attacks based on the compromise of multiple nodes, allowing the adversary to observe the traffic flow and then identify the relationship between sender and recipient. Relationship anonymity, in every threat model, can be reached by achieving at least one between sender and recipient anonymity. Tor implements the onion-service mechanism to offer recipient anonymity. However, it does not protect against a global adversary, that monitors the traffic exchanged in the network. The idea of this paper is to achieve such protection by relying on the collaboration of k Tor relays to hide the actual recipient within an anonymity set of relays. Our approach also includes the exchange of cover traffic among the collaborating Tor relays. We implement this approach by first proposing a modification to Tor (called L-Tor) that preserves the linear circuits as in standard Tor. Then, we propose B-Tor, extending Tor via tree-like circuits. Our analysis shows that using linear circuits (as in L-Tor) would not lead to advantageous results due to the resulting high latency. Instead, we show that B-Tor achieves protection against global adversaries while preserving low-latency applications. Francesco Buccafurri, Vincenzo De Angelis, Sara Lazzaro |
Cybersecur. | 2 |
| 2025 | Hiding identities of MQTT devices against a global network adversaryabstractIn the IoT context, there is an increasing demand for privacy. Indeed, IoT devices can collect and transmit sensitive data that can reveal users’ behavior and preferences to third parties. Making the identity of devices anonymous is one of the privacy challenges. In this paper, we address this problem by referring to the MQTT protocol. MQTT is a widely adopted publish-subscribe model tailored for low-end devices. In particular, we propose an approach to achieve anonymity guarantees in MQTT against a global network adversary. Our approach takes inspiration from mixnet-based anonymous protocols, but it is appropriately tailored for MQTT clients. Indeed, our solution has the following features: (1) it is lightweight for MQTT clients, (2) it satisfies the decoupling principles, and (3) it guarantees that subscribers can join and leave the system at any time. By analyzing the security of the proposed approach, we demonstrate that the considered adversary, via known attacks, is unable to reduce its uncertainty in identifying the originator (publisher) or the recipient (subscriber) of a message. We conducted an experimental campaign showing that the strong benefits of anonymity provided by our solution come at the cost of latency with respect to state of the art which offers lower anonymity guarantees. However, this price is acceptable for the amount of bytes typically sent by IoT devices. Sara Lazzaro, Vincenzo De Angelis, Francesco Buccafurri |
EURASIP J. Inf. Secur. | 2 |
| 2025 | A black-box assessment of authentication and reliability in consumer IoT devices
Sara Lazzaro, Vincenzo De Angelis, Anna Maria Mandalari, Francesco Buccafurri |
Pervasive Mob. Comput. | 2 |
| 2024 | Is Your Kettle Smarter Than a Hacker? A Scalable Tool for Assessing Replay Attack Vulnerabilities on Consumer IoT DevicesabstractConsumer Internet of Things (IoT) devices often leverage the local network to communicate with the corresponding companion app or other devices. This has benefits in terms of efficiency since it offloads the cloud. ENISA and NIST security guidelines underscore the importance of enabling default local communication for safety and reliability. Indeed, an IoT device should continue to function in case the cloud connection is not available. While the security of cloud-device connections is typically strengthened through the usage of standard protocols, local connectivity security is frequently overlooked. Neglecting the security of local communication opens doors to various threats, including replay attacks. In this paper, we investigate this class of attacks by designing a systematic methodology for automatically testing IoT devices vulnerability to replay attacks. Specifically, we propose a tool, named REPLIoT, able to test whether a replay attack is successful or not, without prior knowledge of the target devices. We perform thousands of automated experiments using popular commercial devices spanning various vendors and categories. Notably, our study reveals that among these devices, 51% of them do not support local connectivity, thus they are not compliant with the reliability and safety requirements of the ENISA/NIST guidelines. We find that 75% of the remaining devices are vulnerable to replay attacks with REPLIoT having a detection accuracy of 0.98-1. Finally, we investigate the possible causes of this vulnerability, discussing possible mitigation strategies. Sara Lazzaro, Vincenzo De Angelis, Anna Maria Mandalari, Francesco Buccafurri |
PerCom | 2 |
