VLDB 2026 Research / reviewers in the wild / expert
Oscar Esparza
dblp:40/6314
· DBLP profile ↗
35ranked-venue papers
7as first author
4since 2021 · last 2026
0000-0002-2593-0162ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 15 · 4 first-author · 4 since 2021Security and privacy · 11 · 1 first-authorDatabases, data management, data science and information retrieval · 4 · 2 first-authorArtificial intelligence and machine learning · 2 · 1 first-authorHuman-computer interaction and ubiquitous computing · 2Software engineering, systems software and programming languages · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | FileTrust: A blockchain-based auditable backup solution for IoT-driven environmentsabstractCritical Internet of Things (IoT) deployments in domains such as mining generate large volumes of data that multiple stakeholders rely on. Cloud-centric backup solutions offer limited transparency, concentrate control in one provider, and create single points of failure. We present FileTrust, a blockchain-based auditable backup framework that preserves integrity, confidentiality, availability, and auditability of IoT data in low-trust, multi-stakeholder environments. FileTrust combines an Information Dispersal Algorithm (IDA) with the InterPlanetary File System (IPFS) for distributed storage and uses blockchain and threshold cryptography to enforce access control. Its operation has three procedures: (i) data publishing, where data are dispersed via IDA, stored in IPFS, and referenced on-chain via content identifiers (CIDs); (ii) key establishment and CID protection, where shareholders run verifiable secret sharing (VSS)-based distributed key generation (DKG) to establish a threshold public key, and each CID is protected through a hybrid key-encapsulation mechanism and data-encapsulation mechanism (KEM-DEM) structure in which a fresh per-CID symmetric key encrypts the CID while threshold ElGamal (TElG) encapsulates that key before the resulting tuple is recorded on-chain; and (iii) data access, where shareholders perform threshold operations over the protected key material for authorized requesters, who recover plaintext CIDs, retrieve IPFS fragments, and reconstruct data using the IDA threshold. We formalize the system and threat model, implement FileTrust as Ethereum smart contracts, and evaluate gas cost and storage overhead. The results show that FileTrust provides verifiable, stakeholder-driven backup access without relying on a trusted cloud provider. Mohammadali Farahpoor, Mina Namazi, Miguel C. Soriano, Oscar Esparza |
Ad Hoc Networks | 4 |
| 2025 | NoRDEx: A decentralized optimistic non-repudiation protocol for data exchangesabstractThis article introduces the Non-Repudiable Data Exchange (NoRDEx) protocol, designed to ensure non-repudiation in data exchanges. Unlike traditional non-repudiation and fair exchange protocols, NoRDEx can be considered decentralized as it eliminates the need for a centralized Trusted Third Party (TTP) by using a Distributed Ledger Technology (DLT) to store cryptographic proofs without revealing the exchanged message. NoRDEx is an optimistic non-repudiation protocol, as it only uses the DLT in case of a dispute. The protocol has been implemented and tested in real-world environments, with performance assessments covering cost, overhead, and execution time. A formal security analysis using the Syverson Van Oorschot (SVO) logical model demonstrates NoRDEx’s ability to resolve disputes securely. Fernando Román-García, Juan Hernández-Serrano, Oscar Esparza |
J. Netw. Comput. Appl. | 3 |
| 2024 | Evaluation of TCP Congestion Control Algorithms with traffic control policies in a PEP-based geosynchronous satellite scenarioabstractMuch work has been done in recent years comparing TCP variants in many scenarios, including the satellite one. Some of these studies were carried out with the ns-2 and ns-3 simulators, which may give a good idea of the behavior of these TCP variants, although the results cannot be considered completely realistic. Some of the latest studies use virtualization to derive a variety of measures to test the suitability of Congestion Control Algorithms in a more realistic way. Such studies also take into account new variants of TCP, such as Google’s BBR. However, few of these works have evaluated the behavior of these variants in a scenario based on Performance Enhancing Proxies. Furthermore, no emphasis has been placed on those variants of TCP that try to maximize