Giacomo Verticale

dblp:34/1346 · DBLP profile ↗
← Back
47ranked-venue papers
1as first author
14since 2021 · last 2026
0000-0001-7508-9706ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 30 · 1 first-author · 4 since 2021Software engineering, systems software and programming languages · 5 · 5 since 2021Systems, architecture and hardware · 3 · 3 since 2021Security and privacy · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Energy-efficient Dynamic Partitioning and Tensors Compression of AI Applications in Smart Eyewears
abstract
Resource-constrained smart eyewear (SEW) devices face significant challenges when deploying deep neural networks due to limited computational capacity and battery life. Computational offloading to companion devices like smartphones and cloud servers addresses processing limitations, but data transmission becomes a critical bottleneck, consuming over 50% of total energy in some scenarios. Although lossless compression methods provide limited data reduction for intermediate tensors, lossy techniques such as Vector Quantization (VQ) offer higher compression ratios (requiring only 3.3 bits per float) at the expense of inference accuracy degradation. This paper presents an adaptive multi-stage compression framework that dynamically balances these trade-offs across the SEW-phone-cloud continuum. We employ VQ at the SEW-phone interface where aggressive compression is essential (achieving 89.6% tensor size reduction with 90% retained accuracy), followed by adaptive selection between quantization and run-length encoding for phone-to-cloud transmission based on network conditions. A Deep Q-Network (DQN) agent jointly optimizes network partitioning points and compression strategies to minimize energy consumption while preserving accuracy and meeting latency constraints. A large simulation campaign considering object detection and human pose estimation tasks demonstrate that our method achieves 55--70% energy savings and 86--91% violation reduction compared to Neurosurgeon (a dynamic partitioning baseline without compression), 45.8% energy savings versus local execution, and 61.1% savings over uncompressed offloading, with latency violation rates below 9% and acceptable accuracy loss (8.0--8.1%). These results enable practical deployment of AI applications on battery-limited SEW devices.
Abednego Wamuhindo Kambale, Samin Shokrivahed, Giacomo Verticale, Francesca Palermo, Diana Trojaniello, Danilo Ardagna
ICPE3
2026 Tabular Reinforcement Learning Methods for Artificial Intelligence Tasks Offloading in Smart Eye-Wears
abstract
Virtual and Extended Reality technologies are increasingly adopted in fields such as healthcare, entertainment, and education. These applications heavily rely on Smart Eye-Wears (SEWs) and AI to provide users with new ways to perceive their environment. However, SEWs face limitations in computational power, memory, and battery life. Offloading computations to external servers is a prominent example of edge computation. However, this also presents considerable challenges due to delays caused by varying network conditions and server workloads. This article proposes self-adaptive techniques based on tabular reinforcement learning (RL) to optimize the offloading of Deep Neural Network tasks between the SEW, the user’s smartphone, and cloud servers. The goal is to maintain a high-quality user experience while minimizing energy consumption and 5G connection costs. We evaluated our framework under varying 5G and WiFi bandwidths and cloud latency. The results show that Q-learning, SARSA, and Expected SARSA achieve near-optimal policies, with Q-learning demonstrating superior performance in reducing execution time violations (approximately at 10%) and improving agent stability. Additionally, our approach offers a more favorable tradeoff between energy efficiency and execution time violations compared to two baseline methods. Real-system experiments reveal that the proposed solution can double SEW battery life with respect to local computation while maintaining a good quality of service, with only 11% execution time violations. These findings highlight the effectiveness of our approach in managing resources and enhancing the overall user experience in SEW AI applications.
Abednego Wamuhindo Kambale, Hamta Sedghani, Federica Filippini, Giacomo Verticale, Danilo Ardagna
ACM Trans. Auton. Adapt. Syst.4
2025 An Investigation on Packet Sampling between Kernel and User Space for NIDS
abstract
Extended Berkeley Packet Filter technology has been successfully used to accelerate several data-plane algorithms. An application area of growing interest is Intrusion Detection, where timely packet processing at high speed is critical. In this paper, we focus on anomaly detection, which uses machine learning to identify packets belonging to a malicious flow with the intervention of a packet sampling policy to keep up with the traffic network pace in a kernel-to-user-space pipeline, to investigate the deployment feasibility of the designed anomaly-based kernel-enhanced intrusion detection system. The performance tests related to the packet sampling policy have been carried out taking into account the same dataset used to test the inference algorithm, establishing a packet sampling rate threshold maintaining a high accuracy. The throughput measurements have been tried out on our testbed composed by two back-to-back connected programmable middlebox leveraging on the iperf3 tool to employ the stress test, validating that our designed network intrusion detection system is suitable for deployment.1
Luca Giacometti, Dario Crippa, Sebastiano Miano, Giacomo Verticale
ISNCC4
2025 Middleboxes for Validation of Encrypted FaaS Requests: TLMSP vs Delegated Credentials
abstract
The widespread adoption of TLS has significantly enhanced the end-to-end security of client-server communications, at the price of making security middleboxes incapable of performing deep packet inspection and less effective. This paper compares two recent protocols that received attention in the industry that make it possible for middleboxes to read packet content with the supervision of the server: the Transport Layer Middlebox Security Protocol (TLMSP), standardized by ETSI, and the Delegated Credentials (DC) extension of TLS, standardized by IETF. The former solution allows fine-grained access control to the payload, but requires modifications to the TLS client, hampering its adoption. The latter solution gives limited-time full plaintext access to the middlebox without the server's supervision, but without leaking the server's private keys, making its adoption easier. We integrated our mechanism for policy-checking FaaS requests into publicly available implementations of those protocols and extensively evaluated the performance of both solutions identifying the additional latency components. Results show that the latency added by TLMSP is orders of magnitude higher than the baseline. On the other hand, we observed that DC additional latency is comparable to the baseline, making the latter solution suitable for deployment.
