Aref Meddeb

dblp:39/6920 · DBLP profile ↗
← Back
55ranked-venue papers
12as first author
17since 2021 · last 2026
0000-0002-6678-2223ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 16 · 11 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 12 · 5 since 2021Systems, architecture and hardware · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Entropy-Driven Inconsistencies in Shared Secrets with CRYSTALS-Kyber on Heterogeneous Platforms
abstract
Post-Quantum Cryptography (PQC) is essential to secure future Internet-of-Things (IoT) systems against quantum adversaries. CRYSTALS-Kyber, recently standardized by NIST, provides efficient key encapsulation for constrained devices. This paper investigates Kyber’s interoperability across heterogeneous IoT platforms—Raspberry Pi, ESP32, and x86-64 laptops—using the MQTT protocol. We demonstrate successful key exchanges among homogeneous platforms and mixed Raspberry Pi–laptop systems, but observe failures in ESP32 cross-platform exchanges. Analysis indicates that inconsistent shared secrets originate from entropy variations in platform-specific Random Number Generators (RNGs). Our results highlight the need for standardized entropy handling in PQC implementations for seamless IoT integration.
Mohamed Amine Mighri, Ahmed Benfarah, Aref Meddeb
CCNC3
2026 A Bootstrapped Mixed Lattice-Isogeny-based PQC Key Exchange for IoT Systems
Feten Ben Ahmed, Aref Meddeb
IWCMC2
2026 Survey on IoT security using biometrics and blockchain technology
Alyaa Haleem, Saoussen Ben Jabra, Aref Meddeb
Multim. Tools Appl.3
2025 Evaluating Distance-Induced Performance Trade-offs in IoT: Simple Automatic ReQuest vs. TCP and UDP
abstract
In critical sectors like healthcare, banking, and surveillance, Internet of Things (IoT) applications require reliable communication protocols that ensure high performance under energy constraints. These sectors demand both reliable data delivery and high throughput to support real-time operations, making the balance between these metrics crucial, particularly when devices operate at varying distances. This article provides valuable insights for selecting reliable transport protocols in IoT deployments, especially in scenarios where trade-offs between reliability, throughput, and energy consumption must be carefully managed. We examine the performance impact of distance on the Simple Automatic ReQuest (SARQ) protocol compared to traditional UDP and TCP in IoT environments. Through experimental analysis across varying distances, we evaluated three key performance metrics: throughput, reliability (packet delivery ratio), and energy consumption. Our findings show that distance significantly affects performance, even in short ranges. UDP experiences about 20% decline in throughput and packet delivery ratio as distance increases from 10 to 50 meters, while SARQ maintains consistent performance, demonstrating its robustness to distance-related challenge, and TCP maintains high reliability (100%) but suffers from lower throughput and higher energy consumption, even for short distances. In terms of energy efficiency, SARQ’s consumption lies between UDP’s minimal requirements and TCP’s higher consumption. These characteristics make SARQ particularly suitable for IoT applications requiring balanced performance, offering a practical solution that combines reliable communication with reasonable throughput and energy efficiency.
Manel Chahed, Aref Meddeb, Amine Boufaied
IWCMC2
2025 Quantum internet building blocks state of research and development
abstract
Breakthrough developments in quantum information technology is paving the way to the Quantum Internet. This article aims to provide an overview of the current state of research and development in the field of Quantum Communications and Quantum Internet. We examine the main building blocks and the latest achievements. By providing a holistic overview of recent achievements, this article fosters a deeper understanding of these building blocks, the related opportunities, and challenges associated with the realization of the Quantum Internet. We also provide some simple pedagogical models aimed to give the reader a clear insight on the interactions between quantum networking elements. A simple Quantum Internet 5Level-3D communication model is also provided, which integrates with, rather than parallels, the classical OSI and TCP/IP models. We further describe deployed testbeds and trials and highlight potential opportunities and challenges for Communication Service Provider's. We also provide some KPIs of quantum technologies and their evolution over the last decade. This article is intended as a self-contained entry level tutorial for newcomers who are not familiar with quantum information theory, but with some background knowledge about classical networking. Academics, students, as well as professionals can use this article to become able to begin researching the Quantum Internet, without having to read a plethora of articles, web pages, and books on the subject.
Aref Meddeb
Comput. Networks1
2024 Optimal Routing for Competitive Service Providers in Network Virtualization Context
abstract
In the context of Network Virtualization where service providers may instantiate virtual networks on a common physical infrastructure, multiple virtual servers may be instantiated on physical ones. These virtual servers are in different locations and provide the same service. Then, clients are served without knowing which server is replying and which path is crossed for their traffic routing. Service providers such as competitive ones who lease the physical infrastructure are responsible for adopting the suitable routing strategy. These providers aim to reduce the cost of leased resources while guaranteeing their clients' quality of service requirements. In this paper, we consider the optimal routing problem for competitive service providers in Network Virtualization context. We model it as a mixed integer linear program whose objective function is to minimize the cost under flow and servers' bandwidth constraints. We then solve the proposed program on a small instance of network topology. We notice that Traffic Concentration on the closest server yields an optimal solution: all the traffic of each client should be routed to the closest server in terms of hop count. We finally compare, through analytical models based on the M/D/1/N queue, the performance of Traffic Concentration with three load sharing techniques as a function of traffic intensity. We note that Traffic Concentration reduces the mean sojourn time for all the traffic intensities. However, the load sharing techniques outperform Traffic Concentration in terms of blocking probability for medium and heavy traffic intensities with comparable results for low traffic intensities.