throughput and minimize delay, which is crucial in many services with low latency requirements. Our paper aims to fill this gap, offering a comparative assessment of the performance of these three TCP flavors: BBR, YeAH and CUBIC. We have created four different approaches to mix these TCP flavors with two traffic control techniques, including Active Queue Management (AQM) policies. To perform the testings, we have developed a TCP-Splitting satellite Emulation Framework (TSEF), a platform that allows us to evaluate the performance of TCP flavors on the forward channel of a geosynchronous satellite scenario based on Performance Enhancing Proxies (PEPs). According to our results, we can conclude that the application of AQM policies and ECN marks on aggressive TCP flavors like CUBIC is mandatory to maximize throughput and minimize delay. Oscar Esparza, Jorge Mata-Díaz, Juan J. Alins-Delgado |
Comput. Networks | 2 |
| 2024 | DA2Wa: A secure pairing protocol between a DApp and a wallet for the blockchain scenarioabstractWallet applications play a crucial role in securely storing users’ private keys needed to interact with the blockchain, while decentralized applications (DApps) take profit of blockchain technologies to create transparent, tamper-proof environments without the need for trust relationships. As DApps need private keys to interact with the blockchain, the secure interconnection of these applications is vital yet still challenging. This article introduces DA2Wa, a protocol designed to establish a secure pairing between a cryptocurrency wallet and a DApp, both of which run as isolated applications on the same machine. The protocol utilizes a six-character PIN exchange mechanism, delivering a security level equivalent to that of Bluetooth. To demonstrate the security of DA2Wa, we employ Tamarin Prover, a tool for symbolically modelling and analysing security protocols. Fernando Román-García, Juan Hernández-Serrano, Oscar Esparza |
Comput. Commun. | 3 |
| 2015 | Multipath TCP Architecture for Infotainment Multimedia Applications in Vehicular NetworksabstractThe large deployment of Internet resources has facilitated the accelerated development of Intelligent Transport Systems (ITS) including a large diversity of distributed applications such as non-safety infotainment vehicular applications. In vehicular networks, nodes can connect to Internet using Road Side Units (RSUs), but the complete deployment of RSUs along all the transport network seems unfeasible. So, we can take advantage of multihomed devices using complementary access network technologies, such as satellite networks, in order to maintain the connectivity. Several solutions have been implemented in order to take advantage of multihoming and multipath capabilities of mobile nodes. However, in dynamic network scenarios involving multipath communication channels, the QoS requirements of these applications is not always globally managed and guaranteed. Moreover, specific multimedia semantics of the transmitted data is not usually considered by the available transmission mechanisms and protocols. In this work, we present a Multipath TCP communication architecture that take full advantage of the intrinsic multimedia QoS semantics based in Deep Packet Inspection in order to self-manage the available resources and to provide a more compliant e2e transport service. Sergi Rene, Ernesto Exposito, Mathieu Gineste, Juan J. Alins-Delgado, Oscar Esparza |
VTC Spring | 5 |
| 2015 | A model for revocation forecasting in public-key infrastructures
Carlos Gañán, Jorge Mata-Díaz, Jose L. Muñoz, Oscar Esparza, Juan J. Alins-Delgado |
Knowl. Inf. Syst. | 4 |
| 2015 | EPA: An efficient and privacy-aware revocation mechanism for vehicular ad hoc networks
Carlos Gañán, Jose L. Muñoz, Oscar Esparza, Jorge Mata-Díaz, Juan J. Alins-Delgado |
Pervasive Mob. Comput. | 3 |