| 2024 | K-Anonymous Payments in Pseudonymous BlockchainsabstractLinkability of transactions is a serious threat to cryptocurrency payment anonymity. In fact, in pseudonymous blockchains, payments are not considered to be effectively anonymous. Blockchains such as Monero or Zcash aim to prevent transaction linkability by using complex cryptographic mechanisms. Therefore, they are considered anonymous blockchains. However, the recent literature has proven that, in a threat model in which the adversary is able to monitor network traffic, transaction linkability can be achieved even in anonymous blockchains. In this paper, we propose a solution that allows k-anonymous payments also in the above threat model, thus overcoming the privacy problem that plagues blockchains. The solution is inspired by overlay-routing approaches used in the context of anonymous communication networks when the global network adversary is allowed. Francesco Buccafurri, Vincenzo De Angelis, Sara Lazzaro |
WiMob | 2 |
| 2024 | How can the holder trust the verifier? A CP-ABPRE-based solution to control the access to claims in a Self-Sovereign-Identity scenarioabstractThe interest in Self-Sovereign Identity (SSI) in research, industry, and governments is rapidly increasing. SSI is a paradigm where users hold their identity and credentials issued by authorized entities. SSI is revolutionizing the concept of digital identity enabling the definition of a trust framework wherein a service provider (verifier) validates the claims presented by a user (holder) for accessing services. However, current SSI solutions primarily focus on the presentation and verification of claims, overlooking a dual aspect: ensuring that the verifier is authorized to access the holder's claims. Addressing this gap, this paper introduces an innovative SSI-based solution that integrates decentralized wallets with Ciphertext-Policy Attribute-Based Proxy Re-Encryption (CP-ABPRE). This combination effectively addresses the challenge of verifier authorization. Our solution, implemented on the Ethereum platform, enhances accountability by notarizing key operations through a smart contract. The paper also offers a prototype demonstrating the practicality of the proposed approach. Furthermore, it provides an extensive evaluation of the solution's performance, emphasizing its feasibility and efficiency in real-world applications. Francesco Buccafurri, Vincenzo De Angelis, Roberto Nardone |
Blockchain Res. Appl. | 2 |
| 2024 | A hierarchical distributed trusted location service achieving location k-anonymity against the global observerabstractAs widely known in the literature, location-based services can seriously threaten users’ privacy. Privacy-aware location-based services can be obtained by protecting the user’s identity, so that queries cannot be linked with users. A way to do this is to place a trusted third party, called Location Trusted Service, between the user and the service provider, with the role of mediating the queries coming from the users and proxying them to the provider. Before proxying the query, the Location Trusted Service builds a cloaking area that includes a sufficient number of users such that it can represent an anonymity set. This way, the identity of the user is protected against an untrusted service provider. Unfortunately, in wide-area scenarios, a centralized location-trusted service might represent a serious threat to security and privacy because the service represents a single point of failure that manages very critical and massive information. Moreover, privacy protection also against a global adversary capable to monitor the whole traffic, would result in an excessive amount of cover traffic in the network (being cover traffic necessary in this threat model). To overcome the above limitations we propose a hierarchical Location Trusted Service, whose implementation benefits from the edge–cloud paradigm. In our proposal, the territory is organized in hierarchical zones possibly managed by different autonomous organizations. Organizations that manage higher zones are involved when lower-level organizations are not able to satisfy the requests of the users. As only the lowest-level services manage exact location data, while the higher ones operate only on aggregate values, the risk associated with the single point of failure of the centralized solution is drastically reduced. Moreover, leveraging the edge–cloud implementation of the system, network traffic is better confined to the edge of the network, making the protection against the global observer feasible. A nice feature of our method is that it is parametric with respect to any existing cloaking area construction technique. However, as our method, for non-local queries, operates on aggregate data, a certain degree of approximation is introduced. To validate our proposal, we conducted an experimental campaign on a real-life map by applying our method on top of well-known cloaking area construction technique called Casper. The results turned out to be positive. For a wide range of sizes of the anonymity set, the approximation (expressed by the metric called effectiveness) is less than 10%. On the other hand, concerning the network performance, we have observed an improvement in latency and throughput ranging from 20% to 170% (depending on the size of the anonymity set). In the highest density distribution, we achieve a 66% saving in overall (non-local) traffic compared to the centralized approach. Francesco Buccafurri, Vincenzo De Angelis, Maria Francesca Idone, Cecilia Labrini |