Davide Andreotti, Riccardo Nava, Giacomo Verticale
NetSoft3
2025 AI Applications Resource Allocation in Computing Continuum: A Stackelberg Game Approach
abstract
The growth, development, and commercialization of artificial intelligence-based technologies such as self-driving cars, augmented-reality viewers, chatbots, and virtual assistants are driving the need for increased computing power. Most of these applications rely on Deep Neural Networks (DNNs), which demand substantial computing capacity to meet user demands. However, this capacity cannot be fully provided by users’ local devices due to their limited processing power, nor by cloud data centers due to high transmission latency from long distances. Edge cloud computing addresses this issue by processing user requests through 5G, which reduces transmission latency from local devices to computing resources and allows the offloading of some computations to cloud back-ends. This paper introduces a model for a Mobile Edge Cloud system designed for an application based on a DNN. The interaction among multiple mobile users and the edge platform is formulated as a one-leader multi-follower Stackelberg game, resulting in a challenging non-convex mixed integer nonlinear programming (MINLP) problem. To tackle this, we propose a heuristic approach based on Karush-Kuhn-Tucker conditions, which solves the MINLP problem significantly faster than the commercial state-of-the-art solvers (up to 50,000 times). Furthermore, we present an algorithm to estimate optimal platform profit when sensitive user parameters are unknown. Comparing this with the full-knowledge scenario, we observe a profit loss of approximately 1%. Lastly, we analyze the advantages for an edge provider to engage in a Stackelberg game rather than setting a fixed price for its users, showing potential profit increases ranging from 16% to 66%.
Roberto Sala, Hamta Sedghani, Mauro Passacantando, Giacomo Verticale, Danilo Ardagna
IEEE Trans. Cloud Comput.4
2024 Authorizing Access to Edge Resources at Wire Speed using 5G Device Authentication
abstract
We present a protocol for carrying device authentication information in packets breaking out of the 5 G network and entering the computing resources of a Multiaccess Edge Computing (MEC) site. The authentication information is then used in a network function, called Customer Edge Switch (CES), inserted in front of the ingress into the computing resources, which authorizes traffic flows originated in the mobile network to access computing resources on a per-user and per-service basis according to the principles of zero-trust security.We evaluate the performance of our solution in an emulation environment that includes the 5 G domain, a prototype implementation of the CES using the P4 language, and a Function-as-a-Service computing environment. Results show that the processing delay in the CES is small. We also provide a mathematical model for computing the maximum number of devices that can be managed at wire speed.1
Luca Giacometti, Francesco Battagin, Giacomo Verticale
HPSR3
2024 Detection of Anomalous e2e Encrypted Function Invocation in FaaS using Zero-Knowledge Proofs
abstract
Function-as-a-Service providers manage security devices that are shared among multiple tenants. It is undesirable to give them access to cleartext HTTP requests to perform tasks such as traffic inspection. The recent Zero-Knowledge Middlebox (ZKMB) can be used to enforce network policies on TLS traffic without revealing any information on the content to the policy verifier. In this paper, we describe a ZKMB implementation and a policy designed to check whether the HTTPS function invocations by the clients follow a legitimate pattern. We also present and compare two strategies to distribute allowed patterns, introducing a Moving-Target Defense approach for the function URI randomization, which shows a good tradeoff between detection effectiveness and confidentiality. Performance assessment in our prototype implementation shows that the ZK algorithms are not yet suitable for real-time execution, but current research interest in this technology is expected to narrow this gap.
Davide Andreotti, Giacomo Verticale
NetSoft2
2022 Joint Routing, Channel, and Key-Rate Assignment for Resource-Efficient QKD Networking
abstract
Quantum Key Distribution (QKD) is a recent technology for secure distribution of symmetric keys, which is currently being deployed to increase communications security against quantum attacks. However, the key rate achievable over a weak quantum signal is limited by the link performance (e.g., loss and noise) and propagation distance, especially in multi-node QKD networks, making it necessary to design a scheme to efficiently and timely distribute keys to the various nodes. In this work, we formulate, using a Mixed Integer Linear Programming (MILP) model, a novel Routing, Channel, and Key-rate Assignment (RCKA) problem for QKD with Quantum Key Pool (QKP), which exploits the opportunity of using trusted relays and optical bypass. Our formulation accounts for the possibility to build a quantum key distribution path that combines both quantum channels and trusted relays to increase the acceptance ratio of key rate requests. Leveraging different versions of the proposed MILP model, we evaluate several strategies exploiting different combinations of trusted relays and optical bypass for the RCKA problem. Results show how different trade-offs between security and resource-efficiency (expressed in terms of acceptance ratio of key rate requests vs. key storing rate in QKP) can be achieved when adopting trusted-relay and/or optical-bypass technologies. Trusted relays can provide a higher acceptance ratio when the number of QKD modules (transmitters or receivers) is sufficiently large, while optical bypass, which does not require the implementation of expensive trusted relays, is preferable when the number of QKD modules is a limiting factor.