| 2014 | Certificate Revocation List Distribution System for the KAD NetworkabstractMany peer-to-peer (p2p) overlays require certain security services which could be provided through a Public Key Infrastructure. However, these infrastructures are bound up with a revocation system, such as Certificate Revocation Lists (CRLs). A system with a client/server structure, where a Certificate Authority plays a role of a central server, is prone to suffer from common problems of a single point of failure. If only one Authority has to distribute the whole CRL to all users, perhaps several millions in a structured p2p overlay, a bottleneck problem appears. Moreover, in these networks, users often have a set of pseudonyms that are bound to a certificate, which gives rise to two additional issues: issuing the CRL and assuring its freshness. On the one hand, the list size grows exponentially with the number of network users. On the other hand, these lists must be updated more frequently; otherwise the revocation data will not be fresh enough. To solve these problems, we propose a new distributed revocation system for the Kademlia network. Our system distributes CRLs using the overlay itself and, to not compromise the storage of nodes, lists are divided into segments. This mechanism improves the accessibility, increases the availability and guarantees the freshness of the revocation data. Juan Caubet, Carlos Gañán, Oscar Esparza, Jose L. Muñoz, Jorge Mata-Díaz, Juan J. Alins-Delgado |
Comput. J. | 3 |
| 2014 | RIAPPA: a Robust Identity Assignment Protocol for P2P overlaysabstractABSTRACT Peer‐to‐peer (P2P) overlay networks have been proposed to solve routing problems of big distributed infrastructures, even for Internet scale. But the research community has been questioning the security of these networks for years. Most prior work in security services was focused on trust and reputation systems, anonymity, and secure routing. However, the proper management of identities in overlays is an important prerequisite to provide most of these security services. In this paper, we propose a protocol to control the access to a P2P overlay and to assign identities in a secure way; all this preserving the anonymity of users. This protocol involves two trusted third parties (TTPs), thanks to which it is possible to preserve the users’ anonymity within the network without losing traceability. Users are authenticated by a TTP using real‐world digital certificates, they select their network identifier jointly with the other TTP, and finally, the two TTPs issue the internal certificate to them. The protocol also provides revocability and protection against Sybil attacks, Eclipse attacks, whitewashers, and so on. A detailed protocol description is presented, and a performance and security analysis of the protocol is also provided. Copyright © 2014 John Wiley & Sons, Ltd. Juan Caubet, Oscar Esparza, Jose L. Muñoz, Juan J. Alins-Delgado, Jorge Mata-Díaz |
Secur. Commun. Networks | 2 |
| 2013 | COACH: COllaborative certificate stAtus CHecking mechanism for VANETs
Carlos Gañán, Jose L. Muñoz, Oscar Esparza, Jorge Mata-Díaz, Juan Hernández-Serrano, Juan J. Alins-Delgado |
J. Netw. Comput. Appl. | 3 |
| 2013 | VSPLIT: A Cross-Layer Architecture for V2I TCP Services Over 802.11
Sergi Rene, Oscar Esparza, Juan J. Alins-Delgado, Jorge Mata-Díaz, Jose L. Muñoz |
Mob. Networks Appl. | 2 |
| 2012 | Impact of the Revocation Service in PKI Prices
Carlos Gañán, Jose L. Muñoz, Oscar Esparza, Jorge Mata-Díaz, Juan J. Alins-Delgado |
ICICS | 3 |
| 2012 | On the Self-similarity Nature of the Revocation Data
Carlos Gañán, Jorge Mata-Díaz, Jose L. Muñoz, Oscar Esparza, Juan J. Alins-Delgado |
ISC | 4 |
| 2012 | RAR: Risk Aware Revocation Mechanism for Vehicular NetworksabstractVehicular Ad Hoc Networks (VANETs) require some mechanism to authenticate messages, identify valid vehicles, and remove misbehaving ones. A Public Key Infrastructure (PKI) can provide this functionality using digital certificates. In PKI, key management and corresponding issuance and revocation of digital certificates is one of the key issues that have to be solved. The IEEE 1609.2 standard states that VANETs will rely on the use of certificate revocation lists (CRLs) to achieve revocation. In this paper, we analyze the problems of using CRLs in these type of networks. Moreover, we describe the Risk Aware Revocation (RAR) mechanism that improves the traditional use of CRLs. RAR takes advantage of the two distinct channel types in VANETs to increase the freshness of the revocation information. Moreover, RAR allows users to gauge the risk of operating in a VANET when using CRLs. Carlos Gañán, Jose L. Muñoz, Oscar Esparza, Jorge Mata-Díaz, Juan J. Alins-Delgado, Carlos Silva Cárdenas, Gumercindo Bartra-Gardini |
VTC Spring | 3 |
| 2012 | DECADE: Distributed Emergent Cooperation through ADaptive Evolution in mobile ad hoc networks
Marcela M. Mejia, Néstor M. Peña, Jose L. Muñoz, Oscar Esparza, Marco A. Alzate |
Ad Hoc Networks | 4 |
| 2012 | XPLIT: A cross-layer architecture for TCP services over DVB-S2/ETSI QoS BSM
