Rui L. Aguiar

dblp:53/223 · also Rui Luis Andrade Aguiar · DBLP profile ↗
← Back
176ranked-venue papers
2as first author
40since 2021 · last 2026
0000-0003-0107-6253ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 96 · 2 first-author · 19 since 2021Artificial intelligence and machine learning · 19 · 6 since 2021Software engineering, systems software and programming languages · 19 · 4 since 2021Systems, architecture and hardware · 12 · 2 since 2021Security and privacy · 10Databases, data management, data science and information retrieval · 7 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 3 since 2021Theory of computation · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 PoliFlow: Inferring Control-Flow Policies from Serverless Workflows
Pedro Escaleira, Vitor A. Cunha, João Paulo Barraca, Diogo Gomes 0001, Rui L. Aguiar
CCGrid5
2026 Validating Sustainability in Open Source MANO: A Use Case for Maritime Port Video Analysis
abstract
Under scope of the EXIGENCE SNS JU project, this paper presents the design and tests on two carbon-aware orchestration mechanisms — service throttling and spatial (workload) shifting — built directly into ETSI's Open Source MANO (OSM) platform. They validate it on a real-world edge/cloud video pipeline (Automatic License Plate Recognition for maritime port monitoring), and show up to 47.3% reduction in daily operational carbon emissions without breaking service requirements.
Filipe Antão, Hao Ran Chi, Daniel Corujo, Rui L. Aguiar
NetSoft4
2026 A comprehensive approach for the onboarding, orchestration, and validation of network applications
abstract
The advent of 5G and Beyond 5G networks has propelled the development of innovative applications and services that harness network programmability, data from management and control interfaces, and the capabilities of network slicing. However, ensuring these applications function as intended and effectively utilize 5G/B5G capabilities remains a challenge, mainly due to their reliance on complex interactions with control plane Network Functions. This work addresses this issue by proposing a novel architecture to enhance the onboarding, orchestration, and validation of 5G/B5G-capable applications and services, while enabling the creation of application-tailored network slices. By integrating DevOps principles into the NFV ecosystem, the proposed architecture automates workflows for deployment, testing, and validation, while adhering to standardized onboarding models and continuous integration practices. Furthermore, we also address the realization of such architecture into a platform that supports extensive testing across multiple dimensions, including 5G readiness, security, performance, scalability, and availability. Besides introducing such a platform, this work also demonstrates its feasibility through the orchestration and validation of an automotive application that manages virtual On-Board Units within a 5G-enabled environment. The obtained results underscore the effectiveness of the proposed architecture, as well as the performance and scalability of the platform that materializes it. By integrating DevOps principles, our work aids in reducing deployment complexity, automating testing and validation, and enhancing the reliability of next-generation Network Applications, therefore accelerating their time-to-market.
Rafael Direito, Kostis Trantzas, Jorge Gallego-Madrid, Ana Hermosilla, Diogo Gomes 0001, Christos Tranoris, Rui L. Aguiar, Antonio F. Skarmeta, Spyros G. Denazis
Comput. Networks7
2026 Battery-Aware Dynamic Adaptive Low-Power Device Selection for IoT-Enabled FL Networks
abstract
The integration of Internet of Things (IoT) and Federated Learning (FL) marks a significant step towards pervasiveness, supported by distributed computational resources and enhanced by 5G advancements. However, the efficient and sustainable operation of IoT-enabled FL systems faces critical challenges, particularly in selecting devices that balance energy consumption and system performance. To address this, we propose the Battery-Aware Dynamic and Automated Device Selection (DADS) framework, a novel solution specifically designed for IoT-enabled FL environments. DADS introduces an innovative adaptive mechanism that dynamically adjusts optimization parameters, such as inertia weights and crossover/mutation rates, ensuring a seamless balance between exploration and exploitation. Unlike conventional optimization approaches, DADS employs uniquely developed Adaptive Particle Swarm Optimization (APSO) and Adaptive Genetic Algorithm (AGA) within a cohesive framework. This design enables DADS to respond to dynamic IoT network conditions, such as fluctuating battery levels and device capabilities, ensuring energy-efficient device selection while preserving robust performance. Through extensive performance analysis, DADS demonstrates its novelty by achieving a 20% reduction in energy consumption and a 30% improvement in FL training time compared to state-of-the-art methods. Moreover, DADS significantly enhances battery lifespan, reducing degradation by more than 50%, and optimizes communication efficiency, extending the operational sustainability of IoT devices. These results position DADS as a groundbreaking framework, setting a new benchmark for energy-aware and sustainable IoT-enabled FL systems.