Qiaolun Zhang, Omran Ayoub, Alberto Gatto 0001, Jun Wu 0001, Xi Lin 0003, Francesco Musumeci 0001, Giacomo Verticale, Massimo Tornatore
GLOBECOM7
2022 A Learning Approach for Production-Aware 5G Slicing in Private Industrial Networks
abstract
Industrial scenarios comprise multiple devices executing periodic, mutually-dependent tasks with challenging communications requirements. 5G technology and RAN slicing make it possible to accommodate such requirements. The predictability of the environment can be exploited to improve the network efficiency and performance. We leverage Deep Reinforcement Learning to design a "production-aware" agent based on the Deep Deterministic Policy Gradient algorithm. The proposed scheme combines production and network information to select the spectrum configuration of each slice. In details, by exploiting the knowledge about the upcoming production tasks, the agent can effectively predict the required per-slice spectrum consumption in order to boost the service provisioning reliability and limit the spectrum over-provisioning. We compare the performance of this approach with a "production-unaware" agent and with the optimal spectrum allocation. Simulations show how our solution provides a per-slice reliability in terms of meeting the latency requirements higher than the one provided by the "production-unaware" agent. Moreover, it ensures a tight approximation of the optimal slice spectrum allocation.
Marco Zambianco, Alessandro Lieto, Ilaria Malanchini, Giacomo Verticale
ICC4
2022 CHIMA: a Framework for Network Services Deployment and Performance Assurance
abstract
Network Function Virtualization has dramatically increased the flexibility in the deployment of network services, however the execution of virtual functions on compute nodes equipped with general purpose hardware can result in worse performance compared to the middleboxes they aim to replace. The use of programmable network hardware to perform part of the processing at line rate can drastically increase the throughput while retaining the flexibility.This work presents a new framework, called CHIMA, which extends the capabilities of other frameworks proposed in the literature for the deployment of heterogeneous Service Function Chains (SFCs). Heterogeneous SFCs comprise a combination of virtual functions meant to be executed in containers running on general purpose hardware and of functions for programmable switches written using the P4 language. CHIMA exploits programmable data planes to perform real time monitoring of the services through In-band Network Telemetry and uses the collected information to guarantee the requested levels of performance by redeploying and rerouting sections that are affected by adverse conditions, allowing applications with critical requirements to be deployed as SFCs.The solution has been tested by emulating various topologies and services on the FOP4 platform with bmv2 switches. The analysis shows that the system is capable of detecting faults in the order of hundreds of milliseconds, and the overhead it causes in the process of redeployment is negligible compared to the startup time of functions. Measurements also reveal that the current bottleneck for the runtime relocation of heterogeneous functions is the redeployment and reconfiguration of P4 programs.
Elia Battiston, Daniele Moro, Giacomo Verticale, Antonio Capone
NetSoft3
2022 A reinforcement learning agent for mixed-numerology interference-aware slice spectrum allocation with non-deterministic and deterministic traffic
Marco Zambianco, Giacomo Verticale
Comput. Commun.2
2021 Advancing Design and Runtime Management of AI Applications with AI-SPRINT (Position Paper)
abstract
The adoption of Artificial intelligence (AI) technologies is steadily increasing. However, to become fully pervasive, AI needs resources at the edge of the network. The cloud can provide the processing power needed for big data, but edge computing is close to where data are produced and therefore crucial to their timely, flexible, and secure management. In this paper, we introduce the AI-SPRINT project, which will provide solutions to seamlessly design, partition, and run AI applications in computing continuum environments. AI-SPRINT will offer novel tools for AI applications development, secure execution, easy deployment, as well as runtime management and optimization: AI-SPRINT design tools will allow trading-off application performance (in terms of end-to-end latency or throughput), energy efficiency, and AI models accuracy while providing security and privacy guarantees. The runtime environment will support live data protection, architecture enhancement, agile delivery, runtime optimization, and continuous adaptation.
Hamta Sedghani, Danilo Ardagna, Matteo Matteucci, Giulio Fontana, Giacomo Verticale, Fabrizio Amarilli, Rosa M. Badia, Daniele Lezzi, Ignacio Blanquer, André Martin, Konrad Wawruch
COMPSAC5
2021 Intelligent multi-branch allocation of spectrum slices for inter-numerology interference minimization
Marco Zambianco, Giacomo Verticale
Comput. Networks2
2021 Impact of Processing-Resource Sharing on the Placement of Chained Virtual Network Functions
abstract
Network Function Virtualization (NFV) provides higher flexibility for network operators and reduces the complexity in network service deployment. Using NFV, Virtual Network Functions (VNF) can be located in various network nodes and chained together in a Service Function Chain (SFC) to provide a specific service. Consolidating multiple VNFs in a smaller number of locations would allow decreasing capital expenditures. However, excessive consolidation of VNFs might cause additional latency penalties due to processing-resource sharing, and this is undesirable, as SFCs are bounded by service-specific latency requirements. In this paper, we identify two different types of penalties (referred as “costs”) related to the processing-resource sharing among multiple VNFs: thecontext switching costsand theupscaling costs. Context switching costs arise when multiple CPU processes (e.g., supporting different VNFs) share the same CPU and thus repeated loading/saving of their context is required. Upscaling costs are incurred by VNFs requiring multi-core implementations, since they suffer a penalty due to the load-balancing needs among CPU cores. These costs affect how the chained VNFs are placed in the network to meet the performance requirement of the SFCs. We evaluate their impact while considering SFCs with different bandwidth and latency requirements in a scenario of VNF consolidation.