Juan J. Alins-Delgado, Jorge Mata-Díaz, Jose L. Muñoz, Elizabeth Rendon-Morales, Oscar Esparza |
Comput. Networks | 5 |
| 2012 | Optimal tag suppression for privacy protection in the semantic Web
Javier Parra-Arnau, David Rebollo-Monedero, Jordi Forné, Jose L. Muñoz, Oscar Esparza |
Data Knowl. Eng. | 5 |
| 2012 | A Modeling of Certificate Revocation and Its Application to Synthesis of Revocation TracesabstractOne of the hardest tasks of a public key infrastructure (PKI) is to manage revocation. New communication paradigms push the revocation system to the limit and an accurate resource assessment is necessary before implementing a particular revocation distribution system. In this context, a precise modeling of certificate revocation is necessary. In this paper, we analyze empirical data from real certification authorities (CAs) to develop an accurate and rigorous model for certificate revocation. One of the key findings of our analysis is that the certificate revocation process is statistically self-similar. The proposed model is based on an autoregressive fractionally integrated moving average (ARFIMA) process. Then, using this model, we show how to build a synthetic revocation generator that can be used in simulations for resource assessment. Finally, we also show that our model produces synthetic revocation traces that are indistinguishable for practical purposes from those corresponding to actual revocations. Carlos Gañán, Jorge Mata-Díaz, Jose L. Muñoz, Juan Hernández-Serrano, Oscar Esparza, Juan J. Alins-Delgado |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2011 | A game theoretic trust model for on-line distributed evolution of cooperation inMANETs
Marcela M. Mejia, Néstor M. Peña, Jose L. Muñoz, Oscar Esparza, Marco A. Alzate |
J. Netw. Comput. Appl. | 4 |
| 2011 | An infrastructure for detecting and punishing malicious hosts using mobile agent watermarkingabstractAbstract Mobile agents are software entities consisting of code, data, and state that can migrate autonomously from host to host executing their code. In such scenario there are some security issues that must be considered. In particular, this paper deals with the protection of mobile agents against manipulation attacks performed by the host, which is one of the main security issues to solve in mobile agent systems. This paper introduces an infrastructure for mobile agent watermarking (MAW). MAW is a lightweight approach that can efficiently detect manipulation attacks performed by potentially malicious hosts that might seek to subvert the normal agent operation. MAW is the first proposal in the literature that adapts software watermarks to verify the execution integrity of an agent. The second contribution of this paper is a technique to punish a malicious host that performed a manipulation attack by using a trusted third party (TTP) called host revocation authority (HoRA). A proof‐of‐concept has also been developed and we present some performance evaluation results that demonstrate the usability of the proposed mechanisms. Copyright © 2010 John Wiley & Sons, Ltd. Oscar Esparza, Jose L. Muñoz, Joan Tomàs-Buliart, Miguel Soriano |
Wirel. Commun. Mob. Comput. | 1 |
| 2010 | RDSR-V. Reliable Dynamic Source Routing for video-streaming over mobile ad hoc networks
Jose L. Muñoz, Oscar Esparza, Mónica Aguilar-Igartua, Víctor Carrascal Frías, Jordi Forné |
Comput. Networks | 2 |
| 2010 | PREON: An efficient cascade revocation mechanism for delegation paths
M. Francisca Hinarejos, Jose L. Muñoz, Jordi Forné, Oscar Esparza |
Comput. Secur. | 4 |
| 2009 | A Mechanism to Avoid Collusion Attacks Based on Code Passing in Mobile Agent Systems
Marc Jaimez, Oscar Esparza, Jose L. Muñoz, Juan J. Alins-Delgado, Jorge Mata-Díaz |
WISTP | 2 |
| 2009 | PKIX Certificate Status in Hybrid MANETs
Jose L. Muñoz, Oscar Esparza, Carlos Gañán, Javier Parra-Arnau |
WISTP | 2 |
| 2006 | Secure brokerage mechanisms for mobile electronic commerce
Oscar Esparza, Jose L. Muñoz, Miguel Soriano, Jordi Forné |
Comput. Commun. | 1 |