Alaa AlZailaa, Hao Ran Chi, Ayman Radwan, Rui L. Aguiar
IEEE Trans. Mob. Comput.4
2025 Exploring Recommendations Attacks Through Blind Optimization
Julio Corona, Rafael Teixeira, Mário Antunes 0001, Rui L. Aguiar
DS4
2025 Impact of Resource Heterogeneity on MLOps Stages: A Computational Efficiency Study
Julio Corona, Mário Antunes 0001, Rui L. Aguiar
ICSOFT4
2025 Modeling and Predicting Machine Learning Performance
abstract
Modern Machine Learning (ML) models pose challenges such as long development cycles, high costs, and difficult model selection. Understanding how dataset properties influence performance in a model-agnostic and interpretable way remains limited. This work analyzes the relationship between dataset characteristics and model behavior across diverse algorithms, introducing symbolic regression models that transparently estimate accuracy from dataset features and simple model identifiers. Results show that features such as noisiness, redundancy, and class distribution consistently affect performance. A symbolic model using only dataset features achieved modest accuracy ($R^{2}=0.361$), while including model identification improved predictions ($R^{2}=0.534$). These findings provide interpretable insights into the data-model relationship, supporting preprocessing decisions (e.g., feature selection, class balancing) and informing meta-learning strategies for algorithm recommendation.
Julio Corona, Rafael Teixeira, Mário Antunes 0001, Rui L. Aguiar
ICTAI4
2025 Innovations in MEC Federation: Leveraging SDN for Enhanced Connectivity and Resource Optimization
abstract
Multi-Access Edge Computing (MEC) is a promising paradigm that brings computational capabilities closer to end-users, enabling low-latency and high-bandwidth applications. The federation of multiple MEC platforms has the potential to create a collaborative ecosystem, facilitating resource sharing and scalability. This paper addresses the benefits of exploring the synergies between Software-Defined Networking (SDN) and MEC federation deployments, aiming to enhance the network infrastructure’s overall performance, flexibility, and responsiveness. More concretely, this work explores the integration of MEC and SDN to address performance and resource utilization challenges in congested federated MEC environments, enabling seamless service migration between MEC nodes when resource constraints arise with results showing its ability to maintain service quality under congestion.
David Santos, Miguel Matos, Daniel Corujo, Rui L. Aguiar
LANMAN5
2025 Edge Traffic Steering Integrating CATS and 3GPP
abstract
This paper investigates the development of a solution for Edge Internet Traffic Steering (EITS), focusing on optimizing the performance of services at the network edge using Computing-Aware Traffic Steering (CATS) principles. Motivated by the increasing demand for low-latency connectivity, high bandwidth, resource availability, link redundancy, and efficient memory and CPU usage optimization, this research addresses the limitations of existing traffic steering approaches in meeting the static or dynamic requirements of edge services. The proposed solution leverages network and compute metrics to direct traffic to the most suitable service instance, enhancing overall performance through the use of OpenAirInterface 5G Core Network. The practical implementation of a video streaming use case demonstrated the efficacy of the solution.
David Santos, Jodionisio Muachifi, Daniel Corujo, Rui L. Aguiar
WCNC5
2025 Understanding what Federated Learning Models Learn: a Comparative Study with Traditional Models
abstract
Federated Learning (FL) offers a robust framework for training Machine Learning (ML) models across distributed devices while preserving data privacy. However, concerns remain about whether FL-trained models learn in the same way as their centralized-data counterparts. This paper examines the impact of FL on model behavior, utilizing Explainable AI (XAI) techniques and correlation metrics to compare feature importance. By applying two XAI metrics across four public datasets and evaluating multiple FL strategies, we assess how closely federated models align with traditionally trained ones. Although models often achieve similar classification performance (Matthews's Correlation Coefficient (MCC) > 0.9), we observe significant differences in attribution patterns, especially in async approaches, with correlation scores below 0.7 Spearman's Rank Correlation Coefficient (SRCC) on several occasions and below 0.4 SRCC for the worst scenario. These findings suggest that identical performance does not always imply equivalent learning. Furthermore, since these findings were obtained under Independent and Identically Distributed (IID) settings, it is expected that under non-IID settings, the results might be even worse, underscoring the need for explainability-driven validation tools to ensure the reliability, fairness, and trustworthiness of FL models in practice.
