VLDB 2026 Research / reviewers in the wild / expert
Georgios Mantas
dblp:48/10015
· DBLP profile ↗
29ranked-venue papers
1as first author
7since 2021 · last 2023
0000-0002-8074-0417ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 11 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 since 2021Systems, architecture and hardware · 3 · 2 since 2021Security and privacy · 3 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Outlier Detection for Risk-Based User Authentication on Mobile DevicesabstractMobile user authentication is the primary means of verifying the claimed identity of a user before granting access to resources on a mobile device. Common user authentication methods include passwords and biometrics. Despite the fact that passwords have been the most popular user authentication method for several decades, recent research suggests that they are no longer secure or convenient for mobile users due to several limitations that compromise both device security and usability. Biometric-based user authentication, on the other hand, is gaining popularity because it appears to strike a balance between security and usability. Such methods rely on human physical traits (physiological biometrics) or user involuntary actions (behavioral biometrics) for authentication. Risk-based user authentication using behavioral biometrics is particularly promising for mobile user authentication enhancing mobile authentication security while maintaining usability. In this context, we present an overview of mobile user authentication and discuss risk-based user authentication for mobile devices as a suitable approach to deal with the security vs. usability challenge. Afterwards, we test and evaluate a set of outlier detection algorithms for risk estimation in order to identify the most suitable ones for risk-based user authentication on mobile devices in terms of their accuracy and efficiency. Maria Papaioannou, Georgios Zachos, Georgios Mantas, Ismael Essop, Firooz B. Saghezchi, Jonathan Rodriguez 0001 |
GLOBECOM | 3 |
| 2023 | Secure Multi-Party Computation-Based Privacy-Preserving Authentication for Smart CitiesabstractThe increasing concern for identity confidentiality in the Smart City scenario has fostered research on privacy-preserving authentication based on pseudonymization. Pseudonym systems enable citizens to generate pseudo-identities and establish unlinkable anonymous accounts in cloud service providers. The citizen's identity is concealed, and his/her different anonymous accounts cannot be linked to each other. Unfortunately, current pseudonym systems require a trusted certification authority (CA) to issue the cryptographic components (e.g., credentials, secret keys, or pseudonyms) to citizens. This CA, generally a Smart City governmental entity, has the capability to grant or revoke privacy rights at will, hence posing a serious threat in case of corruption. Additionally, if the pseudonym system enables de-anonymization of misusers, a corrupted CA can jeopardize the citizens’ privacy. This paper presents a novel approach to construct a pseudonym system without a trusted issuer. The CA is emulated by a set of Smart City service providers by means of secure multi-party computation (MPC), which circumvents the requirement of assuming an honest CA. The paper provides a full description of the system, which integrates an MPC protocol and a pseudonym-based signature scheme. The system has been implemented and tested. Victor Sucasas, Abdelrahaman Aly, Georgios Mantas, Jonathan Rodriguez 0001, Najwa Aaraj |
IEEE Trans. Cloud Comput. | 3 |
| 2023 | Attribute-Based Pseudonymity for Privacy-Preserving Authentication in Cloud ServicesabstractAttribute-based authentication is considered a cornerstone component to achieve scalable fine-grained access control in the fast growing market of cloud-based services. Unfortunately, it also poses a privacy concern. User’s attributes should not be linked to the users’ identity and spread across different organizations. To tackle this issue, several solutions have been proposed such as Privacy Attribute-Based Credentials (Privacy-ABCs), which support pseudonym-based authentication with embedded attributes. Privacy-ABCs allow users to establish anonymous accounts with service providers while hiding the identity of the user under a pseudonym. However, Privacy-ABCs require the selective disclosure of the attribute values towards service providers. Other schemes such as Attribute-Based Signatures (ABS) and mesh signatures do not require the disclosure of attributes; unfortunately, these schemes do not cater for pseudonym generation in their construction, and hence cannot be used to establish anonymous accounts. In this article, we propose a pseudonym-based signature scheme that enables unlinkable pseudonym self-generation with embedded attributes, similarly to Privacy-ABCs, and integrates a secret sharing scheme in a similar fashion to ABS and mesh signature schemes for attribute verification. Our proposed scheme also provides verifiable delegation, enabling users to share attributes according to the service providers’ policies. Victor Sucasas, Georgios Mantas, Maria Papaioannou, Jonathan Rodriguez 0001 |