Achref El Amri, Aref Meddeb
AICCSA2
2024 Simple ARQ Protocol for Reliable Transport in LowPANs
abstract
Due to the surge in IoT devices, numerous protocols have been proposed to meet their needs. UDP is commonly used for IoT because of its simplicity, low latency, minimal overhead, and low energy consumption. In contrast, TCP is less suitable for IoT due to its higher resource demands, complexity, and greater energy consumption, which are challenging for small devices with limited resources. Therefore, often, reliability is provided by upper-layer protocols, mainly by the applications themselves. In fact, classical IoT applications such as sensing, identification and actuating generate multiple copies of data due to the hardware redundancy and periodic updates. Examples of such applications include, agricultural, environmental, traffic, and healthcare monitoring. UDP and TCP protocols may be inadequate for IoT applications requiring reliable, real-time communication. In critical situations like battlefields or disasters, sensors might only send a few messages before being destroyed. Therefore, the network itself must ensure reliability in these scenarios. Moreover, smart textiles are more and more integrating sensory devices and require reliable transmissions. In fact, with the very stringent resource constraints on one hand, and the requirements to respect the Specific Absorption Rate (SAR) of human bodies, on the other hand, re-transmissions and power must be kept at their lowest levels. In this paper, we propose a simple Automatic Request (SARQ) transport protocol that uses acknowledgments and a retransmission mechanism. Through a realistic simulation setup using Contiki motes in cooja simulator, we show that our protocol exhibits slightly higher energy consumption and resource requirements than UDP, but far less than TCP. Conversely, we show that our protocol exhibits 99% Packet Delivery Ratio (PDR), while UDP and TCP exhibit 74% and 99% PDR, respectively.
Manel Chahed, Aref Meddeb, Amine Boufaied
AICCSA2
2024 Performance Evaluation and Benchmarking of PQC CRYSTALS-Kyber on Embedded Devices
abstract
The growing threat posed by quantum computing to classical cryptographic primitives has prompted significant research activities on Post-Quantum Cryptography (PQC). Among these, CRYSTALS-Kyber has emerged as a promising candidate due to its IND-CCA2 security and efficient performance. This paper presents a comprehensive benchmarking study focused on evaluating the performance of CRYSTALS-Kyber on embedded devices, with a particular emphasis on the popular Raspberry Pi platform.
Mohamed Amine Mighri, Ahmed Benfarah, Aref Meddeb
AICCSA3
2023 A Survey of Intrusion Detection-Based Trust Management Approaches in IoT Networks
Meriem Soula, Bacem Mbarek, Aref Meddeb, Tomás Pitner
AINA (3)3
2023 Performance Evaluation of Path Loss Models for Internet of Wearable Things
abstract
The Internet of Wearable Things (IoWT) is a promising technology for Wireless Body Area Networks (WBAN). In fact, WBAN channel characterization has become a major challenge, especially for real-time monitoring and remote control of vital signs and physiological data of patients in medical applications. In this paper, we present a performance evaluation of the IEEE 802.15.6 CM3A model based on our mathematical voxel-human body channel model at 2.4 GHz for various distances between the coordinator and the on-body wearable sensor antennas. Theoretical studies and simulation results are presented in detail. The proposed channel modeling, based on 3D voxel-body models, is in good agreement with the IEEE 802.15.6 CM3A model, and a comparison of path loss models performances is also presented. All numerical simulation results are performed using CST microwave studio.
Marwen Amiri, Abdelaziz Hamdi, Aref Meddeb
INISTA3
2023 Design of a Wearable Patch Antenna and Channel Modeling for Internet of Bodies Application
abstract
The Internet of Bodies (IoB) is being widely used in military, civil, and medical applications. IoB uses wearable interconnected sensors on, in, or around a human body. Due to the significant signal loss caused by human tissue frequency absorption and the complexity of the propagation environment, one of the most critical challenges in IoB is the characterization of the communication channel between wireless sensors. It is also hard to predict the dynamic behavior of the individual wearing the wireless sensors. In this paper, we propose a mathematical model for the communication channel between transceiver and receiver antennas in free space and in human body propagation environments. We also propose a design of a new patch antenna at 2.4 GHz. Simulation results show that the antenna has good performances in both free space and voxel human body environments.
Marwen Amiri, Abdelaziz Hamdi, Aref Meddeb
IWCMC3
2023 An Effective Replica Node Detection Scheme in Internet of Things Networks
abstract
The importance of Internet of Things (IoT) lies in its far-reaching impact on our daily lives, so it is prone to risks. Therefore, security measures must be considered before deploying IoT networks to avoid intrusions. Most of the relevant work in the literature have been dedicated to improve the intrusion detection system and security systems. However, most current Intrusion Detection System (IDS) approaches suffer from the lack of a proper testing procedures before an actual attack. In this paper, we propose a low-cost solution to detect malicious nodes by ensuring that witness nodes work properly. We propose an effective automatic detection strategy for the test sequence and selection of witness nodes. The goal is to test the automatic correct actions of a witness node when an attacker launches a replication or cloning attack. We present a case study of replication attacks in IoT and use the CupCarbon simulator to evaluate our approach and demonstrate how a compromised node could be detected among witness nodes.
Bacem Mbarek, Meriem Soula, Tomás Pitner, Aref Meddeb
IWCMC4
2023 A dual-mode MAC protocol with service differentiation for industrial IoT networks using wake-up radio
Mayssa Ghribi, Aref Meddeb
Ad Hoc Networks2
2023 A secure lightweight mutual authentication scheme in Social Industrial IoT environment
Arij Ben Amor, Sarra Jebri, Mohamed Abid, Aref Meddeb
J. Supercomput.4
2022 Comparative Study of QoS-aware Network Coding Protocols in WSNs
abstract
For Wireless Sensor Networks (WSN), quality of service (QoS) can be defined as the quantity and quality of information that is extracted from data collected in the en-vironment where the sensors are deployed. The level of QoS can be measured by a set of parameters, such as throughput, delay, packet loss, energy efficiency, and reliability. Network Coding (N C) is a promising method that can be applied to solve several shortcomings of WSNs to support QoS. In this paper, a comparative study of some protocols based on NC in WSN is provided. We show that the Network Coding based Duty Cycle Learning Algorithm (NCDCLA), which we proposed in a previous work, outperforms all its predecessors.