Rafael Teixeira, Leonardo Almeida, Julio Corona, Mário Antunes 0001, Rui L. Aguiar
WiMob6
2025 Real-time adaptive resource management for high-resolution computer vision over private 5G networks
Filipe Antão, David Santos, André Perdigão, Tiago Barros, Fatma Marzouk, Alisson O. Chaves, Daniel Corujo, Rui L. Aguiar
Comput. Networks9
2025 Automating 5G network slice management for industrial applications
André Perdigão, José Quevedo, Rui L. Aguiar
Comput. Commun.3
2025 Beyond performance comparing the costs of applying Deep and Shallow Learning
abstract
The rapid growth of mobile network traffic and the emergence of complex applications, such as self-driving cars and augmented reality, demand ultra-low latency, high throughput, and massive device connectivity, which traditional network design approaches struggle to meet. These issues were initially addressed in 5th Generation (5G) and Beyond-5G (B5G) networks, where Artificial Intelligence (AI), particularly Deep Learning (DL), is proposed to optimize the network and to meet these demanding requirements. However, the resource constraints and time limitations inherent in telecommunication networks raise questions about the practicality of deploying large Deep Neural Networks (DNNs) in these contexts. This paper analyzes the costs of implementing DNNs by comparing them with shallow ML models across multiple datasets and evaluating factors such as execution time and model interpretability. Our findings demonstrate that shallow ML models offer comparable performance to DNNs, with significantly reduced training and inference times, achieving up to 90% acceleration. Moreover, shallow models are more interpretable, as explainability metrics struggle to agree on feature importance values even for high-performing DNNs.
Rafael Teixeira, Leonardo Almeida, Mário Antunes 0001, Diogo Gomes 0001, Rui L. Aguiar
Comput. Commun.6
2025 Leveraging decentralized communication for privacy-preserving federated learning in 6G Networks
abstract
Artificial intelligence (AI) is a fundamental pillar in developing next-generation networks. Federated learning (FL) emerges as a promising solution to address data privacy concerns during AI model training within the network. However, training AI models on user equipment raises challenges regarding battery consumption, unreliable connections, and communication overhead. This paper proposes Zenoh, a data-centric communication middleware, as an alternative to the traditional Message Passing Interface (MPI) for FL applications. Zenoh’s decentralized nature and low communication overhead make it suitable for resource-constrained devices and unreliable network connections. The paper compares Zenoh and MPI in a realistic FL scenario, demonstrating Zenoh’s potential to outperform MPI in terms of flexibility, communication efficiency, and system complexity.
Rafael Teixeira, Gabriele Baldoni, Mário Antunes 0001, Diogo Gomes 0001, Rui L. Aguiar
Comput. Commun.5
2025 5G slicing under the hood: An in-depth analysis of 5G RAN features and configurations
André Perdigão, José Quevedo, Rui L. Aguiar
J. Netw. Comput. Appl.3
2024 Adaptive Admission Control for 6G Network Slicing Resource Allocation (A2C-NSRA)
Fadoua Debbabi, Rihab Jmal, Lamia Chaari, Raouia Taktak, Rui L. Aguiar
AINA (1)5
2024 Rethinking Security: The Resilience of Shallow ML Models (Extended Abstract)
abstract
The growth of Machine Learning (ML) has led to the commercialization of applications like data analytics, autonomous systems, and security diagnostics. These models are becoming widespread across various domains. However, security and privacy issues accompany this growth. Although actively researched, there's fragmentation in analyzing and defining ML models' resilience. This work examines the resilience of shallow ML models against typical data poisoning attacks. Our study assessed their strengths in adversarial scenarios using the MNIST dataset in a CAPTCHA context. Results show notable resilience, with accuracy and generalization maintained despite malicious inputs, offering insights to strengthen future ML systems. Understanding the mechanisms enabling this resilience can aid in fortifying the security of future ML systems.