IEEE Trans. Cloud Comput. | 2 |
| 2023 | DECENT: Decentralized and Efficient Key Management to Secure Communication in Dense and Dynamic EnvironmentsabstractIntelligent Transportation Systems (ITS), one aspect of the Smart City paradigm, aim to improve the efficiency, convenience, and safety of travelers. The integration of (vehicular) communication technologies allows communication between the on-board communication units (OBUs) of vehicles, roadside units (RSUs), and vulnerable road users (VRUs), and contribute to the efficacy of ITS applications. However, these additional sources of information must be reliable and accurate. Security primitives such as confidentiality, integrity, and authenticity are required, but only achievable when supported with a suitable cryptographic key management scheme. This paper presents the design of a decentralized and efficient key management scheme, abbreviated as the DECENT scheme. This scheme provides secure multi-hop communication in dense and dynamic network environments while functioning in a self-organized manner. Through threshold secret sharing techniques, network nodes act as a distributed trusted third party (TTP) such that a threshold number of nodes can collaborate to execute key management functions. These functions include decentralized node admission and key updating. Novelties include (i) the unique self-healing characteristic, meaning that DECENT is capable of independently recovering from network compromise, and (ii) guidelines for choosing an appropriate security threshold in any deployment scenario which maximizes the level of security while simultaneously guaranteeing that decentralized key management services can be provided. Marcus de Ree, Georgios Mantas, Jonathan Rodriguez 0001, Ifiok E. Otung |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2022 | Novelty Detection for Risk-based User Authentication on Mobile DevicesabstractUser authentication acts as the first line of defense verifying the identity of a mobile user, often as a prerequisite to allow access to resources in a mobile device. For several decades, user authentication was based on the “something the user knows”, known also as knowledge-based user authentication. Recent studies state that although knowledge-based user authentication has been the most popular for authenticating an individual, nowadays it is no more considered secure and convenient for the mobile user as it is imposing several limitations. These limitations stress the need for the development and implementation of more secure and usable user authentication methods. Toward this direction, user authentication based on the “something the user is” has caught the attention. This category includes authentication methods which make use of human physical characteristics (also referred to as physiological biometrics), or involuntary actions (also referred to as behavioral biometrics). In particular, risk-based user authentication based on behavioral biometrics appears to have the potential to increase mobile authentication security without sacrificing usability. In this context, we, firstly, present an overview of user authentication on mobile devices and discuss risk-based user authentication for mobile devices as a suitable approach to deal with the security vs. usability challenge. Afterwards, a set of novelty detection algorithms for risk estimation is tested and evaluated to identify the most appropriate ones for risk-based user authentication on mobile devices. Maria Papaioannou, Georgios Zachos, Georgios Mantas, Jonathan Rodriguez 0001 |
GLOBECOM | 3 |
| 2022 | A Cryptographic Perspective to Achieve Practical Physical Layer SecurityabstractCommunications, wired and wireless, have integrated various cryptographic techniques to ensure privacy and counter surveillance. These techniques have been integrated in most of the network layers, except for the physical layer. This physical layer has, thus far, dealt with schemes such as source coding, channel coding, and (de)modulation, to enable the transmission of data in a reliable and efficient manner. The emergence of physical layer security extends the functionalities at the physical layer to include secure communication, aiming at the transmission of a signal that can only be correctly retrieved by the intended receiver. Therefore, the goals of physical layer security align with cryptographic schemes utilized at the other network layers. From