Amra Sghaier, Aref Meddeb
AICCSA2
2022 Performance Analysis of Wake-Up Radio Based Protocols Considering Non-ideal Transmission Channel
Mayssa Ghribi, Aref Meddeb
AINA (1)2
2022 CaWuQoS-MAC: Collision Avoidance and QoS Based MAC Protocol for Wake-Up Radio Enabled IoT Networks
Mayssa Ghribi, Aref Meddeb
AINA (1)2
2020 Survey and taxonomy of MAC, routing and cross layer protocols using wake-up radio
Mayssa Ghribi, Aref Meddeb
J. Netw. Comput. Appl.2
2019 CASK: Conditional Authentication and Session Key Establishment In Fog-assisted Social IoT Network
abstract
The Fog-assisted Social Internet of Things (FSIoT) is an emergent paradigm that brought new opportunities in terms of service provisioning in the IoT-Fog network. Therefore, in such environment, the establishment of secure and trust communication scheme is a crucial need between peer IoT devices having similar social profiles. In this context, we propose a Conditional Authentication and Session Key establishment (CASK)-Algorithm for a fog-assisted Social IoT environment. The algorithm allows users profile matching before establishing the authenticated session key. CASK is performed using ECC and one_way hash function. Comparing to the existing works, our solution presents many advantages in terms of security aspects, efficiency, social-awareness and reduced computation overheads.
Arij Ben Amor, Mohamed Abid, Aref Meddeb
IWCMC3
2019 SAMAFog: Service-Aware Mutual Authentication Fog-based Protocol
abstract
Authentication is an important and challenging issue for the security of fog computing where fog nodes afford several services (storage, service access, computing, ..) to edge users. Operators and cloud service providers try to take profit from this paradigm to be closer to customers and satisfy their desires. They try to ensure privacy and secure mutual authentication between users and fog nodes when accessing services. The mainly existing fog-based authentication solutions didn't achieve complete security needs and/or have large computation overheads. In this paper, SAMAFog: a service aware and efficient mutual authentication protocol for the fog network is proposed. The mutual authentication between fog servers and users and the establishment of the session key are ensured using low-cost cryptographic primitives such as ECC and one_way hash function. The security features of the proposed scheme are formally evaluated using BAN-Logic method and AVISPA tool. In addition, comparative performance analysis is given among our scheme and relevant protocols. The results of comparative analysis illustrate that the proposed protocol provides robust, lightweight and efficient security performance for mutual authentication in fog environment.
Arij Ben Amor, Mohamed Abid, Aref Meddeb
IWCMC3
2019 6LowPSec: An end-to-end security protocol for 6LoWPAN
Ghada Glissa, Aref Meddeb
Ad Hoc Networks2
2019 An Optimized NS2 Module for UHF Passive RFID Systems
Rahma Ben Fraj, Vincent Beroulle, Nicolas Fourty, Aref Meddeb
J. Electron. Test.4
2019 A new variant of cuckoo search algorithm with self adaptive parameters to solve complex RFID network planning problem
Atef Jaballah, Aref Meddeb
Wirel. Networks2
2018 Load Sharing Techniques for Server Selection in Network Virtualization
abstract
Network Virtualization enables service providers to share the same physical network infrastructure in order to create virtual networks. Service providers who own their physical infrastructure tend to maximize the revenue and resource utilization while respecting the quality of service's constraints. For this, they choose Load Sharing techniques for server selection in the context of Network Virtualization where clients send their requests and receive responses without knowing which server has responded and which path is used. Equally Distributed, Round Robin, Weighted Round Robin and Equally Distributed combined with Round Robin are proposed as Load Sharing techniques on multiple servers. In this paper, we evaluate the performance of these techniques as a function of traffic intensity in terms of latency, jitter, packet loss ratio and connection to server failure. Then, we compare these performances with those of Traffic Concentration on the closest server which is adopted by service providers who don't own their infrastructure and want to lease it. Through simulation, we notice that both Traffic Concentration and Weighted Round Robin reduce the latency when the network is slightly loaded and at medium and heavy traffics respectively. However, Equally Distributed and Round Robin provide the best performance in terms of packet loss ratio. These two simulation results are proved by an analytical model based on the M/D/1/K waiting queue. Also, the combination of Equally Distributed with Round Robin minimizes the jitter values. Finally, Equally Distributed and Round Robin decrease the probability of connection failure.
Achref El Amri, Aref Meddeb
AICCSA2
2018 Time Modeling with NS2 in UHF RFID Anti-Collision Protocols
abstract
In UHF RFID systems, many collisions happen due to the numerous tag responses generated by the inventory process. This is a serious worry faced by the RFID technology which can limit RFID system performances. As a matter of fact, the extra identification delays added by these collisions and the extra energy consumed can bring a waste of bandwidth to the interrogation process. Considering these collisions has been identified as a critical task in RFID systems. Indeed, the efficiency of tag identification is related to the performance of the algorithm of anti-collision, which is implemented on the tag and the reader. To evaluate this performance, an RFID module has already been developed in the NS2 Simulator. This NS2 RFID module implements an RFID system based on the Q-Algorithm of EPC global Radio-Frequency Identification Protocols Class1 Generation-2 Standard (EPC C1 Gen2). The focus of this module is the network layer and its mechanisms for anticollision. In this paper, we propose an optimization of the time model of this NS2 RFID module. This optimization is based on the use of several slots time durations. First, we validate our RFID module model by simulation with NS2 and comparison with theoretical results. Secondly, we conduct a performance evaluation of two recent RFID anti-collision algorithms (Q+ and Split Q-Algorithm), evaluate their performances with this novel model and compared them to the Q-Algorithm of the EPC C1 Gen2 standard. By evaluating the performance of these protocols in our RFID module, we validate that the Split Q-Algorithm and the Q+ minimize the Q-Algorithm identification time. Our new model much more realistic in terms of timing can be of great help in further investigating the performance of the Q-Algorithm and for actual UHF RFID systems performance analysis.