Rafael Teixeira, Mário Antunes 0001, João Paulo Barraca, Diogo Gomes 0001, Rui L. Aguiar
DSAA5
2024 DRL-Based Battery and Power Optimization in FL-enabled IoT Networks for eHealth
abstract
In the advancing realm of e-health applications powered by 5G networks, the paramount goal of extending the sustainability of e-health services hinges on efficient energy management of Internet of Things (IoT) devices. This paper presents a cutting-edge Deep Reinforcement Learning (DRL)based approach for the dynamic optimization of IoT device selection and power allocation in Federated Learning (FL) tasks, with an emphasis on battery energy conservation to foster AIenabled e-health applications. Adhering to the strict demands of e-health applications in 5G networks, such as ultra-low latency and high data throughput, while prioritizing energy efficiency, this approach aims to prolong IoT device lifespans without sacrificing FL accuracy. By intelligently navigating network dynamics and device constraints through DRL, this framework optimizes energy usage, enhancing the sustainability and reliability of ehealth services within the 5G ecosystem. The comparative analysis reveals that the proposed approach excels in optimizing energy consumption, download and upload throughput, and training efficiency compared to conventional algorithms, establishing a new benchmark for future optimizations in FL applications across IoT devices. Compared to representative algorithms, our approach reduces energy consumption by >80% and training time by >34%, optimizing performance in FL-enabled e-Health applications.
Alaa AlZailaa, Hao Ran Chi, Ayman Radwan, Rui L. Aguiar
GLOBECOM4
2024 Metric Impact Towards Carbon-Aware Multi-domain Network Orchestration
abstract
Under the fact that carbon footprint is broadly overlooked in information and communication technologies, multi-domain network orchestration, with even higher carbon footprint for inter-domain management than single-domain scenarios, is urged to be transited to be carbon-aware, towards Green 6G. To begin with, stakeholders are required to reach consensus on metrics for carbon measurement. However, there are limited efforts that discuss the impact of metrics, lack of which directly causes biased and chaotic network orchestration. This paper fills this research gap to provide a comprehensive analytics of metrics and their impacts towards carbon-aware multi-domain network orchestration. To do so, a generic architecture is developed correspondingly, based on which commonly used energy/carbon-aware metrics are summarized and analyzed. Representative scenarios are designed for simulation analysis to comprehensively reflect multi-domain network orchestration. Results reveal that improper metric selection could lead to up to 99.92% biased decision of network orchestration, regarding carbon footprint. In conclusion, this paper provides analytical guidance to the future carbon-aware multi-domain network orchestration, with the impact of metrics.
Hao Ran Chi, Daniel Corujo, Ayman Radwan, Rui L. Aguiar
GLOBECOM4
2024 Carbon-Aware Full-Decentralized Multi-Provider Edge Computing Peer Offloading
abstract
The edge computing market has been proliferating, which is foreseen to embrace more solution providers joining under the framework of 6G. Many research efforts exist, focusing on edge computing peer offloading among a single provider. However, there are limited discussions on multi-provider scenarios, which raises new challenge associated with providers' synchronization and property protection. Moreover, carbon footprint for multi-provider edge computing peer offloading will be even higher, which is also overlooked. Therefore, this paper provides a generic architecture and system model of full-decentralized on-demand edge computing peer offloading, specifically targeting multi-provider scenarios with providers' protection and carbon reduction. The carbon-aware peer offloading algorithm is formulated as an optimization process with Lagrangian modeling, which is physically embedded in edge computing servers, thus reaching consensus without data aggregation or property-sensitive data sharing. Simulation results reveal that the proposed algorithm achieves reduced carbon footprint, while maintaining a high quality of service.
Hao Ran Chi, Daniel Corujo, Rui L. Aguiar
INDIN3
2024 MoFaaS: A Moving Target Defense Approach to Fortify Functions as a Service
abstract
Serverless computing is becoming increasingly relevant in the cloud and applied in other fields, such as telecom. This paper proposes the Moving Functions as a Service (MoFaaS) system, a Moving Target Defense (MTD) and N-Version Programming (NVP)-based approach designed to improve the protection of applications and services built using Function as a Service (FaaS). The mechanism works by rotating the version to be executed next for each function. Therefore, when an attacker triggers the execution of a specific workflow path in distinct moments, the versions of the functions responding to those requests will probably be different. Consequently, if one or more function variants are vulnerable, the attacker cannot target them reliably. In the end, we conducted a preliminary practical demonstration to prove this system’s effectiveness. Its analysis shows that the attack difficulty increases with the number of versions per function and the versions an attacker has to compromise to achieve its objectives.