the extensive study of physical layer security schemes, we have observed that there is a knowledge gap regarding certain security principles practiced by cryptographers and the experts within physical layer security, causing many physical layer security schemes to be impractical for standardization and the wide-scale integration into information and communication technologies. This paper describes a variety of security principles and concepts, practiced by cryptographers, and of importance to physical layer security experts. We aim to raise the awareness of these security principles and concepts to experts within the field of physical layer security to improve the practicality, standardization, and integration potential of the design of future physical layer security schemes. Marcus de Ree, Georgios Mantas, Jonathan Rodriguez 0001 |
GLOBECOM | 2 |
| 2021 | DISTANT: DIStributed Trusted Authority-based key managemeNT for beyond 5G wireless mobile small cells
Marcus de Ree, Georgios Mantas, Jonathan Rodriguez 0001, Ifiok E. Otung, Christos V. Verikoukis |
Comput. Commun. | 2 |
| 2020 | An Autonomous Host-Based Intrusion Detection System for Android Mobile Devices
José Carlos Ribeiro, Firooz B. Saghezchi, Georgios Mantas, Jonathan Rodriguez 0001, Simon J. Shepherd, Raed A. Abd-Alhameed |
Mob. Networks Appl. | 3 |
| 2020 | Editorial: Security and Privacy Protection for Mobile Applications and Platforms
Victor Sucasas, Georgios Mantas, Saud Althunibat, José-Fernán Martínez |
Mob. Networks Appl. | 2 |
| 2020 | A Signature Scheme with Unlinkable-yet-Accountable Pseudonymity for Privacy-Preserving CrowdsensingabstractCrowdsensing requires scalable privacy-preserving authentication that allows users to send anonymously sensing reports, while enabling eventual anonymity revocation in case of user misbehavior. Previous research efforts already provide efficient mechanisms that enable conditional privacy through pseudonym systems, either based on Public Key Infrastructure (PKI) or Group Signature (GS) schemes. However, previous schemes do not enable users to self-generate an unlimited number of pseudonyms per user to enable users to participate in diverse sensing tasks simultaneously, while preventing the users from participating in the same task under different pseudonyms, which is referred to as sybil attack. This paper addresses this issue by providing a scalable privacy-preserving authentication solution for crowdsensing, based on a novel pseudonym-based signature scheme that enables unlinkable-yet-accountable pseudonymity. The paper provides a detailed description of the proposed scheme, the security analysis, the performance evaluation, and details of how it is implemented and integrated into a real crowdsensing platform. Victor Sucasas, Georgios Mantas, Joaquim Bastos, Francisco Damião, Jonathan Rodriguez 0001 |
IEEE Trans. Mob. Comput. | 2 |
| 2019 | A Lightweight Authentication Mechanism for M2M Communications in Industrial IoT EnvironmentabstractIn the emerging industrial Internet of Things (IIoT) era, machine-to-machine (M2M) communication technology is considered as a key underlying technology for building IIoT environments, where devices (e.g., sensors, actuators, and gateways) are enabled to exchange information with each other in an autonomous way without human intervention. However, most of the existing M2M protocols that can be also used in the IIoT domain provide security mechanisms based on asymmetric cryptography resulting in high computational cost. As a consequence, the resource-constrained IoT devices are not able to support them appropriately and thus, many security issues arise for the IIoT environment. Therefore, lightweight security mechanisms are required for M2M communications in IIoT in order to reach its full potential. As a step toward this direction, in this paper, we propose a lightweight authentication mechanism, based only on hash and XOR operations, for M2M communications in IIoT environment. The proposed mechanism is characterized by low computational cost, communication, and storage overhead, while achieving mutual authentication, session key agreement, device's identity confidentiality, and resistance against the following attacks: replay attack, man-in-the-middle attack, impersonation attack, and modification attack. Alireza Esfahani, Georgios Mantas, Rainer Matischek, Firooz B. Saghezchi, Jonathan Rodriguez 0001, Ani Bicaku, Silia Maksuti, Markus Tauber, Christoph Schmittner, Joaquim Bastos |
IEEE Internet Things J. | 2 |