Rahma Ben Fraj, Vincent Beroulle, Nicolas Fourty, Aref Meddeb
AINA4
2018 Slicing aware QoS/QoE in software defined smart home network
abstract
Home networks are gaining a large portion of the global wired and wireless network fabric. These networks present more and more challenges due to their growing heterogeneity, user high expectations versus scare resources. The continued emergence of applications and devices with stringent Quality of Service and Quality of Experience requirements call for novel solutions, effective in aggregating and managing the resources of smart house-holds. Software defined networking offers a high degree of flexibility for implementing such networking solutions to improve the performance of smart homes. In prior works on SDHN, the focus was either on slicing the control plane or on traffic management in the data plane of the home networks. In this work, we are combining the two approaches by associating a data plane bandwidth slicing model to the control plane slices that accommodates the flows data rate requirement. By investigating different slicing strategies, we aim to determine the best strategy that provides isolation, fair resource sharing, good QoE, and performance improvement which are very important factors for effective management of the future smart residential networks.
Saoussen Chaabnia, Aref Meddeb
NOMS2
2018 Driver information system: a combination of augmented reality, deep learning and vehicular Ad-hoc networks
Lotfi Abdi, Aref Meddeb
Multim. Tools Appl.2
2017 A Privacy-Preserving Authentication Scheme in an Edge-Fog Environment
abstract
In the three hierarchy architecture Edge-Fog-Cloud, delivering services with low latency is needed from the cloud to fog users with the intermediate of fog servers.Private and secure communication scheme will be necessary between fog users and dynamic fog servers. Fog servers are dynamic in joining and leaving the fog. This dynamic change of fogs must be transparent to the fog users. Our solution lies on the introduction of a mutual authentication between Fog users at the Edge of the network and the Fog servers at the Fog layer. We propose a fog user-fog server anonymous mutual authentication scheme in which fog user and fog server authenticate each other and establish a session key without disclosing user's real identity. Our scheme is based on Pseudonym Based Cryptography PBC, Elliptic Curve Discrete Logarithm Problem ECDLP and bilinear pairing to establish the session key.To evaluate the new solution, a security analysis and a formal validation with AVISPA are presented.
Arij Ben Amor, Mohamed Abid, Aref Meddeb
AICCSA3
2017 Resource Allocation Heuristics for Network Virtualization
abstract
Network Virtualization allows overcoming the limitations of the current Internet. It enables the embedding of virtual networks on physical ones. Service providers share the same physical infrastructure in order to provide their own services and deploy their new ones. The allocation of available physical resources is an important issue for Network Virtualization. Due to the hardness of this problem, many heuristics are proposed to simplify its resolution. In this paper, we present two novel heuristics for physical resource allocation which are Traffic Concentration and Load Sharing. With Traffic Concentration heuristic, service providers concentrate all the traffic on the shortest path. However, with Load Sharing heuristic, they share the load on multiple paths. We compare the performances of these heuristics in terms of latency, jitter, packet loss ratio, connection to server probability, node and link utilization, throughput and leased bandwidth as a function of the number of used servers. Simulation results demonstrate that the choice of resource utilization has an impact on the performance: with Traffic Concentration, we gain in terms of cost of leased bandwidth and jitter. But, with Load Sharing, we gain in terms of latency, packet loss ratio, connection to server probability and throughput.
Achref El Amri, Aref Meddeb
AICCSA2
2017 A Security Analysis of LOADng Routing Protocol
abstract
Along with other standards, the Lightweight On-demand Ad hoc Distance-vector routing protocol - Next Generation (LOADng), has provided a baseline architecture for the Internet of Things. Trying to ensure an advanced communication in the world of smart, tiny and embedded networking devices, LOADng should establish and maintain secure links between all communicating objects. This paper mainly addresses the security aspect of LOADng routing, it analyses the impact of using ICV and Timestamp TLVs protection to preserve control messages from various possible vulnerabilities. The experimental evaluation, through the Contiki OS, proves the feasibility and the efficiency of these two security methods against LOADng deficiencies.
Ghada Glissa, Aref Meddeb
AICCSA2
2017 In-vehicle cooperative driver information systems
abstract
Critical traffic problems such as accidents and traffic congestion require the development of new transportation systems. Research in perceptual and human factors assessment is needed for relevant and correct display of this information for maximal road traffic safety as well as optimal driver comfort. One of the solutions to prevent accidents is to provide information on the surrounding environment of the driver. The development and deployment of cooperative vehicular safety systems undeniably require a combination of dedicated wireless communications, computer vision, and AR technologies as the building blocks of cooperative safety systems. Augmented Reality Head-Up Display (AR-HUD) can facilitate a new form of dialogue between the vehicle and the driver; and enhance ITS by superimposing surrounding traffic information on the users view and keep drivers view on roads. In this paper, we propose a fast deep-learning-based object detection approaches for identifying and recognizing road obstacles types, as well as interpreting and predicting complex traffic situations. A single Convolutional Neural Network (CNN) predicts region of interest and class probabilities directly from full images in one evaluation. We also investigated potential costs and benefits of using dynamic conformal AR cues in improving driving safety. A new AR-HUD approach to create real-time interactive traffic animations was introduced in terms of types of obstacle, rules for placement and visibility, and projection of these on an in-vehicle display.