Comput. Networks | 2 |
| 2024 | Enforcing security policies on interacting authentication systemsabstractSecurity policies of authentication systems are a crucial factor in mitigating the risk of impersonation, which is often the first stage of advanced persistent threats. Online authentication systems may often interact with each other, due to various mechanisms, such as account recovery or federated authentication. This leads to an implicit extension of the security policies of an authentication system with policies over which the system has no control. As a result, an authentication system that adopts very strong security policies can be unexpectedly weak. This paper deals with the above problem, which affects most real-world online authentication systems. The paper proposes a theoretical framework that formalizes authentication policies and interactions among authentication systems, together with a protocol that prevents, whenever an interaction is established or updated, the security issues described above. An SSI-based implementation of the proposed protocol is presented as well. • Online authentication systems may interact with each other (e.g., for account recovery, federated authentication, etc.). • Interaction between authentication systems may be adopted to bypass strong security policies of authentication systems. • Our work proposes a framework that formalizes authentication policies and interactions among authentication systems. • We provide an SSI-based protocol for the establishment and the update of the interactions between authentication systems. Francesco Buccafurri, Vincenzo De Angelis, Sara Lazzaro, Andrea Pugliese 0001 |
Comput. Secur. | 2 |
| 2024 | MQTT-I: Achieving End-to-End Data Flow Integrity in MQTTabstractMQTT has become the de facto standard in the IoT. Although standard MQTT lacks built-in security features, several proposals have been made to address this gap. Unfortunately, no existing proposal aims to offer end-to-end data flow integrity in the threat model of untrusted broker. Consider that, the broker has a privileged role, since it is in the middle of communication between publishers and subscribers. Our paper attempts to bridge this gap by introducing a new protocol called MQTT-I, which achieves end-to-end data flow integrity. Our solution is inspired by approaches based on Merkle Hash Trees, commonly used in the context of outsourced data to guarantee data integrity. Our solution aligns with the specific nature of MQTT, in which: (1) publishers and subscribers dynamically join and leave the system, (2) the decoupling principle holds, meaning that publishers and subscribers do not establish any form of agreement, and (3) data, whose integrity should be protected, are multi-topic streams. Moreover, the proposed solution allows us to find the right balance between performance and security. We perform both theoretical and experimental analysis to demonstrate that the introduced security features come with an acceptable overhead in terms of computational and energy cost. Francesco Buccafurri, Vincenzo De Angelis, Sara Lazzaro |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | COPSEC: Compliance-Oriented IoT Security and Privacy Evaluation FrameworkabstractA rising number of Internet of Things (IoT) security and privacy threats have been documented over the last few years. However, IoT devices' domain designs are out-of-date and do not take into consideration the changing dangers associated with them. In this paper, we present COPSEC, a novel framework for evaluating whether IoT devices are compliant with security guidelines and privacy regulations. We extract metrics from existing guidelines and regulations and test them on a set of devices by performing hundreds of automated experiments. Our results indicate not only that these devices are not compliant with basic security guidelines, but also that their data collection operations may introduce privacy risks for the users that adopt them. Gianluca Anselmi, Anna Maria Mandalari, Sara Lazzaro, Vincenzo De Angelis |
MobiCom | 4 |
| 2023 | Adapting P2P Mixnets to Provide Anonymity for Uplink-Intensive Applications