Pedro Escaleira, Vitor A. Cunha, João Paulo Barraca, Diogo Gomes 0001, Rui L. Aguiar
ISCC5
2023 Exploring the Intricacies of Neural Network Optimization
Rafael Teixeira, Mário Antunes 0001, Rúben Sobral, Diogo Gomes 0001, Rui L. Aguiar
DS6
2023 Towards Efficient Provisioning of Dynamic Edge Services in Mobile Networks
abstract
Edge computing brings added benefits for different elements in the overall system (e.g., users, operators and service providers). However, currently there are no proper interfaces and mechanisms to instantiate third-party services within the operators' infrastructure (e.g., as a MEC application), thus hindering edge computing to reach its full potential. To fill this gap, this paper presents architectural enhancements, interfaces and mechanisms to enable dynamic and efficient third-party service deployment within the operators' domain. A simulation-based analysis is presented to showcase the relevance of the proposed solution. Results highlighted the benefits of optimal migration of third-party services into a distributed setting, compared to the unveiled drawbacks of a centralized approach. In addition, the key components of the solution are implemented and experimentally validated through a proof-of-concept prototype showcasing the performance impact of the proposed approach as well as the suitability of its implementation.
José Quevedo, Daniel Corujo, David Santos, Hao Ran Chi, Ayman Radwan, Rui L. Aguiar, Osama Abboud, Artur Hecker
ICC7
2023 A Zero-Touch and NFV-Based Full-Mesh VPNaaS Solution - Demo
abstract
NFV has risen to be a solution to abstract Network Functions from the hardware, providing numerous advantages to Network Operators. However, many challenges have appeared with the evolution of NFV. An example are the inter-domain scenarios where services are spanned across multiple independent domains. Using VPNs to interconnect all domains can attenuate the difficulties imposed by such scenarios. In this paper, we present a NFV-based solution for deploying full-mesh VPNs to interconnect different administrative domains, without manual intervention.
Daniel Gomes, Rafael Direito, Diogo Gomes 0001, Rui L. Aguiar
NetSoft4
2023 Multi-Criteria Dynamic Service Migration for Ultra-Large-Scale Edge Computing Networks
abstract
Multiaccess edge computing (MEC) service migration is a technology whose key objective is to support ultralow-latency access to services. However, the complex ultralarge-scale edge service migration problem requires extensive research efforts, regarding the foreseen ultradensified edge nodes in 5G and beyond. In this article, we propose a novel dynamic service migration optimization architecture for ultralarge-scale MEC networks. We develop a new multicriteria decision-making algorithm: Technique for order of preference by similarity to ideal solution with attribute-based Niche count, named TOPANSIS, which showcases its strength to provide an optimal solution for service migration in large-scale deployments towards optimal data rate, latency, and load balancing. We further decentralize the operation of TOPANSIS to release the traffic burden from central datacenters by leveraging local decision making by edge nodes, while relying on central cloud coordination to account for the overall network information. Simulation results showcase that the proposed architecture outperforms the selected benchmarks with an average improvement of 39.41% for latency, 2.92% for data rate, as well as 10.53% and 6.26% for RAM and CPU load balancing, respectively. Moreover, the feasibility of the proposed solution is validated by means of a proof-of-concept implementation and experimental assessments.
Hao Ran Chi, David Santos, José Quevedo, Daniel Corujo, Osama Abboud, Ayman Radwan, Artur Hecker, Rui L. Aguiar
IEEE Trans. Ind. Informatics9
2023 Game theory for B5G upper-tier resource allocation using network slicing
Fadoua Debbabi, Rui L. Aguiar, Rihab Jmal, Lamia Chaari
Wirel. Networks2
2022 Multi-access Edge Computing as a Service
abstract
Standardization organizations, such as the European Telecommunications Standards Institute (ETSI), have been gathering efforts to specify the Edge Computing paradigm. However, there is still a lack of complete, interface-wise, actual implementations and evaluations of a fully functional Edge Computing architecture. On these grounds, the work presented in this paper proposes a new Multi-access Edge Computing (MEC)-Network Functions Virtualization (NFV) architecture for a challenging Business to Business to Consumer (B2B2C) model, based on the references provided by ETSI, and provides a prototype implementation to demonstrate its viability. The tests conducted show that the proposed framework can be efficiently deployed, allowing Telecommunications Operators to rapidly instantiate and provide an elastic Edge Infrastructure to their customers.
Pedro Escaleira, Miguel Mota, Diogo Gomes 0001, João Paulo Barraca, Rui L. Aguiar
CNSM5
2022 Multi-Criteria Modeled Live Service Migration for Heterogeneous Edge Computing
abstract
In this paper, we modeled the emerging edge-computing-enabled live service migration as a multi-criteria problem optimization, tackling migration costs and benefits, as well as discussion of service providers' data privacy, simultaneously. Based on the optimization formulation, we conducted a small-scale analytical feasibility test, considering widely-utilized multi-criteria decision making algorithms, based on which we proposed a new TOPSIS based service migration algorithm. The algorithm was evaluated using simulations, whose results show that the proposed algorithm is sufficient to support live service migration for heterogeneous edge computing, while outperforming benchmarks in with respect to reducing migration costs and increasing achieved benefits, by 34.52% and 60.21%, respectively.