Lotfi Abdi, Aref Meddeb
IWCMC3
2017 Inter-vehicle video communications over Vehicular Ad Hoc Networks
abstract
Cooperative driving systems based on Vehicular Ad Hoc Networks (VANETs) for information exchange can assist the driver in making the right decision in a challenging situation of a vision obstruction by a vehicle or any other object. Via inter-vehicle communications, a video stream captured by a windshield-mounted camera in a vehicle is augmented with 3D information and broadcasted to the vehicle behind it, where it is displayed to assist the driver. In this paper, we present an adaptive video streaming solution for a highway scenario, using an efficient broadcasting mechanism. Our work consists of designing and implementing a complete framework that integrates Simulation of Urban Mobility, Network Simulator and EvalVid to evaluate the video quality. Simulation results show that the our scheme is capable of identifying video contents and network topology with great accuracy. We also demonstrate the effectiveness of the rebroadcaster selection mechanism used to select the broadcasting node, which increases the packet delivery ratio, reduces the delay, and extends the transmission range between the source and the destination.
Lotfi Abdi, Aref Meddeb
IWCMC3
2017 Impact of server placement on routing performance in Network Virtualization
abstract
Network Virtualization allows service providers to instantiate virtual networks on a common physical infrastructure in order to provide their services to customers. In this context, customers send their requests to servers without knowing which path is used and which server has responded. Many strategies can be adopted by service providers to route their traffics such as Traffic Concentration on one server or Load Sharing on multiple servers. In this work, we compare the performances of these two strategies using both OSPF and disjoint paths as a function of traffic concentration ratio on each server. The evaluation criteria are latency of DNS requests, UDP jitter and UDP packet loss ratio. Through simulation, we conclude that server placement has an impact on routing performance: latency decreases for the closest server but it increases for further ones and UDP packet loss ratio increases for all servers. These two results are proved by the M/D/1/K queue formulas for sojourn time and blocking probability. Also, UDP jitter rises for all servers. Finally, disjoint paths provide better performances than OSPF shortest paths.
Achref El Amri, Aref Meddeb
IWCMC2
2017 6LoWPAN multi-layered security protocol based on IEEE 802.15.4 security features
abstract
Security should be an integral part of IoT communication stack facing vulnerabilities imposed by protocol diversity. In this paper, we propose a new multilayer security protocol based on the security specifications of the IEEE 802.15.4 standard, operating at both the MAC and the 6LoWPAN adaptation layers in order to ensure all essential security aspects to broad public and industrial acceptance. Measurements demonstrate that this alternation between end-to-end and hop-by-hop security protects the entire network against internal and external attacks with minimum overhead, energy consumption, and delay; and a robust hardware implementation.
Ghada Glissa, Aref Meddeb
IWCMC2
2017 IEEE 802.15.4 security sublayer for OMNET++
abstract
Most network simulators do not support security features. In this paper, we introduce a new security module for OMNET++ that implements the IEEE 802.15.4 security suite. This module, developed using the C++ language, can simulate all devices and sensors that implement the IEEE 802.15.4 standard. The OMNET++ security module is also evaluated in terms of quality of services in the presence of physical hop attacks. Results show that our module is reliable and can safely be used by researchers.
Ghada Glissa, Aref Meddeb
IWCMC2
2017 Algorithm for Readers Arrangement without Collision in RFID Networks
abstract
Radio Frequency IDentification (RFID) was identified as one of the ten best technologies in the 21st century. This technology is frequently used in different sectors: industrial, agricultural and academic. In RFID networks, readers and tags communicate wirelessly through electromagnetic signals. Due to the optimized tag coverage, multiple readers must be deployed in the same working area, causing reader-to-reader or/and readerto- tag collisions. In addition, the RFID reader is characterized by a maximum number of tags that can read them and a maximum interrogation range. Then the problem of activating the RFID readers and adjusting their interrogation ranges in order to cover the maximum number of tags without collisions is one of hot spot researches in RFID networks. This problem is known as the Reader Coverage Collision Avoidance Arrangement (RCCAA) problem. In the literature, an algorithm called the Maximum-Weight-Independent-Set-Based Algorithm (MWISBA) was put forward to solve the RCCAA problem. In this algorithm, only the interrogation ranges of readers where adjusted. The interference range was not taken into account. Thus, a readerto- reader collision could occur if a reader interrogated a tag located in the overlap area of its interrogation area with the interference area of another reader. To fill in this gap, we propose an improvement of the MWISBA called the MWISBAII which is able to solve the RCCAA problem avoiding all types of collisions. The experimental results show the superiority of our algorithm compared with the state-of-the-art solutions.
Aref Meddeb, Atef Jaballah
PDCAT1
2016 A broadcast authentication scheme in IoT environments
abstract
Broadcast authentication has been widely investigated in the context of wireless sensor networks, Internet, RFIDs, and other scenarios. With the emergence of the Internet of Things that allows to connect different wireless technologies to provide services, broadcast authentication is crucial. Broadcast authentication aims to confirm that the sender of the message is the pretended source. In this direction, different state of the art proposals address this problem either by reducing the communication and overhead burden of security solutions, or by reducing the impact of attacks that aim to jeopordize the effectiveness of the service. In this paper, we propose an improved authentication scheme that is efficient for resource constrained devices. In particular, we shed the light into the security vulnerabilities of lightweight authentication mechanisms and their inability to tackle memory DoS attacks. Hence, we propose an improved scheme derived from the streamlined μTESLA, referred to as X-μTESLA. We demonstrate through our analytical and simulation results that X-μTESLA reduces communication overhead and yields a better performance in terms of energy consumption, memory overhead, and authentication delay than its previous counterparts.
Bacem Mbarek, Aref Meddeb, Wafa Ben Jaballah, Mohamed Mosbah 0001
AICCSA2
2016 A Secure Routing Protocol Based on RPL for Internet of Things
abstract
Data transportation and routing in Internet of Things (IoT) is a challenging issue where massive data collection and gathering are predictable. The Routing Protocol for Low- power and Lossy Networks (RPL) is one of the best candidates to ensure routing in 6LoWPAN networks. However, RPL is vulnerable to a number of attacks related to exchanged control messages. In this paper, we propose a new secure routing protocol based on RPL referred to as Secure-RPL (SRPL). The main aim of SRPL is to prevent misbehaving nodes from maliciously changing control message values such as the rank of a node that may disturb a network by creating a fake topology. We introduce the concept of rank threshold along with hash chain authentication technique to deal with internal attacks like sinkhole, black hole, selective forwarding attacks etc. Simulation results show that SRPL is robust and resistant to this kind of attacks based on malicious manipulation of RPL metrics.