Francesco Buccafurri, Vincenzo De Angelis, Sara Lazzaro |
SECRYPT | 2 |
| 2023 | MQTT-A: A Broker-Bridging P2P Architecture to Achieve Anonymity in MQTTabstractThe demand for privacy in the current digital era is continuously growing. This is particularly true in the context of IoT, in which huge amounts of data are handled. Communication anonymity is a fundamental requirement when high privacy levels should be guaranteed. On the other hand, very little attention has been devoted to this problem in the past scientific literature, when referring to MQTT, which is the de-facto standard for IoT communication. In this paper, we try to cover this gap. Specifically, we propose a new protocol, called MQTT-A, which extends the MQTT bridging mechanism to support the anonymity of both publishers and subscribers. This task is accomplished through the P2P collaboration of intermediate bridge brokers, which forward the requests of clients so that the final broker cannot understand the actual source/destination. Moreover, an anonymity-preserving topic discovery mechanism is provided, which allows clients to discover available topics and associated brokers, preventing client identification. Importantly, all the MQTT-A messages are exchanged by leveraging standard MQTT primitives and the bridging mechanism natively offered by MQTT. This allows us not to require changes in the standard MQTT infrastructure. To validate the performance of our solution, we performed a deep experimental campaign by deploying the bridge brokers on cloud platforms in various countries of the world. The experimental validation shows that, the price of latency we have to pay because of the trade-off with anonymity is quite reasonable. Moreover, no significant impact on goodput occurs in the case of good network conditions. Francesco Buccafurri, Vincenzo De Angelis, Sara Lazzaro |
IEEE Internet Things J. | 2 |
| 2023 | Enabling anonymized open-data linkage by authorized partiesabstractNowadays, many entities collect useful information about users, in order to implement the provided service, and publish them as open data. To prevent privacy leakage, data are often anonymized prior to publication. Unfortunately, anonymization strongly hinders data linkage, which can be very useful for analysis purposes instead. In this paper, we deal with the above problem, by proposing a technique that enriches anonymized open data with pseudo-random labels. This way, some authorized parties (i.e., the analysts) are enabled to link data regarding the same user coming from different sources. Instead, for non-authorized people, labels do not carry any information, thus not introducing additional privacy threats with respect to original open data. In other words, our solution allows us to recover linkage capabilities on anonymized open data, thus enabling more powerful data exploitation. Indeed, the linked open data paradigm, involving both the public sector and business, is recognized as one of the most promising approaches for boosting societal growth. To offer a concrete solution, we refer to an existing open-data standard and we implement the protocol through a SAML-based SSO framework adhering to the eIDAS regulation. Francesco Buccafurri, Vincenzo De Angelis, Sara Lazzaro |
J. Inf. Secur. Appl. | 2 |
| 2022 | The Ginger: Another Spice to Hinder Attacks on Password Files
Francesco Buccafurri, Vincenzo De Angelis, Sara Lazzaro |
WEBIST | 2 |
| 2022 | An integrity-preserving technique for range queries over data streams in two-tier sensor networks
Francesco Buccafurri, Vincenzo De Angelis, Gianluca Lax |
Comput. Networks | 2 |
| 2022 | A centralized contact-tracing protocol for the COVID-19 pandemic
Francesco Buccafurri, Vincenzo De Angelis, Cecilia Labrini |
Inf. Sci. | 2 |
| 2021 | Extending Routes in Tor to Achieve Recipient Anonymity against the Global AdversaryabstractTor is a famous routing overlay network based on the Onion multi-layered encryption to support communication anonymity in a threat model in which some network nodes are malicious. However, Tor does not provide any protection against the global passive adversary. In this threat model, an idea to obtain recipient anonymity, which is enough to have relationship anonymity, is to hide the recipient among a sufficiently large anonymity set. However, this would lead to high latency both in the set-up phase (which has a quadratic cost in the number of involved nodes) and in the successive communication. In this paper, we propose a way to arrange a Tor circuit with a tree-like topology, in which the anonymity set consists of all its nodes, whereas set-up and communication latency depends on the number of the sole branch nodes (which is a small fraction of all the nodes). Basically, the cost goes down from quadratic to linear. Anonymity is obtained by applying a broadcast-based technique for the forward message, and cover traffic (generated by the terminal-chain nodes) plus mixing over branch nodes, for the response. Francesco Buccafurri, Vincenzo De Angelis, Maria Francesca Idone, Cecilia Labrini |