Marco Savi, Massimo Tornatore, Giacomo Verticale
IEEE Trans. Cloud Comput.3
2020 Spectrum Allocation for Network Slices with Inter-Numerology Interference using Deep Reinforcement Learning
abstract
Network slicing and mixed-numerology schemes are essential technologies to efficiently accommodate different services in 5G radio access networks (RAN). To fully take advantage of these techniques, the design of spectrum slicing policies needs to account for the limited availability of the radio resources as well as the inter-numerology interference generated by slices employing different numerologies. In this context, we formulate a binary non-convex problem that maximizes the aggregate capacity of multiple network slices. The resulting spectrum allocation minimizes the inter-numerology interference under the frequent channel fluctuations characterizing the various users. To address the computational complexity of the designed objective function, we leverage deep reinforcement learning (DRL) to design a model-free solution computation. In detail, the trained centralized DRL agent exploits the channel fading statistic in order to provide a spectrum allocation that minimizes the inter-numerology interference. Results reveal that the proposed DRL scheme achieves performance that is comparable to the optimal one. It also outperforms a baseline scheme that statically allocate the radio resources.
Marco Zambianco, Giacomo Verticale
PIMRC2
2020 Interference Minimization in 5G Physical-Layer Network Slicing
abstract
The interference resulting from densification of access points and the coexistence of different numerologies within the same spectrum severely hinders inter-slice isolation. We propose a slice allocation policy that enforces inter-slice isolation by minimizing the inter-slice interference suffered by each virtual operator. In detail, we design a binary quadratic non-convex optimization problem that minimizes i) the inter-slice interference generated by interfering base stations and ii) the inter-slice interference generated by the multiplexing of spectrum slices having different numerologies. We also provide a heuristic algorithm to render the solution scalable in practical scenarios. We assess the performance of both approaches by evaluating the signal-to-interference-plus-noise ratio (SINR) associated to each slice through simulations. Results reveal that the heuristic algorithm provides a solution comparable with the optimal one on different minimization scenarios. Moreover, a considerable SINR improvement is observed with respect to a base-line scheme that does not account for inter-slice interference.
Marco Zambianco, Giacomo Verticale
IEEE Trans. Commun.2
2020 A Privacy-Preserving Reinforcement Learning Algorithm for Multi-Domain Virtual Network Embedding
abstract
The problem of optimally deploying a virtual network onto a substrate physical network is referred to as Virtual Network Embedding (VNE). In general, this embedding is requested by a customer to an Internet Service Provider (ISP), which performs the VNE over its physical telecom network. In several situations, the physical substrate infrastructure is composed of multiple independent ISPs. In this scenario, ISPs are concerned about exposing to a third-party entity (e.g., the customer) sensitive infrastructural details that are needed to perform an effective embedding. Following a common privacy-preserving approach, known as Limited Information Disclosure (LID), the embedding may be performed by the customer based on a limited and abstracted view of the multi-domain infrastructure that ISPs accept to expose. With this approach, embedding is sub-optimal (e.g., embedding cost is not minimized) in comparison with the case where all information is available, i.e., Full Information Disclosure (FID). In this work, we propose a Reinforcement-Learning-based algorithm able to process data that the customer and ISPs cipher under the Shamir Secret Sharing (SSS) scheme. This approach guarantees total privacy to both the customer and the ISPs (e.g., details about a virtual function are only revealed to the ISP in charge of hosting it) and achieves comparable embedding cost of an existing FID heuristic, as observed from extensive simulations. The main drawback of our algorithm is the high overhead of data that ISPs and the customer need to exchange with each other to execute it. Hence, we also explore the trade-off between embedding cost and data overhead resulting from the reduction of operations done by the RL. In general, intermediate embedding costs between the FID and LID heuristics can be obtained at a significant reduction of data overhead, while not sacrificing any privacy guarantees.
Davide Andreoletti, Tanya Velichkova, Giacomo Verticale, Massimo Tornatore, Silvia Giordano
IEEE Trans. Netw. Serv. Manag.3
2019 Privacy-Preserving Caching in ISP Networks
abstract
Content Providers (CPs) typically encrypt the content sent over the telecom network to improve security and privacy of their final users, as well as to protect business-critical information (e.g., contents' popularity). Due to this encryption, Internet Service Providers (ISPs) can not easily apply caching strategies that require the inspection of traffic traversing their networks to select the most popular contents. The most common approach to solve the conflict between privacy and caching consists in allowing a CP to manage the caches (e.g., by storing and delivering the contents) directly from inside the area of the ISP. However, in this way ISPs lose the legitimate control on a portion of traffic traversing their networks. An alternative approach is enabled by recently-proposed architectural solutions that allow a CP to encrypt the contents and associate pseudonyms to them, and the ISP to count the occurrences of such identifiers to infer popularity-related information without inspecting the original contents. However, we observe that ISPs can still obtain valuable information about contents' popularity that may threaten CPs' privacy. In this paper, we formalize a strategy of association between pseudonyms and contents that effectively improves privacy but leads to a degradation of caching performance. We formally define privacy in this context and study the trade-off between caching and privacy considering differerent metrics, such as the hit-rate and the retrieval latency. The results, obtained by means of simulations over both real and synthetic data, show that privacy can be significantly improved while accepting a minor impact on the hit-rate of caching and suggest the applicability of the considered architecture in a real scenario of content delivery.