Ghada Glissa, Abderrezak Rachedi, Aref Meddeb
GLOBECOM3
2016 Energy efficient security protocols for wireless sensor networks : SPINS vs TinySec
abstract
In wireless sensor networks (WSNs), Security is critical for many sensor network applications, such as military target tracking and security monitoring. In particular, providing authentication to small sensor nodes is challenging, due to the limited capabilities of sensor nodes in terms of computation, communication, memory storage, and energy supply. Therefore, the implementation of authentication techniques for wireless sensor networks generally using encryption algorithms such as Elliptic Curve Cryptography (ECC), DES and RSA have great challenges in WSNs. In this paper, we compare and analyze the most used authentication protocols proposed in literature, i.e. SPINS and TinySec, were analyzed and simulated using NS-2 simulator.
Bacem Mbarek, Aref Meddeb
ISNCC2
2016 Minimum energy multi-objective clustering model for Wireless Sensor Networks
abstract
Wireless Sensor Networks (WSNs) constitute a very dynamic research area. The constraints related to deployment, topology, and energy motivates much of the research activities related to the WSNs. In a network of thousands of sensor nodes, routing management and data exchange are expensive in terms of energy consumption and storage capacity. In fact, a sensor needs to store a lot of information to perform data routing. A lot of researchers have proposed clustering to minimize energy consumption by cutting the network into groups and routing captured information at different hierarchical levels. Clustering has been deeply investigated for energy savings in the WSNs. It has also the advantage of being an alternative to address scalability problems. However, building and maintaining a cluster structure requires an additional cost compared to flat networks. In this paper, we address the problem of maximizing the network lifetime by means of cluster formation and by assigning sensor nodes to cluster heads. We propose a multi-objective model for clustering that guarantees an optimal selection of cluster heads among sensor nodes with the highest residual energy while simultaneously minimizing the intra cluster distance. The numerical results demonstrate the effectiveness of our model compared to existing ones.
Manel Souissi, Aref Meddeb
IWCMC2
2016 DEAR: Delay and Energy Aware Routing In Wireless Sensor Networks
abstract
One of the critical issues in a Wireless Sensor Network (WSN) is the design of a proper routing protocol. While the requirement of low latency and low-energy consumption is getting more and more importance in emerging applications, the WSN should be capable of fulfilling its mission in a timely manner and without loss of energy. In this paper, we focus on multi-hop flat routing. A mathematical model for Delay and Energy Aware Routing (DEAR) is proposed. Our model aims to build a trade-off between energy consumption and delay. The goal is to find out a route from all sensor nodes to the base station, which has a comparably lower overall distance, with fewer data forwards. We define a multi-objective function for simultaneously minimizing the distance and minimizing the delay in forwarding. To demonstrate the effectiveness of DEAR, we compare it with the LeeMoon (Lee and Moon Model), the MHRM (Minimum Hop Routing Model), and the MTEM (Minimum Transmission Energy Model). the numerical results show that our model outperforms those models in terms of latency and energy consumption.
Manel Souissi, Aref Meddeb
IWCMC2
2016 A Survey on Intelligent MAC Layer Jamming Attacks and Countermeasures in WSNs
abstract
Security abides a tremendous key requirement in the context of Internet of Things (IoT). IoT connects multiple objects together through wired and wireless connections in the aim of enabling ubiquitous interaction where any components can communicate with each other without any constraint. One of the most important elements in the IoT concept is Wireless Sensor Network (WSN). Due to their unattended and shared nature of radio for communication, security becomes an important issue. Wireless sensor nodes are vulnerable to radio jamming. When the jammer has the ability to interpret data link layer protocols, it becomes as energy-efficient as legitimate nodes. This paper presents a comprehensive survey on different sophisticated jamming attacks based on MAC layer. Techniques used to defeat each one of the intelligent jammers are classified based on the knowledge capacity of MAC protocols rules. The concepts behind existing protocols, that are dedicated by design to defeat such type of jammers, are presented. We conclude by a recapitulative table summarizing jamming attacks and proposed MAC-based solutions, and highlight open research directions.
Taieb Hamza, Georges Kaddoum, Aref Meddeb, Georges Matar
VTC Fall3
2015 A secure authentication mechanism for resource constrained devices
abstract
The Internet of Things (IoT) is formed by smart objects and services to interact in real time, and that are deployed in various applications such as home monitoring, healthcare, and smart cities. However, security concerns should not be overlooked since an adversary could exploit the vulnerabilities in the design of some secure protocols. To this aim, in this paper we focus in particular on broadcast authentication in resource constrained devices. This security service is still in its infancy when devices are deployed in unattended environments. We propose a new authentication mechanism based on the state of the art protocol μTESLA, that aims to reduce the delay of forged packets in the receivers buffer, by efficiently computing the key disclosure delay. Then, we integrate this mechanism to two protocols of state of the art LEAP and LEAP++. Furthermore, we assess the feasibility of our solution with a thorough simulation study, taking into account the energy consumption, the delay of forged packets, and the authentication delay.