Ayman Radwan, Hao Ran Chi, Daniel Corujo, José Quevedo, David Santos, Rui L. Aguiar, Osama Abboud, Artur Hecker
GLOBECOM7
2022 Overview of AI-based Algorithms for Network Slicing Resource Management in B5G and 6G
abstract
We are now in the early stage of the Fifth Generation (5G) commercialization, and its improved capabilities and unique features will revolutionize the present wireless network. The 3rd Generation Partnership Project (3GPP) is currently working on the 5G New Radio, also known as the worldwide standardization of 5G, which can operate across a wide variety of frequency bands from minus than 6GHz to mmWave (100GHz). Nonetheless, 5G will not be able to satisfy all requirements for the foreseeable future. Hence, Beyond 5G (B5G) and Sixth Generation (6G) have emerged as concepts representing Next Generation Wireless Networks (NGWNs). B5G and 6G networks will probably integrate Artificial intelligence-based services, tactile services, hybrid access, quantum computing, edge computing, and optical wireless communication. This paper describes potential background concepts relating to Network Slicing and artificial intelligence. We present the literature review by studying the impact of Artificial Intelligence with its promising methods, training models, and architectures to be integrated into B5G Network slicing to perform Resource Management.
Fadoua Debbabi, Rihab Jmal, Lamia Chaari, Rui L. Aguiar, Rayen Gnichi, Samar Taleb
IWCMC4
2022 Inter-slice B5G Bandwidth Resource Allocation
abstract
The Beyond 5G (B5G) networks vision afford wireless access to a vertical market with varying Quality of Service (QoS) requirements. Network Slicing (NS) is one of the key features that offers the opportunity to have a logical network that affects the market model of these verticals. Accordingly, Network Slicing opens the door to new market players including the Infrastructure Provider (InP) and the Virtual Network Operator (VNO). The InP is the owner of the infrastructure that supports several types of slices. The VNO will buy network resources (i.e., bandwidth) from the InP in order to provide a particular service to its users. Consequently, deciding on the optimal resources allocation among VNO users while maximizing the revenue of the InP has become a fundamental issue that needs to be solved. Previous works have presented optimal solutions for resources allocation and focused mainly on a single scenario based on pricing mechanisms. In this paper, we propose an inter-slice resources allocation based on multiple sets, namely customer residential profile, industry coverage, and business area. We propose an Integer Linear Programming (ILP) formulation to the problem, describe an admission control scheme and devise a greedy-based heuristic to solve the problem.
Fadoua Debbabi, Raouia Taktak, Rihab Jmal, Lamia Chaari, Rui L. Aguiar
NCA5
2022 Towards a Fully Automated System for Testing and Validating NetApps
abstract
5G technologies provide several advancements regarding low latency and high bandwidth network scenarios, thus enabling new vertical use cases. Nonetheless, the lack of testing and validation mechanisms for NFV-based services poses a severe challenge in reducing their time to market. In this work we showcase a service to automate the validation of 5G NetApps, thus striving towards reducing the time to market of these applications, and introducing a new layer of trust in their reliability and availability.
Rafael Direito, Diogo Gomes 0001, Rui L. Aguiar
NetSoft3
2022 An Overview of Interslice and Intraslice Resource Allocation in B5G Telecommunication Networks
abstract
We are now in the first phase of the Fifth Generation (5G) network, and its full potential is still a long way to reach. Network operators and manufacturers are preparing to release new 5G end-users services and products. Each service must be performant to meet the need of users. Network Slicing (NS) is now one of the most popular 5G technologies in the research community. For network softwarization, Network Slicing affords flexibility and scalability with embedded Quality of Experience (QoE) and Quality of Services (QoS) features. In this paper, we explore the latest developments in related research fields. We summarize the 3GPP network slicing evolution, the Radio Access Network, and Core Network architectures. We describe background concepts correlated with inter-slice and intra-slice, as well as their management and orchestration architectures. We extend our discussion to the taxonomy of NGWN resource allocation via a deep comparison of the optimization algorithms. Finally, we enrich our study by including open issues and some recommendations for the future.