| 2019 | A Novel Intrusion Detection and Prevention Scheme for Network Coding-Enabled Mobile Small CellsabstractNetwork coding (NC)-enabled mobile small cells are observed as a promising technology for fifth-generation (5G) networks that can cover the urban landscape by being set up on-demand at any place and at any time on any device. Nevertheless, despite the significant benefits that this technology brings to the 5G of mobile networks, major security issues arise due to the fact that NC-enabled mobile small cells are susceptible to pollution attacks; a severe security threat exploiting the inherent vulnerabilities of NC. Therefore, intrusion detection and prevention mechanisms to detect and mitigate pollution attacks are of utmost importance so that NC-enabled mobile small cells can reach their full potential. Thus, in this article, we propose for the first time, to the best of our knowledge, a novel intrusion detection and prevention scheme (IDPS) for NC-enabled mobile small cells. The proposed scheme is based on a null space-based homomorphic message authentication code (MAC) scheme that allows detection of pollution attacks and takes proper risk mitigation actions when an intrusive incident is detected. The proposed scheme has been implemented in Kodo and its performance has been evaluated in terms of computational overhead. Reza Parsamehr, Alireza Esfahani, Georgios Mantas, Ayman Radwan, Shahid Mumtaz, Jonathan Rodriguez 0001, José-Fernán Martínez |
IEEE Trans. Comput. Soc. Syst. | 3 |
| 2018 | Software-Defined Networking for Ubiquitous Healthcare Service Delivery
Foteini Andriopoulou, Konstantinos Birkos, Georgios Mantas, Dimitrios K. Lymberopoulos |
BROADNETS | 3 |
| 2018 | Security Framework for the Semiconductor Supply Chain Environment
Alireza Esfahani, Georgios Mantas, Mariana Barcelos, Firooz B. Saghezchi, Victor Sucasas, Joaquim Bastos, Jonathan Rodriguez 0001 |
BROADNETS | 2 |
| 2018 | Profile Management System in Ubiquitous Healthcare Cloud Computing Environment
Evy I. Karavatselou, Maria-Anna Fengou, Georgios Mantas, Dimitrios K. Lymberopoulos |
BROADNETS | 3 |
| 2018 | Security Threats in Network Coding-Enabled Mobile Small Cells
Reza Parsamehr, Georgios Mantas, Ayman Radwan, Jonathan Rodriguez 0001, José-Fernán Martínez |
BROADNETS | 2 |
| 2018 | Key Management for Secure Network Coding-Enabled Mobile Small Cells
Marcus de Ree, Georgios Mantas, Ayman Radwan, Jonathan Rodriguez 0001, Ifiok E. Otung |
BROADNETS | 2 |
| 2018 | Towards an Autonomous Host-Based Intrusion Detection System for Android Mobile Devices
José Carlos Ribeiro, Georgios Mantas, Firooz B. Saghezchi, Jonathan Rodriguez 0001, Simon J. Shepherd, Raed A. Abd-Alhameed |
BROADNETS | 2 |
| 2018 | Machine Learning to Automate Network Segregation for Enhanced Security in Industry 4.0
Firooz B. Saghezchi, Georgios Mantas, José Carlos Ribeiro, Alireza Esfahani, Hassan Alizadeh, Joaquim Bastos, Jonathan Rodriguez 0001 |
BROADNETS | 2 |
| 2018 | A privacy-enhanced OAuth 2.0 based protocol for Smart City mobile applicationsabstractIn the forthcoming Smart City scenario, Service Providers will require users to authenticate themselves and authorize their mobile applications to access their remote accounts. In this scenario, OAuth 2.0 has been widely adopted as a de facto authentication and authorization protocol. However, the current OAuth 2.0 protocol specification does not consider the user privacy issue and presents several vulnerabilities that can jeopardize users’ privacy rights. Therefore, in this paper we propose an OAuth 2.0 based protocol for Smart City mobile applications that addresses the user privacy issue by integrating a pseudonym-based signature scheme and a signature delegation scheme into the OAuth 2.0 protocol flow. The proposed solution allows users to self-generate user-specific and app-specific pseudonyms on-demand and ensure privacy-enhanced user authentication at the Service Provider side. The proposed protocol has been validated with Proverif and its performance has been evaluated in terms of time and space complexity. Results show that the proposed protocol can provide users with efficient and effective means to authenticate towards service providers while preventing user tracking and impersonation from malicious entities located in the network side or in the users’ mobile device. Victor Sucasas, Georgios Mantas, Saud Althunibat, Leonardo Oliveira, Angelos Antonopoulos 0001, Ifiok E. Otung, Jonathan Rodriguez 0001 |
Comput. Secur. | 2 |
| 2018 | Physical-layer entity authentication scheme for mobile MIMO systemsabstractExploiting physical layer in achieving different security aspects in wireless communications has been widely encouraged. In this work, the authors propose an entity authentication scheme for mobile devices with multiple antennas, which is purely based on physical layer parameters. According to the proposed scheme, in order to authenticate a device, a number of predefined authentication signals should be detected at the receive antennas on the authenticator side. The transmitted signals are designed based on the instantaneous channel responses in order to deliver the authentication signals to the receiver. The proposed scheme works efficiently even for mobile users, which is considered a significant improvement over previous related works. Mathematical analysis of the different involved factors along with sufficient simulations show the high performance of the proposed authentication scheme. Saud Althunibat, Victor Sucasas, Georgios Mantas, Jonathan Rodriguez 0001 |