Bacem Mbarek, Aref Meddeb, Wafa Ben Jaballah, Mohamed Mosbah 0001
AICCSA2
2015 Integration of a robust watermark scheme in a high efficiency codec H.265/HEVC with capacity-quality-bitrate trade-off
abstract
Recently, new challenges are imposed to secure video broadcasting and sharing, and to guarantee confidentiality, integrity, copyright and traceability. In addition, due to the social media development, several new problems have emerged in users' privacy and security policy as identity theft, copyright infringement and unauthorized content sharing. The watermarking is a crucial way to assure safety objectives as it allows embedding an imperceptible mark in the digital video data. In this paper, we integrate two robust watermark schemes in a high efficiency codec HEVC, which can be easily implemented in the codec since they require only little extra computation. Experimental results demonstrate that our proposed scheme (named XY method) does not affect the video quality, nor escalate bitrate. Our digital watermarking system presents a trade-off between capacity, fidelity, bitrate and robustness parameters.
Mhamdi Mohamed, Faten Ben Abdallah, Lotfi Abdi, Aref Meddeb
MoMM4
2013 On building multiple spanning trees and VLAN assignment in metro ethernet networks
abstract
Abstract While most of today's research effort is being devoted to wireless technologies involving the tiniest and most sophisticated devices, Ethernet is evolving from a best effort, plug‐and‐play LAN technology, towards a carrier‐grade WAN technology. Most of the new Ethernet standards rely on spanning tree protocols (STP) such as Rapid STP (RSTP) and multiple STP (MSTP). RSTP offers faster convergence than the legacy STP but like its predecessor, it uses a single tree to carry all the traffic offered to the network, seriously impacting throughput and bandwidth usage. MSTP however supports multiple spanning tree instances but does not provide generic methods to build those instances. Moreover, MSTP does not provide efficient methods to map between spanning trees and virtual LANs (VLAN). Operators must manually provision this mapping which seriously affects network operation expenditures and network performance. In this paper, we introduce a multiple spanning tree generation algorithm (MSTGA) and a VLAN‐spanning tree mapping algorithm (VSTMA) aimed at helping operators leverage their networks, save bandwidth, and support service level agreements with their customers. These algorithms can be used to extend and/or work with MSTP. We show that MSTGA maximizes throughput while VSTMA minimizes bandwidth usage. We also show that combining edge‐disjoint spanning trees with VSTMA constitutes the best bandwidth/throughput tradeoff. © 2012 Wiley Periodicals, Inc. NETWORKS, 2013
Aref Meddeb
Networks1
2010 An efficient source authentication scheme in wireless sensor networks
abstract
Wireless sensor networks (WSN) are being widely deployed in military, healthcare and commercial environments. Since sensor networks pose unique challenges, traditional security methods, commonly used in enterprise networks, cannot be directly applied. In particular, broadcast source authentication is a critical security service in wireless sensor networks since it allows senders to broadcast messages to multiple receivers in a secure way. Public-key cryptography based solutions such as Elliptic Curve Cryptography (ECC) and Identity Based Cryptography (IBC) have been proposed but they all suffer from severe energy depletion attacks, resulting from a high computational and communication overheads. In this paper, we present a novel symmetric-key-based authentication scheme that exhibits low broadcast authentication overhead and thus avoiding the problem flaws inherent to the public key cryptography based schemes. Our scheme is built upon the integration of multi-level μTesla protocol, staggered authentication and the Bloom Filter. We show that our authentication scheme is very efficient in terms of energy consumption related to both computation and communication.
Wafa Ben Jaballah, Aref Meddeb, Habib Youssef
AICCSA2
2009 Optimal VPN design: The ILEC/CLEC dilemma
abstract
Layer 2 and layer 1 VPN services, ranging from simple leased lines to extending private LANs, are commonplace today. However, with the continuously growing economic difficulties, capital meltdown and telecommunication business turmoil, delivering those VPN services at the lowest cost or with the maximum revenue margin, while committing to Service Level Agreements (SLA), has become essential. We show that whether we tackle the optimal VPN design problem from an Incumbent Local Exchange Carrier (ILEC) standpoint or from a Competitive Local Exchange Carrier (CLEC) standpoint, we obtain contradictory rules. We show that by building Edge Disjoint VPN trees and splitting the traffic among them, the ILEC can achieve maximum throughput, revenue, and better network performance. On the other hand, by concentrating all the VPN traffic over a single tree, the CLEC can minimize the cost of leased bandwidth while meeting minimum SLA targets. We then propose two simple algorithms that can help carriers and service provides leverage their networks and increase their revenue margins while committing to tight SLAs with their customers.
Aref Meddeb, Abdelwahed Berguiga, Habib Youssef
ISCC1
2009 Benefits of a pure layer 2 security approach in Metro Ethernet
abstract
With the emergence of Metro Ethernet as a high speed and carrier grade technology across public networks, the support of Quality of Service (QoS) and Service Level Agreements (SLA) has become an essential feature of Ethernet. In such context, the issues of network security and data transfer delay are regaining significant importance. The IEEE has recently introduced the 802.1AE MACSec protocol which aims at providing hop by hop security but that does not guarantee end to end security across public networks. In order to provide end-to-end security, in general a higher layer security protocol such as IPSec would be required. In this paper we propose an enhancement to the MACSec protocol in order to maintain the advantages of providing security at layer 2 while assuring an end-to-end security; alleviating the need for higher layer security protocols. We show that our approach enhances network performance in terms of transfer delay and delay variation while providing security levels comparable to those delivered by the combination of IPSec and MACSec.
Aref Meddeb, Enis Elgueder, Issam Harrathi, Habib Youssef
ISCC1
2009 Building cost effective lower layer VPNs: The ILEC/CLEC paradox
abstract
Layer 2 and layer 1 VPN services, ranging from simple leased lines to extending private LANs, are commonplace today. With the continuously growing economic difficulties, capital meltdown and telecommunication business turmoil, delivering those VPN services at the lowest cost or with the maximum revenue margin, while committing to service level agreements (SLA), has become essential. We show that whether we tackle the VPN design problem from an incumbent local exchange carrier (ILEC) standpoint or from a competitive local exchange carrier (CLEC) standpoint, we obtain contradictory rules. We show that by building edge disjoint VPN trees and splitting the traffic among them, the ILEC can achieve maximum throughput, revenue, and better network performance. On the other hand, by concentrating all the VPN traffic over a single tree, the CLEC can minimize the cost of leased bandwidth while meeting minimum SLA targets. We then propose two simple algorithms that can help carriers and service provides, respectively, leverage their networks and increase their revenue margins while committing to tight SLAs with their customers.