Fadoua Debbabi, Rihab Jmal, Lamia Chaari, Rui L. Aguiar
IEEE Trans. Netw. Serv. Manag.4
2021 Deploying Scalable and Stable XDP-Based Network Slices Through NASOR Framework for Low-Latency Applications
Rodrigo Moreira, Pedro Frosi Rosa, Rui L. Aguiar, Flávio Oliveira Silva 0001
AINA (2)3
2021 Misalignment problem in matrix decomposition with missing values
abstract
Data collection within a real-world environment may be compromised by several factors such as data-logger malfunctions and communication errors, during which no data is collected. As a consequence, appropriate tools are required to handle the missing values when analysing and processing such data. This problem is often tackled via matrix decomposition. While it has been successfully applied in a wide range of applications, in this work we report an issue that has been neglected in literature and “degenerates” the quality of the imputations obtained by matrix decomposition in multivariate time-series (with smooth evolution). Briefly, the problem consists of the misalignment of the matrix decomposition result: the missing values imputations fall within an incorrect range of values and the transitions between observed and imputed values are not smooth. We address this problem by proposing a postprocessing alignment strategy. According to our experiments, the post-processing adjustment substantially improves the accuracy of the imputations (when the misalignment occurs). Moreover, the results also suggest that the misalignment occurs mostly when dealing with a small number of time-series due to lack of generalisation ability.
Sofia Fernandes 0001, Mário Antunes 0001, Diogo Gomes 0001, Rui L. Aguiar
DSAA4
2021 Three-Tier Fuzzy-based Orchestration in MEC
abstract
Handing over highly demanding tasks to remote or nearby computing units helps accommodate the service Quality of Service (QoS) requirements, and compensates for the limited computational capabilities of User Equipment (UE) such as smartphones and tablets. Task offloading is a promising technique being proposed for Virtualized Edge (VE) environments to solve a wide range of issues, frequently with the aim of enabling resource-intensive low-latency services. However, the volatile nature of 5G and B5G networks, as they continuously change due to dynamic policies, optimization processes, and users' mobility, formalizes a major obstacle facing offloading and overall resource orchestration. To cope with such a challenge, under the scope of Multi-access Edge Computing (MEC), a three-tier fuzzy-based orchestration strategy is proposed with the aim of offloading the users' workload to the optimum computing units to support stricter QoS requirements and reduce the perceived service delay. To evaluate our solution, we compare the proposed workload orchestrator with different employed algorithms. The evaluation shows that our orchestrator achieves nearly ideal performance, and outperforms the state-of-the-art approaches considered.
Hadeel Abdah, João Paulo Barraca, Rui L. Aguiar
GLOBECOM3
2021 Low-Latency Task Classification and Scheduling in Fog/Cloud based Critical e-Health Applications
abstract
5G wireless networks have been designed to provide high reliability, ultra-low latency, and support of massive amount of connected devices, in the scope of the Internet of Things (IoT). Advances in electronics and networking are enabling the wide adoption of multiple types of verticals, under the umbrella of IoT. One area of IoT, which is gaining lots of attention, is e-Health. Within e-Health, users’ monitoring in general, and monitoring of vital signs, such as heartbeat rate, are very useful in saving many lives; however, they require ultra-low latency. Cloud-based networking and computing have been proposed to achieve the required low latency. Furthermore, fog computing was proposed to further decrease the achieved latency for critical tasks and services; however, this adds more complexity to the control of the network, in addition to the task scheduling among both the cloud and fog layer. In this paper, we tackle this problem by proposing a task classification and scheduling scheme in a fog-cloud networking environment, by considering comprehensively modeled characteristics of tasks, user profile, environmental exposure and networking features, targeting the improvement of overall latency for higher priority critical tasks. Moreover, we perform an analytical study on the execution comparison between cloud and fog computing services, which paves the way to further develop an orchestrator for task scheduling, among the multi-layer fog-cloud based e-Health systems. Simulation results show that the proposed task scheduling scheme outperforms the benchmark, by guaranteeing ultra-low latency for critical tasks (high-priority), while ensuring sufficient latency performance for latency-tolerant tasks.