IET Commun. | 3 |
| 2017 | Towards a Hybrid Intrusion Detection System for Android-based PPDR terminalsabstractMobile devices are used for communication and for tasks that are sensitive and subject to tampering. Indeed, attacks can be performed on the users' devices without user awareness, this represents additional risk in mission critical scenarios, such as Public Protection and Disaster Relief (PPDR). Intrusion Detection Systems are important for scenarios where information leakage is of crucial importance, since they allow to detect possible attacks to information assets (e.g., installation of malware), or can even compromise the security of PPDR personnel. HyIDS is an Hybrid IDS for Android and supporting the stringent security requirements of PPDR, by comprising agents that continuously monitor mobile device and periodically transmit the data to an analysis framework at the Command Control Center (CCC). The data collection retrieves resource usage metrics for each installed application such as CPU, memory usage, and incoming and outgoing network traffic. At the CCC, the HyIDS employs Machine Learning techniques to identify patterns that are consistent with malware signatures based on the data collected from the applications. The HyIDS's evaluation results demonstrate that the proposed solution has low impact on the mobile device in terms of battery consumption and CPU/memory usage. Pedro Borges, Bruno Sousa, Firooz B. Saghezchi, Georgios Mantas, José Carlos Ribeiro, Jonathan Rodriguez 0001, Luís Cordeiro, Paulo Simões 0001 |
IM | 5 |
| 2017 | Towards trustworthy end-to-end communication in industry 4.0abstractIndustry 4.0 considers integration of IT and control systems with physical objects, software, sensors and connectivity in order to optimize manufacturing processes. It provides advanced functionalities in control and communication for an infrastructure that handles multiple tasks in various locations automatically. Automatic actions require information from trustworthy sources. Thus, this work is focused on how to ensure trustworthy communication from the edge devices to the backend infrastructure. We derive a meta-model based on RAMI 4.0, which is used to describe an end-to-end communication use case for an Industry 4.0 application scenario and to identify dependabilities in case of security challenges. Furthermore, we evaluate secure messaging protocols and the integration of Trusted Platform Module (TPM) as a root of trust for dataexchange. We define a set of representative measurable indicator points based on existing standards and use them for automated dependability detection within the whole system. Ani Bicaku, Silia Maksuti, Silke Palkovits-Rauter, Markus Tauber, Rainer Matischek, Christoph Schmittner, Georgios Mantas, Mario Thron, Jerker Delsing |
INDIN | 7 |
| 2017 | Towards a secure network architecture for smart grids in 5G eraabstractSmart grid introduces a wealth of promising applications for upcoming fifth-generation mobile networks (5G), enabling households and utility companies to establish a two-way digital communications dialogue, which can benefit both of them. The utility can monitor real-time consumption of end users and take proper measures (e.g., real-time pricing) to shape their consumption profile or to plan enough supply to meet the foreseen demand. On the other hand, a smart home can receive real-time electricity prices and adjust its consumption to minimize its daily electricity expenditure, while meeting the energy need and the satisfaction level of the dwellers. Smart Home applications for smart phones are also a promising use case, where users can remotely control their appliances, while they are away at work or on their ways home. Although these emerging services can evidently boost the efficiency of the market and the satisfaction of the consumers, they may also introduce new attack surfaces making the grid vulnerable to financial losses or even physical damages. In this paper, we propose an architecture to secure smart grid communications incorporating an intrusion detection system, composed of distributed components collaborating with each other to detect price integrity or load alteration attacks in different segments of an advanced metering infrastructure. Firooz B. Saghezchi, Georgios Mantas, José Carlos Ribeiro, Mohammed Al-Rawi, Shahid Mumtaz, Jonathan Rodriguez 0001 |
IWCMC | 2 |