Davide Andreoletti, Omran Ayoub, Silvia Giordano, Giacomo Verticale, Massimo Tornatore
HPSR4
2019 An Open Privacy-Preserving and Scalable Protocol for a Network-Neutrality Compliant Caching
abstract
The distribution of video contents generated by Content Providers (CPs) significantly contributes to increase the congestion within the networks of Internet Service Providers (ISPs). To alleviate this problem, CPs can serve a portion of their catalogues to the end users directly from servers (i.e., the caches) located inside the ISP network. Users served from caches perceive an increased QoS (e.g., average retrieval latency is reduced) and, for this reason, caching can be considered a form of traffic prioritization. Hence, since the storage of caches is limited, its subdivision among several CPs may lead to discrimination. A static subdivision that assignes to each CP the same portion of storage is a neutral but ineffective appraoch, because it does not consider the different popularities of the CPs' contents. A more effective strategy consists in dividing the cache among the CPs proportionally to the popularity of their contents. However, CPs consider this information sensitive and are reluctant to disclose it. In this work, we propose a protocol based on Shamir Secret Sharing (SSS) scheme that allows the ISP to calculate the portion of cache storage that a CP is entitled to receive while guaranteeing network neutrality and resource efficiency, but without violating its privacy. The protocol is executed by the ISP, the CPs and a Regulator Authority (RA) that guarantees the actual enforcement of a fair subdivision of the cache storage and the preservation of privacy. We perform extensive simulations and prove that our approach leads to higher hit-rates (i.e., percentage of requests served by the cache) with respect to the static one. The advantages are particularly significant when the cache storage is limited.
Davide Andreoletti, Cristina Rottondi, Silvia Giordano, Giacomo Verticale, Massimo Tornatore
ICC4
2018 Discovering the Geographic Distribution of Live Videos' Users: A Privacy-Preserving Approach
abstract
Content delivery involves multiple entities, such as Content Providers (CPs) and Internet Service Providers (ISPs). To better serve its users, the CP may deploy resources (e.g.,caches) as close as possible to them. In this work, we consider the deployment of Virtual Servers (VSs) to stream live videos owned by the CP in the network of the ISP. An efficient deployment requires the knowledge of both the users' position and requests. However, the CP knows what users request but not their exact position, while the ISP has knowledge of users' locations but not of their requests (due to content encryption). To guarantee users' privacy, the ISP and the CP cannot exchange these information with each other. In this paper, we make the two parties cooperate by employing a secure multiparty computation protocol which does not require the two parties to reveal the aforementioned information. This protocol allows the ISP to obtain the number of requests for a specific live-video content issued from a given area at the cost of a negligible overhead. Knowing this information, the ISP efficiently deploys the VSs with the aim of minimizing the number of hops crossed by the live videos to reach their viewers. We assess the average number of hops saved when the geographic distribution of requests is known and we conclude that it is relevant. Then, we investigate scenarios in which the privacy of both the CP and the ISP can be violated, and we propose several countermeasures. In particular, the parties can distort their data when executing the protocol, which results in a trade-off between performance and privacy. We conclude that the fulfillment of stringent privacy requirements comes at significant performance loss.
Davide Andreoletti, Silvia Giordano, Giacomo Verticale, Massimo Tornatore
GLOBECOM3
2018 Imprecise Markov Models for Scalable and Robust Performance Evaluation of Flexi-Grid Spectrum Allocation Policies
abstract
The possibility of flexibly assigning spectrum resources with channels of different sizes greatly improves the spectral efficiency of optical networks, but can also lead to unwanted spectrum fragmentation. We study this problem in a scenario where traffic demands are categorized in two types (low or high bit-rate) by assessing the performance of three allocation policies. Our first contribution consists of exact Markov chain models for these allocation policies, which allow us to numerically compute the relevant performance measures. However, these exact models do not scale to large systems, in the sense that the computations required to determine the blocking probabilities-which measure the performance of the allocation policies-become intractable. In order to address this, we first extend an approximate reduced-state Markov chain model that is available in the literature to the three considered allocation policies. These reduced-state Markov chain models allow us to tractably compute approximations of the blocking probabilities, but the accuracy of these approximations cannot be easily verified. Our main contribution then is the introduction of reduced-state imprecise Markov chain models that allow us to derive guaranteed lower and upper bounds on blocking probabilities, for the three allocation policies separately or for all possible allocation policies simultaneously.
Alexander Erreygers, Cristina Rottondi, Giacomo Verticale, Jasper De Bock
IEEE Trans. Commun.3
2017 A redundant gateway prototype for wireless avionic sensor networks
abstract
Wireless Sensor Network (WSN) technologies provide advantages that allow them to replace traditional wired systems in an ever growing number of applications. This paper describes the design of a WSN for mission critical applications such as the case of avionics, in which data collected from the sensors can be delivered to a cloud application through multiple independent gateways, thereby increasing data availability in presence of failures. Since the same data might be distributed along multiple paths, system-wide synchronization must be provided in order to guarantee data consistency. A heartbeat protocol is introduced along each path in order to guarantee timely detection of any single failure. We present a solution that can be implemented using open source software and commercial off-the-shelf hardware, which makes this approach viable for networks with a large number of heterogeneous sensors. Results reported in this paper show some sample measurements as well as the performance evaluation for our heartbeat algorithm in terms of latency between a failure and a full recovery of the system.
