VLDB 2026 Research / reviewers in the wild / expert
Iván Abellán Álvarez
dblp:295/7771
· DBLP profile ↗
3ranked-venue papers
3as first author
3since 2021 · last 2026
0000-0003-4670-433XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 first-author · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Privacy evaluation of the European Digital Identity Wallet's Architecture and Reference FrameworkabstractDigital identity wallets promise significant advancements in digital identity management by offering users a high degree of convenience, security, and control over their data disclosure. However, there is also criticism regarding their privacy guarantees, especially when used in regulated use cases that require high levels of assurance on the correctness and binding of a legal identity. In this paper, we present a comprehensive privacy model and analysis of one of the most prominent digital wallets – the European Digital Identity Wallet (EUDIW) – as specified by the Architecture and Reference Framework (ARF) and the eIDAS 2.0 regulation. We employ a suite of qualitative privacy risk assessment methods to systematically map and evaluate information flows in three key use cases. Our analysis identifies multiple privacy risks – including linkability, identifiability, and excessive attribute data disclosure – and reveals that although the ARF is designed to comply with privacy-by-design principles, inherent design choices, such as the reliance on SD-JWT and mDOC data formats, as well as the concept of a Wallet Unit Attestation (WUA), retain risks to user privacy. Building on our findings, we then highlight how advanced Privacy-Enhancing Technologies (PETs), such as (general-purpose) Zero-Knowledge Proofs (ZKPs), can reduce or mitigate some of these risks. Iván Abellán Álvarez, Pol Hölzmer, Johannes Sedlmeir |
Comput. Secur. | 1 |
| 2025 | Private authorization codes: data minimization in card not present transactionsabstractWeb-based credit card payments require complete disclosure of all payment card details for transaction authorization. The card’s CVV (Card Verification Value) is the secret code that authorizes card not presented transactions. Currently, all payment card details must be shared among various intermediaries involved in processing the transaction. To mitigate the risks associated with fraudulent transactions, industries have adopted security standards such as the PCI DSS. Credit card data confidentiality rests on all involved stakeholders adhering to best security practices, including data communication encryption, and do not misuse the payment information. However, this security posture does not prevent potential credit card data leaks. We propose an alternative method for conducting remote card payments that does not require disclosing the authorization code while ensuring high interoperability with existing payment networks. Our approach demonstrates how designated verifier Zero-Knowledge Proofs (ZKP) enable minimal disclosure of card details, particularly protecting the confidentiality of authorization codes. Iván Abellán Álvarez |
ICBC | 1 |
| 2025 | Privacy-preserving distributed clustering: A fully homomorphic encrypted approach for time seriesabstractIn time series analysis, particularly in domains like smart metering, the drive for accurate predictions often depends on access to fine-grained, sensitive data. This need raises significant privacy concerns, especially in distributed data environments. To address these challenges, we apply the LINDDUN privacy threat modeling framework to identify and formalize privacy risks, and establish privacy requirements specific to distributed clustering of time series data. We extend the framework by integrating system design assumptions early on, and derive new attack trees that align with current threat patterns. We propose a distributed clustering protocol based on fully homomorphic encryption, and further enhance privacy guarantees by integrating differential privacy mechanisms and a software-based local caching strategy to bound computational costs. In the context of smart metering, assuming a semi-honest model where agents adhere to the protocol without collusion, our simulation results indicate a favorable trade-off between privacy and performance at ϵ ≃ 3 . 0 . Our approach offers a blueprint for designing privacy-first systems that enable accurate predictions while safeguarding individual privacy. Iván Abellán Álvarez, Sergio Potenciano Menci |
Comput. Secur. | 1 |