| 2016 | An OAuth2-based protocol with strong user privacy preservation for smart city mobile e-Health appsabstractIn the context of the Smart City concept, mobile e-Health applications can play a pivotal role towards the improvement of citizens' quality of life, since they can enable citizens to access personalized e-Health services, without limitations on time and location. However, accessing personalized e-Health services through citizens' mobile e-Health applications, running on their mobile devices, raises many privacy issues in terms of citizens' identity and location. These privacy issues should be addressed so that citizens, concerned about privacy leakage, will embrace Smart City mobile e-Health applications and reap their benefits. Hence, in this paper we propose an OAuth2-based protocol with strong user privacy preservation that addresses these privacy issues. Our proposed protocol follows the OAuth2 protocol flow and integrates a pseudonym-based signature scheme and a delegation signature scheme into the user authentication phase of the OAuth2 protocol. The proposed protocol enables citizens authentication towards the servers providing personalized e-Health services, while preserving their privacy from malicious mobile applications and/or eavesdroppers. Moreover, the proposed protocol does not require to store sensitive information in the citizens' mobile devices. Victor Sucasas, Georgios Mantas, Ayman Radwan, Jonathan Rodriguez 0001 |
ICC | 2 |
| 2016 | An autonomous privacy-preserving authentication scheme for intelligent transportation systems
Victor Sucasas, Georgios Mantas, Firooz B. Saghezchi, Ayman Radwan, Jonathan Rodriguez 0001 |
Comput. Secur. | 2 |
| 2015 | Application-layer denial of service attacks: taxonomy and surveyabstractThe recent escalation of application-layer denial of service (DoS) attacks has attracted a significant interest of the security research community. Since application-layer DoS attacks usually do not manifest themselves at the network level, they avoid traditional network-layer-based detection. Therefore, the security community has focused on specialised application-layer DoS attacks detection and mitigation mechanisms. However, the deployment of reliable and efficient defence mechanisms against these attacks requires the comprehensive understanding of the existing application-layer DoS attacks supported by a unified terminology. Thus, in this paper we address this issue and devise a taxonomy of application-layer DoS attacks. By devising the proposed taxonomy, we intend to give researchers a better understanding of these attacks and provide a foundation for organising research efforts within this specific field. Georgios Mantas, Natalia Stakhanova, Hugo Gonzalez, Hossein Hadian Jazi, Ali A. Ghorbani 0001 |
Int. J. Inf. Comput. Secur. | 1 |
| 2013 | A profile-based Trust Management scheme for Ubiquitous Healthcare environmentabstractUbiquitous Healthcare environment materializes the patient-centric paradigm providing healthcare services without spatial and temporal limitations. However, the nature of Ubiquitous Healthcare services requiring exchange of sensitive personal data raises trust issues. In this paper, we propose a profile-based Trust Management scheme that enables the patient to select the most trustworthy Healthcare Provider in a Ubiquitous Healthcare environment. Furthermore, we propose an extended User Profile structure integrating trust-related information in order to enhance the functionality of the proposed Trust Management scheme. Georgia N. Athanasiou, Georgios Mantas, Maria-Anna Fengou, Dimitrios K. Lymberopoulos |
BIBE | 2 |
| 2013 | A New Framework Architecture for Next Generation e-Health ServicesabstractThe challenge for fast and low-cost deployment of ubiquitous personalized e-Health services has prompted us to propose a new framework architecture for such services. We have studied the operational features and the environment of e-Health services and we led to a framework structure that extends the ETSI/Parlay architecture, which is used for the deployment of standardized services over the next generation IP networks. We expanded the ETSI/Parlay architecture with new service capability features as well as sensor, profiling and security mechanisms. The proposed framework assists the seamless integration, within the e-Health service structure, of diverse facilities provided by both the underlying communication and computing infrastructure as well as the patient's bio and context sensor networks. Finally, we demonstrate the deployment of a tele-monitoring service in smart home environment based on the proposed framework architecture. Maria-Anna Fengou, Georgios Mantas, Dimitrios K. Lymberopoulos, Nikos Komninos, Spyros Fengos, Nikolaos Lazarou |
IEEE J. Biomed. Health Informatics | 2 |