Davide Scazzoli, Andrea Mola, Bilhanan Silverajan, Maurizio Magarini, Giacomo Verticale
PIMRC5
2017 Up-to-date key retrieval for information centric networking
Giulia Mauri, Giacomo Verticale
Comput. Networks2
2016 A novel technique for ZigBee coordinator failure recovery and its impact on timing synchronization
abstract
In mission critical wireless sensor networks (WSNs) accurate timestamping of the occurrence of events measured by the sensor nodes is often required together with a high degree of reliability. While precise timestamping requires synchronization of the sensor nodes, reliability is obtained by adding redundancy in all potential single point of failure nodes. In this paper, we focus on a ZigBee-based WSN using two personal area network (PAN) coordinators with different PAN identifiers (IDs) and, for this configuration, we propose a solution where if the primary PAN coordinator goes down, connections are transferred to the other by changing the PAN ID of the nodes. Our proposed solution provides significant gains in terms of recovery speed and timing synchronization accuracy in comparison to a solution that is proposed in the literature.
Davide Scazzoli, Atul Kumar 0005, Navuday Sharma, Maurizio Magarini, Giacomo Verticale
PIMRC5
2015 ICN based shared caching in future converged fixed and mobile network
abstract
The explosion of mobile multimedia and Internet-of-things (IoT) services implies strong requirements for seamless switching among various types of networks. Thus, to offer true ubiquitous Internet connection, a Fixed and Mobile Converged (FMC) network architecture is essential for the future 5G network. Such a convergent network can not only improve the utilization of network resources, but also inspire new add-on services for FMC network operators. In this paper, we introduce a shared caching overlay based on Information Centric Networking (ICN). It is deployed on top of the FMC network and controlled by the FMC network operator to offer Caching as a Service (CaaS) to Over-The-Top (OTT) service providers and virtual network operators. Business analysis and performance evaluation will highlight the benefits of deploying such a controlled Shared Caching System (SCS) over an FMC network.
Jean-Charles Point, Selami Çiftçi, Onur Eker, Giulia Mauri, Marco Savi, Giacomo Verticale
HPSR7
2015 Performance evaluation of video server replication in metro/access networks
Marco Savi, Roberto Fratini, Giacomo Verticale, Massimo Tornatore
Comput. Networks3
2015 Privacy-friendly load scheduling of deferrable and interruptible domestic appliances in Smart Grids
Cristina Rottondi, Giacomo Verticale
Comput. Commun.2
2015 Mitigation of peer-to-peer overlay attacks in the automatic metering infrastructure of smart grids
abstract
Abstract Measurements gathered by smart metres and collected through the automatic metering infrastructure of smart grids can be accessed by numerous external subjects for different purposes, ranging from billing to grid monitoring. Therefore, to prevent the disclosure of personal information through the analysis of energy consumption patterns, the metering data must be securely handled. Peer‐to‐peer networking is a promising approach for interconnecting communication nodes among the automatic metering infrastructure to efficiently perform data collection while ensuring privacy and confidentiality, but it is also prone to various security attacks. This paper discusses the impact of the most relevant peer‐to‐peer attack scenarios on the performance of a protocol for privacy preserving aggregation of metering data. The protocol relies on communication gateways located in the customers’ households and interconnected by means of a variant of the Chord overlay. We also propose some countermeasures to mitigate the effects of such attacks: we integrate a verifiable secret sharing scheme based on Pedersen commitments in the aggregation protocol, which ensures data integrity, with compliance checks aimed at identifying the injection of altered measurements. Moreover, we introduce Chord auxiliary routing tables to counteract the routing pollution performed by dishonest nodes. The paper evaluates the computational complexity and effectiveness of the proposed solutions through analytical and numerical results. Copyright © 2014 John Wiley & Sons, Ltd.
Cristina Rottondi, Marco Savi, Giacomo Verticale, Christoph Krauß
Secur. Commun. Networks3
2014 Using replicated video servers for VoD traffic offloading in integrated metro/access networks
abstract
Internet traffic is increasingly becoming a mediastreaming traffic. Especially, Video-on-Demand (VoD) services are pushing the demand for broadband connectivity to the Internet, and optical fiber technology is being deployed in the access network to keep up with such increasing demand. To provide a more scalable network architecture for video/content delivery, network operators are currently considering novel integrated metro/access networks which accommodate replicated video servers directly in their infrastructure. In such way, servers for VoD delivery are placed nearer to the end users, the core segment of the network is partially traffic offloaded, and the end users experience better performance in terms of QoS. In our work, we will evaluate the performance improvement of an integrated metro/access architecture for VoD delivery with replicated video servers considering different configurations in terms of number of replicated servers, meshing degree and adopted network technologies. We develop a network simulator in which replicas of video servers (called Metro Servers, or MSs) are deployed to meet the demand of VoD traffic. In the result section we compare the performance of the various configurations and discuss which are the minimum requirements to minimize blocking of the VoD requests.
Roberto Fratini, Marco Savi, Giacomo Verticale, Massimo Tornatore
ICC3
2013 A decisional attack to privacy-friendly data aggregation in Smart Grids
abstract
The privacy-preserving management of energy consumption measurements gathered by Smart Meters plays a pivotal role in the Automatic Metering Infrastructure of Smart Grids. Grid users and standardization committees are requiring that utilities and third parties collecting aggregated metering data are prevented from accessing measurements at the household granularity, and data perturbation is a technique used to provide a trade-off between the privacy of individual users and the precision of the aggregated measurements. In this paper, we discuss a decisional attack to aggregation with data-perturbation, showing that a curious entity can exploit the temporal correlation of Smart Grid measurements to detect the presence or absence of individual data generated by a given user inside an aggregate. We also propose a countermeasure to such attack and show its effectiveness using both synthetic and real home energy consumption measurement traces.