CW | 2 |
| 2021 | A Privacy-Preserving Protocol for Proximity-Based Services in Social NetworksabstractA number of real-life social networks provide the users with proximity-based services. This feature exposes to seri-ous privacy threats, because it could allow massive tracking from an honest-but-curious provider. Whilst proximity-based services have been deeply studied in the literature in a general setting, no solution (to the best of our knowledge) has been provided to the problem of delivering privacy-preserving proximity-based services entirely within existing social networks. The problem is not trivial, because a social network provider can play as a global passive adversary, monitoring the flow of all the messages exchanged in the network. Therefore, to allow proximity testing between Alice and Bob not requiring that they reveal their position to the social network provider is not enough. Indeed, even the fact that proximity testing is performed between Alice and Bob (independently of the result) is a serious privacy leakage. In this paper, we provide a solution preventing also this privacy leak, giving thus a concrete way to implement privacy-preserving proximity-based services in social networks. Francesco Buccafurri, Vincenzo De Angelis, Maria Francesca Idone, Cecilia Labrini |
GLOBECOM | 2 |
| 2021 | A game theory-based approach to discourage fake reviewsabstractThe introduction of a review system in e-commerce platforms results in an effective business model. The effects of positive/negative reviews on the success of a product are well studied in the literature. Therefore, for the vendors, it is crucial to obtain positive reviews of their products. This fact opens fraudulent scenarios. Indeed, some vendors can pay an incentive to the buyers to obtain, in exchange, a fake positive review. This fake-review system (FRS) is so widespread that vendors rely on ad-hoc companies that, through intermediaries, find buyers available to release fake reviews. In this paper, we propose a game-theory-based strategy to discourage the above fraudulent business model, and an effective way to implement this strategy leveraging an Ethereum smart contract. Specifically, the contribution of the paper is two-fold. First, we formalize the current business model as a sequential game, and we identify sufficient conditions making FRS advantageous. Second, we propose to introduce in the review system a new mechanism, thanks to which, the corresponding sequential game requires conditions necessary to make advantageous FRS that are strictly less convenient than the previous ones. We implemented the solution and evaluate the cost of the smart contract execution. Vincenzo De Angelis, Francesco Buccafurri |
KES | 1 |
| 2021 | A Distributed Location Trusted Service Achieving k-Anonymity against the Global AdversaryabstractWhen location-based services (LBS) are delivered, location data should be protected against honest-but-curious LBS providers, them being quasi-identifiers. One of the existing approaches to achieving this goal is location k-anonymity, which leverages the presence of a trusted party, called location trusted service (LTS), playing the role of anonymizer. A drawback of this approach is that the location trusted service is a single point of failure and traces all the users. Moreover, the protection is completely nullified if a global passive adversary is allowed, able to monitor the flow of messages, as the source of the query can be identified despite location k-anonymity. In this paper, we propose a distributed and hierarchical LTS model, overcoming both the above drawbacks. Moreover, position notification is used as cover traffic to hide queries and multicast is minimally adopted to hide responses, to keep k-anonymity also against the global adversary, thus enabling the possibility that LBS are delivered within social networks. Francesco Buccafurri, Vincenzo De Angelis, Maria Francesca Idone, Cecilia Labrini |
MDM | 2 |
| 2021 | Anonymous Short Communications over Social Networks
Francesco Buccafurri, Vincenzo De Angelis, Maria Francesca Idone, Cecilia Labrini |
SecureComm (2) | 2 |