| 2005 | Analysis of peer-to-peer distributed reputation schemesabstractPeer-to-peer systems consist of groups of nodes acting as clients and servers. These groups of nodes communicate directly among themselves through wide-area networks. Some of the benefits of fully distributed peer-to-peer systems are scalability, resource aggregation and interoperability without any administration cost or centralized infrastructure support. In this context, reputation schemes aid the service requesters to choose the proper resource provider and to prevent malicious behaviors. This paper analyzes reputation management in fully distributed peer-to-peer systems. This paper discusses the main issues that a reputation framework must address and analyzes the most representative distributed reputation systems. This paper also discusses the main advantages and drawbacks of each proposal in relation to peer-to-peer reputation system requirements Manuel Rodriguez-Perez, Oscar Esparza, Jose L. Muñoz |
CollaborateCom | 2 |
| 2005 | Efficient Certificate Revocation System Implementation: Huffman Merkle Hash Tree (HuffMHT)
Jose L. Muñoz, Jordi Forné, Oscar Esparza, Manel Rey |
TrustBus | 3 |
| 2004 | Punishing manipulation attacks in mobile agent systemsabstractMobile agents are software entities consisting of code, data and state that can migrate autonomously from host to host performing some actions on behalf of a user. Unfortunately, security issues restrict the use of mobile agents, despite the benefits. The protection of mobile agents against the attacks of malicious hosts is considered the most difficult security problem to solve in mobile agent systems. Previously, the mobile agent watermarking approach (MAW) was presented as a new attack detection technique to aid solving the problem of malicious hosts. That approach was based on embedding a fixed watermark into the mobile agent. Some improvements are now introduced to MAW. Instead of a fixed watermark, the origin host embeds a watermark that can change dynamically during execution. In each host, the marked code creates a data container where the watermark is transferred and the results are hidden. When the agent returns home, the origin host verifies the execution integrity by applying a set of integrity rules to the containers. The paper also explains how MAW can be used to punish malicious hosts by using a trusted third party, the host revocation authority. Oscar Esparza, Miguel Soriano, Jose L. Muñoz, Jordi Forné |
GLOBECOM | 1 |
| 2004 | Reducing the Communication Overhead of an Offline Revocation Dictionary
Jose L. Muñoz, Jordi Forné, Oscar Esparza, Josep Pegueroles 0001, Esteve Pallarès |
TrustBus | 3 |
| 2003 | Using OCSP to Secure Certificate-Using Transactions in M-commerce
Jose L. Muñoz, Jordi Forné, Oscar Esparza, Miguel Soriano |
ACNS | 3 |
| 2003 | Mobile Agent Watermarking and Fingerprinting: Tracing Malicious Hosts
Oscar Esparza, Marcel Fernandez, Miguel Soriano, Jose L. Muñoz, Jordi Forné |
DEXA | 1 |
| 2003 | Protocols for Malicious Host Revocation
Oscar Esparza, Miguel Soriano, Jose L. Muñoz, Jordi Forné |
ICICS | 1 |
| 2003 | Host Revocation Authority: A Way of Protecting Mobile Agents from Malicious Hosts
Oscar Esparza, Miguel Soriano, Jose L. Muñoz, Jordi Forné |
ICWE | 1 |
| 2003 | A protocol for detecting malicious hosts based on limiting the execution time of mobile agentsabstractMobile agents are software entities consisting of code and data that can migrate autonomously from host to host executing their code. Despite its benefits, security issues strongly restrict the use of code mobility. The protection of mobile agents against the attacks of malicious hosts is considered the most difficult security problem to solve in mobile agent systems. In O. Esparza et al. [2003] the authors introduced the idea of limiting the execution time in the hosts. Malicious hosts need time to analyze and modify an agent in order to take some profit. Controlling the execution time in the hosts permits detecting manipulation attacks performed by malicious hosts during the agents' execution. This paper presents a protocol for detecting malicious hosts based on the idea of execution time limiting. Oscar Esparza, Miguel Soriano, Jose L. Muñoz, Jordi Forné |
ISCC | 1 |
| 2003 | Implementation of an Efficient Authenticated Dictionary for Certificate RevocationabstractPublic key cryptography is widely used to provide the security services necessary to develop WEB applications. The PKI is the infrastructure that supports the public key cryptography and the revocation of certificate implies one of its major costs. The authors have developed a revocation system based on the data structures proposed by Naor and Nissim in their authenticated dictionary (AD). Our implementation is called ADMHT and in this paper we address some open issues that are necessary to implement such a system. Jose L. Muñoz, Jordi Forné, Oscar Esparza, Miguel Soriano |
ISCC | 3 |