Cristina Rottondi, Marco Savi, Daniele Polenghi, Giacomo Verticale, Christoph Krauß
GLOBECOM4
2013 Secure distributed data aggregation in the automatic metering infrastructure of smart grids
abstract
The widespread deployment of Automatic Metering Infrastructures in Smart Grid scenarios rises great concerns about privacy preservation of user-related data, from which detailed information about customer's habits and behaviours can be deduced. Therefore, the users' individual measurements should be aggregated before being provided to External Entities such as utilities, grid managers and third parties. This paper proposes a security architecture for distributed aggregation of smart metering data relying on Gateways placed at the customers' premises, which collect the data generated by local Meters and provide communication and cryptographic capabilities. We propose a secure communication protocol based on multiparty computation aimed at preventing Gateways and External Entities from inferring information about individual data. The routing of information flows can be centralized or it can be performed in a distributed fashion using a protocol similar to Chord.
Cristina Rottondi, Giacomo Verticale, Christoph Krauß
ICC2
2013 Privacy-preserving smart metering with multiple data Consumers
Cristina Rottondi, Giacomo Verticale, Antonio Capone
Comput. Networks2
2013 Distributed Privacy-Preserving Aggregation of Metering Data in Smart Grids
abstract
The widespread deployment of Automatic Metering Infrastructures in Smart Grid scenarios rises great concerns about privacy preservation of user-related data, from which detailed information about customer's habits and behaviors can be deduced. Therefore, the users' individual measurements should be aggregated before being provided to External Entities such as utilities, grid managers and third parties. This paper proposes a security architecture for distributed aggregation of additive data, in particular energy consumption metering data, relying on Gateways placed at the customers' premises, which collect the data generated by local Meters and provide communication and cryptographic capabilities. The Gateways communicate with one another and with the External Entities by means of a public data network. We propose a secure communication protocol aimed at preventing Gateways and External Entities from inferring information about individual data, in which privacy-preserving aggregation is performed by means of a cryptographic homomorphic scheme. The routing of information flows can be centralized or it can be performed in a distributed fashion using a protocol inspired by Chord. We compare the performance of both approaches to the optimal solution minimizing the data aggregation delay.
Cristina Rottondi, Giacomo Verticale, Christoph Krauß
IEEE J. Sel. Areas Commun.2
2012 A negotiation-based scheme for service level pricing for wireless access
Paolo Giacomazzi, Igor Stanojev, Giacomo Verticale
Comput. Commun.3
2010 A Negotiation Approach for Pricing the Wireless Access
abstract
In this paper, we propose a new algorithm for bilateral multi-attribute negotiations between autonomous agents with nonlinear utilities and detail on its application for pricing the wireless access services. In particular, we consider a scenario in which a wireless service provider adapts its offer of wireless bandwidth to the dynamics of the access demand and of the available spectrum. To achieve this, the provider performs one-to-one negotiations with the customers over the service transmission rate and the service price. The proposed negotiation algorithm is a practical solution for pricing those customers that require constant-rate service. Numerical simulations provide in-depth illustration of the scheme performance for various network settings.
Igor Stanojev, Giacomo Verticale, Paolo Giacomazzi
ICC2
2009 An Analytical Expression for Service Curves of Fading Channels
abstract
In this paper, we develop a method for analyzing time-varying wireless channels in the context of the modern theory of the stochastic network calculus. In particular, our technique is applicable to channels that can be modeled as Markov chains, which is the case of channels subject to Rayleigh fading. Our approach relies on theoretical results on the convergence time of reversible Markov processes and is applicable to chains with an arbitrary number of states. We provide two expressions for the delay tail distribution of traffic transmitted over a fading channel fed by a Markov source. The first expression is tighter and only requires a simple numerical minimization, the second expression is looser, but is in closed form.
Giacomo Verticale, Paolo Giacomazzi
GLOBECOM1
2007 Analytical Methods for Resource Allocation and Admission Control with Dual-Leaky-Bucket Regulated Traffic
abstract
In this paper, we study the problems of resource allocation and admission control of traffic flows with guaranteed quality of service. Specifically, we deal with traffic flows regulated by dual-leaky buckets and we establish the analytical expressions for (a) the minimum capacity to be allocated in order to guarantee the required delay performance and for (b) the maximum number of flows that is possible to accept, known the link capacity, with statistical QoS constraints on the delay. With the closed-form formulae obtained with our analysis, we compare the performance of the dual-leaky-bucket and of the simpler token-bucket regulators, and we discuss the conditions that make the dual-leaky bucket outperform the token bucket.
Paolo Giacomazzi, Luigi Musumeci, Gabriella Saddemi, Giacomo Verticale
ICC4
2006 Optimal Selection of Token Bucket Parameters for the Admission of Aggregate Flows in IP networks
abstract
A linear bounded arrival process (LBAP) traffic regulator is characterized by two parameters, the token rate r and the bucket size b, and the design of such a traffic regulator consists in selecting the most appropriate (r, b) pair according to a performance metric to be optimized. This (r, b) pair is currently selected through a two-step process. Firstly, the LBAP curve of the regulator, formed by all the pairs (r, b) satisfying an assigned performance target, is calculated. On the LBAP curve, all the pairs (r, b) are equivalent, as far as the assigned performance target is concerned. In the second step the preferred (r, b) pair on the LBAP curve is chosen according to an additional criterion, which makes it possible to optimise an objective function. Usually, this objective function accounts for the performance of the regulator only, without considering the transport of the regulated traffic flow from the output of the regulator to the final destination through the network. In this work, we propose an alternative approach to perform the second step of the selection of the (r, b) pair on the LBAP curve. Our approach, the minimum capacity criterion, as opposed to traditional methods considering the regulator alone, chooses the (r, b) pair which minimizes the network capacity allocated in order to guarantee the end-to-end negotiated delay of the traffic flow. We show that with our criterion this capacity is much smaller than that required with other criterions presented in the literature.