| 2021 | Hardening Trust Models against Slandering Attacks in Relayed Content Delivery ServicesabstractThere are a number of application contexts in which services are delivered by a given provider to some clients through other relay clients in a collaborative fashion. This is, for example, the case of sensor networks, vehicular networks, D2D, and so on. In this case, a security problem arises. Indeed, when a service is relayed by a client, it is not sure that it is relayed correctly. Therefore, the final client could be deceived if malicious relay clients exist. The classical way to contrast this problem is to use a trust mechanism, managed by the provider, based on the feedback returned by the clients. Thanks to this mechanism, the trust of malicious relay clients can be decreased, then reducing (even cancelling) the negative effects of these clients in the community. The trust mechanisms of this type often suffer from weakness against slandering attacks. Dishonest final clients can fraudulently decrease the trust of relay clients, by reporting a false feedback. In this paper, we propose a general approach to fortify the trust mechanism against this kind of attacks. Francesco Buccafurri, Vincenzo De Angelis, Maria Francesca Idone, Cecilia Labrini |
WiMob | 2 |
| 2021 | WIP: An Onion-Based Routing Protocol Strengthening AnonymityabstractAnonymous Communication Networks (ACNs) are networks in which, beyond data confidentiality, also traffic flow confidentiality is provided. The most popular routing approach for ACNs also used in practice is Onion. Onion is based on multiple encryption wrapping combined with the proxy mechanism (relay nodes). However, it offers neither sender anonymity nor recipient anonymity in a global passive adversary model, simply because the adversary can observe (at the first relay node) the traffic coming from the sender, and (at the last relay node) the traffic delivered to the recipient. This may also cause a loss of relationship anonymity if timing attacks are performed. This paper presents Onion-Ring, a routing protocol that improves anonymity of Onion in the global adversary model, by achieving sender anonymity and recipient anonymity, and thus relationship anonymity. Francesco Buccafurri, Vincenzo De Angelis, Maria Francesca Idone, Cecilia Labrini |
WOWMOM | 2 |
| 2020 | A Privacy-Preserving Solution for Proximity Tracing Avoiding Identifier ExchangingabstractDigital contact tracing is one of the actions useful, in combination with other measures, to manage an epidemic diffusion of an infectious disease in an after-lock-down phase. This is a very timely issue, due to the pandemic of COVID19 we are unfortunately living. Apps for contact tracing aim to detect proximity of users and to evaluate the related risk in terms of possible contagious. Existing approaches leverage BLE or GPS, or their combination, even though the prevailing approach is BLE-based and relies on a decentralized model requiring the mutual exchange of ephemeral identifiers among users' smartphones. Unfortunately, a number of security and privacy concerns exist in this kind of solutions, mainly due to the exchange of identifiers, while GPS-based solutions (inherently centralized) may suffer from threats concerning massive surveillance. In this paper, we propose a solution leveraging GPS to detect proximity, and BLE only to improve accuracy, with no exchange of identifiers. Unlike related existing solutions, no complex cryptographic mechanism is adopted, while ensuring that the server does not learn anything about locations of users. Francesco Buccafurri, Vincenzo De Angelis, Cecilia Labrini |
CW | 2 |
| 2019 | An Attribute-Based Privacy-Preserving Ethereum Solution for Service Delivery with Accountability RequirementsabstractThe main benefit of smart contracts over Ethereum is that different parties with conflicting interests can exchange value without trusting each other. As a matter of fact, solutions in which service delivery is regulated by smart contracts are proliferating. Sometimes, services can be negotiated and delivered only on the basis of some attributes, without disclosing the identity of the customer to the service supplier. However, accountability is still required, so that, in case of need, the identity of the customer should be linked to the service delivered and communicated to the appropriate parties. In this paper, we propose a practical solution to the above problem that integrates the features of Ethereum with a (Ciphertext-Policy) Attribute-Based Encryption scheme. To show the effectiveness of our proposal, we instantiate the general model to a significant use case. Francesco Buccafurri, Vincenzo De Angelis, Gianluca Lax, Lorenzo Musarella, Antonia Russo |
ARES | 2 |
| 2019 | Self-sovereign Management of Privacy Consensus using BlockchainabstractIn this paper, we propose a solution implementing a self-sovereign approach to manage privacy consensus in a open domain. The idea is allowing the user to set her policies in a unique way, in such a way that she keeps the full control on her personal data. The goal is achieved by combining blockchain with Attribute-Based Encryption and Proxy Re-encryption. Blockchain is also used to implement the notarization of the critical actions to obtain accountability and non-repudiation. Francesco Buccafurri, Vincenzo De Angelis |
WEBIST | 2 |