Aref Meddeb, Abdelwahed Berguiga, Habib Youssef
LCN1
2008 Smart Spanning Tree Bridging for Carrier Ethernets
abstract
Carrier Ethernet WAN transport services are taking off rapidly and the simplicity, ubiquity, and plug-and-play features of Ethernet are some key success factors. Originally, these transport services assumed the use of VLANs and spanning tree protocols within provider bridge (PB) and provider backbone bridge (PBB) networks. Because the existing spanning tree protocols (STP, RSTP, and MSTP) were deemed inadequate for carrier networks, very recently, a new class of shortest path routing solutions have been introduced that avoid the use of spanning tree protocols in the core namely, shortest path bridging (SPB) and shortest path backbone bridging (SPBB). As a proof of concept, this paper aims at illustrating that we can still use spanning trees in carrier Ethernets provided that the tree generation and VLAN-spanning-tree mapping are performed adequately. We call our solution smart spanning tree bridging (SSTB). SSTB can be used to enhance the 802.1s MSTP, without requiring significant changes in the current Ethernet equipment. Using very simple but yet realistic numerical examples, we show that SSTB yield near optimal bandwidth and link usage. We also show that SSTB outperform SPB in terms of service delivery, frame loss and jitter, while being comparable in terms of bandwidth usage and latency.
Aref Meddeb
GLOBECOM1
2008 Smart Spanning Tree Bridging for Metro Ethernets
abstract
Metro Ethernet is taking off rapidly as a WAN service and the simplicity, ubiquity, and plug-and-play features of Ethernet are some key success factors. The original bridging methods assumed the use of VLANs and spanning tree protocols within provider bridge (PB) and provider backbone bridge (PBB) networks. Because of the inadequacy of the existing spanning tree protocols to support carrier network requirements, very recently, a new class of shortest path routing solutions have been introduced that avoid the use of spanning tree protocols in the core namely, shortest path bridging (SPB). This paper aims at illustrating that we can still use spanning trees in metro ethernet provided that the tree generation and VLAN-spanning-tree mapping are performed adequately. We call our solution smart spanning tree bridging (SSTB). SSTB can be used to enhance the 802.1s MSTP, without requiring significant changes in the current Ethernet equipment. Using very simple but yet realistic numerical examples, we show that SSTB yields near optimal bandwidth and link usage. We also show that SSTB outperforms SPB in terms of service delivery, frame loss and jitter, while being comparable in terms of bandwidth usage and latency. Further, SSTB requires only a couple of spanning tree instances, significantly reducing processing and complexity of bridged networks.
Aref Meddeb
LCN1
2006 Multiple Spanning Tree Generation and Mapping Algorithms for Carrier Class Ethernets
abstract
Ethernet is evolving from a plug-and-play LAN technology towards a carrier grade WAN technology. In order to support Service Level Agreements (SLA) over Public Ethernets, extensions to STP include RSTP and MSTP. RSTP offers faster convergence than STP but uses a single tree for the entire network. In order to achieve a better utilization of the network links, MSTP supports multiple spanning trees, one tree per VLAN group. However, MSTP does not provide efficient methods to build those spanning trees. Furthermore, MSTP does not provide methods to perform efficient VLAN-Spanning-Tree Mapping. Operators must manually provision this mapping which might seriously impact OPEX and network performance. In this paper, we propose very simple and yet easy to use spanning tree generation and mapping algorithms; which can be used to extend and/or work with the 802.1s MSTP. We show that these algorithms yield optimal bandwidth utilization and enhanced network throughput compared to existing methods.
Aref Meddeb
GLOBECOM1
2004 Minimum cost optoelectronic networks: the optics/electronics tradeoff
abstract
A design model for optoelectronic networks based on DWDM technology is proposed. We give mathematical formulations for the logical layer design problem and for the wavelength assignment and routing problem. We study the tradeoff between optical cross-connects and electronic muxes that should be deployed in the various PoPs in order to minimize the cost of the network. We show that cost savings can he significant when we use both electronic muxes and optical cross-connects compared to the all-optical solution. We also show that the savings increase considerably with the traffic volume.
Aref Meddeb
ICC1
2004 Benefits of multicast traffic split routing in packet switched networks
abstract
We propose a simple multicast traffic split routing for packet switched networks (Internet). We propose a mathematical model that maximizes the reward generated by successfully forwarding packets from source to destinations. Using this model, we show that in order to reduce packet loss, while keeping the delay bounded: 1) trees should be as small as possible (typically spanning trees) and 2) trees should be as disjoint as possible. We also show that these two routing rules are independent of the traffic forecast which makes them of practical interest. We then propose a simple traffic split routing algorithm based on these two rules. Numerical results show that traffic split routing outperforms shortest path routing in terms of packet loss while being comparable in terms of queuing delay.
Aref Meddeb
ICC1
2002 The impact of point-to-multipoint traffic concentration on multirate networks design
abstract
We consider the problem of multirate network design with point-to-multipoint communications. We give a mathematical formulation for this problem. Using approximations, we show that traffic concentration on a small number of links significantly reduces the cost of the network. We then propose a heuristic based on the traffic concentration principle to solve the network design problem approximately. Because this heuristic no longer requires advanced knowledge of demand matrices, we explain how it can be used as the basis for real-time design procedures. By means of numerical results, we show that this heuristic yields nearly optimal solutions.
Aref Meddeb, André Girard, Catherine Rosenberg
IEEE/ACM Trans. Netw.1