Paolo Giacomazzi, Luigi Musumeci, Gabriella Saddemi, Giacomo Verticale
GLOBECOM4
2006 A Novel Location-Based Multicast Protocol for Ad-Hoc Networks
abstract
A novel location-based multicast routing protocol for ad-hoc networks is proposed. Starting from a well-known extension of the GPSR protocol to multicast, reduced bandwidth consumption is obtained by performing clustering estimation of the destination group and by considering each cluster as a single node for packet forwarding. As the new protocol limits the number of packet replications, network efficiency is improved. When real-time multicast traffic is carried, the packet delivery ratio is increased without noticeably affecting end-to-end delay. We study the performance of our protocol through simulation, with a simulator implementing a full MAC protocol. This allows to measure the performance in bandwidth-limited scenarios and to validate the results
Giuseppe Caizzone, Walter Erangoli, Paolo Giacomazzi, Giacomo Verticale
PIMRC4
2006 Two different approaches for providing QoS in the Internet backbone
Paolo Giacomazzi, Luigi Musumeci, Gabriella Saddemi, Giacomo Verticale
Comput. Commun.4
2006 An analytical model based on the ETSI criteria for the evaluation of user satisfaction in UMTS
Paolo Giacomazzi, Luigi Musumeci, Giacomo Verticale
Wirel. Networks3
2005 An enhanced GPSR routing algorithm for TDMA-based ad-hoc networks
abstract
This work proposes an enhancement of the GPSR routing protocol to improve the performance of point-to-point IP-based voice communications in a vehicular ad-hoc network. Our enhancement reduces significantly the end-to-end delay in ad-hoc networks using a TDMA-based medium access control protocol. The proposed enhancement of GPSR routing basically consists in an optimized choice of the next hop node based on the time slot used by the node to transmit outgoing packets. We evaluate the performance improvements in terms of end-to-end packet delay, packet loss ratio and synthetic mean opinion score that users would assign to the voice communications. We show that, with our procedure, it is possible to obtain a significant performance improvement in terms of network scalability and quality of IP telephone calls
Giuseppe Caizzone, Walter Erangoli, Paolo Giacomazzi, Giacomo Verticale
GLOBECOM4
2005 A power control algorithm with high channel availability for vehicular ad hoc networks
abstract
We propose a new power control algorithm capable of managing the topology of a vehicular ad hoc network by adjusting transmission power dynamically. Our algorithm is simple to implement, as it is based only on local information and no exchange of power-related signaling among nodes is required. The algorithm has the objective of making the network operate with both a very low and a very high user density, while maintaining its performance unaltered. This target is obtained by controlling transmission power, so that the number of neighbors of each node is always within a minimum and maximum threshold. In this way, it is possible to cope concurrently with the problems of node isolation and clustering at low load and of excessive competition for radio resources at high load. Finally, the algorithm provides high channel availability for connected users. The algorithm is robust, as performance does not depend on user speed, which has a large variance in a vehicular scenario.
Giuseppe Caizzone, Paolo Giacomazzi, Luigi Musumeci, Giacomo Verticale
ICC4
2003 An analytical model for user satisfaction in WCDMA systems based on the ETSI criteria
abstract
Most analytical models for the evaluation of convergence and capacity of WCDMA systems aim at evaluating only the outage probability of a given cellular deployment scenario. This is not in line with the ETSI guidelines for performance evaluation, which state that the coverage and the capacity of the system should be measured in terms of a given percentage of unsatisfied users. In this paper, we elaborate an analytical model capable of giving such a figure. In addition, a comparison between analytical and simulation results confirms the validity of the proposed model.
Paolo Giacomazzi, Luigi Musumeci, Giacomo Verticale
ICC3
2002 A proposal for an Ethernet-over-WDM wide area multiplexing architecture
abstract
This paper presents a workable solution for transport of IP packets over optical networks. The protocol heavily relies on the data link and physical layer of the proposed standard 10 Gbit/s Ethernet. The architecture is able to optically multiplex and forward asynchronous packets like those generated by classical Ethernet devices.
Guido Gilardi, Achille Pattavina, Giacomo Verticale
ICC3
2000 An Architecture for Effective Push/Pull Web Surfing
abstract
World Wide Web (WWW) pages are the vehicle of complex information generated from different sources and with different objectives. This paper proposes to complement the ordinary, pull based, Web browsing architecture by exploiting readily available technologies which address the requirements of a large part of the information. In our solution, push technology and IP multicasting enable the source originated delivery of content to multiple users. Moreover, the real time protocol offers a means to address the delivery of time sensitive content. Ordinary WWW browsers have been used to prove the effectiveness of the proposal in a prototype implementation. Advertising banner delivery, news multicasting and fair electronic auctions are among the target applications of our solution.
Vittorio Trecordi, Giacomo Verticale
ICC (2)2
2000 Per-flow delay performance in a FIFO scheduler fed by policed UDP sources
Vittorio Trecordi, Giacomo Verticale
Comput. Commun.2