Alaa AlZailaa, Hao Ran Chi, Ayman Radwan, Rui L. Aguiar
ICC4
2021 A hybrid SDN solution for mobile networks
David Santos, Flavio Meneses, Daniel Corujo, Rui L. Aguiar
Comput. Networks5
2021 NASOR: A network slicing approach for multiple Autonomous Systems
Rodrigo Moreira, Pedro Frosi Rosa, Rui L. Aguiar, Flávio Oliveira Silva 0001
Comput. Commun.3
2021 Misalignment problem in matrix decomposition with missing values
Sofia Fernandes 0001, Mário Antunes 0001, Diogo Gomes 0001, Rui L. Aguiar
Mach. Learn.4
2021 TOTP Moving Target Defense for sensitive network services
Vitor A. Cunha, Daniel Corujo, João Paulo Barraca, Rui L. Aguiar
Pervasive Mob. Comput.4
2020 Enabling Multi-domain and End-to-End Slice Orchestration for Virtualization Everything Functions (VxFs)
Rodrigo Moreira, Pedro Frosi Rosa, Rui L. Aguiar, Flávio Oliveira Silva 0001
AINA3
2020 Handover Prediction Integrated with Service Migration in 5G Systems
abstract
As the research community inclines toward adopting increasingly complex techniques for future networks, and simple methods are often ignored, being labeled as trivial. In this paper, we argue that simple methods can sometimes outperform more sophisticated ones. We demonstrate that by evaluating two prediction mechanisms to forecast mobile user's handovers exploiting user-network association patterns. We perform a series of experiments on real-world data, evaluating the performance characteristics of such methods over more sophisticated and complex prediction techniques. Furthermore, we discuss how to easily bootstrap these mechanisms into the 5G network architecture. We suggest the use of these methods associated with Multi-access Edge Computing (MEC) scenarios, as a mean to identify favorable edge nodes to host the mobile applications, to best provide continuous and QoS-aware service for mobile users.
Hadeel Abdah, João Paulo Barraca, Rui L. Aguiar
ICC3
2020 Quantifying the Influence of Regulatory Instructions over the Detection of Network Neutrality Violations
Marcio Barbosa de Carvalho, Vitor A. Cunha, Eduardo da Silva, Daniel Corujo, João Paulo Barraca, Rui L. Aguiar, Lisandro Z. Granville
Networking6
2020 A search space optimization method for fuzzy access control auditing
Diogo Domingues Regateiro, Óscar Mortágua Pereira, Rui L. Aguiar
Knowl. Inf. Syst.3
2019 Distributed and Scalable Platform for Collaborative Analysis of Massive Time Series Data Sets
Eduardo Duarte, Diogo Gomes 0001, David Campos 0001, Rui L. Aguiar
DATA4
2019 Safeguarding from abuse by IoT vendors: Edge messages verification of cloud-assisted equipment
Vitor A. Cunha, Eduardo da Silva, Marcio Barbosa de Carvalho, Daniel Corujo, João Paulo Barraca, Diogo Gomes 0001, Alberto E. Schaeffer Filho, Carlos Raniery Paula dos Santos, Lisandro Z. Granville, Rui L. Aguiar
IM10
2019 Stream Generation: Markov Chains vs GANs
Ricardo Jesus, Mário Antunes 0001, Petia Georgieva, Diogo Gomes 0001, Rui L. Aguiar
IoTBDS5
2019 A Network Service for Preventing Data Leakage from IoT Cloud-assisted Equipment
abstract
The fact that most IoT solutions are provided by third parties, along with the pervasiveness of the collected data, raises privacy and security concerns. There is a need to verify which data is being sent to the third party, as well as preventing those channels from becoming an exploitation avenue. We propose to use existing API definition languages to create contracts which define the data that can be transmitted, their format and constraints. To verify the compliance with these contracts, we propose a Network Service architecture which validates REST-like API requests/responses against a Swagger schema. We deal with encrypted traffic using an Service Function Chaining (SFC)-enabled Man-in-the-Middle (MITM), allowing verifications in “real-time.” We devised a Proof of Concept and showed that we were able to detect (and stop) contract violations.
Vitor A. Cunha, Rui L. Aguiar, Eduardo da Silva, Marcio Barbosa de Carvalho, Daniel Corujo, João Paulo Barraca, Diogo Gomes 0001, Alberto E. Schaeffer Filho, Carlos Raniery Paula dos Santos, Lisandro Z. Granville
ISCC2
2019 Content Retrieval while Moving Across IP and NDN Network Architectures
abstract
Research on Future Internet has gained traction in recent years, with a variety of clean-slate network architectures being proposed. The realization of such proposals may lead to a period of coexistence with the current Internet, creating a heterogeneous Future Internet. In such a vision, mobile nodes (MNs) can move across access networks supporting different network architectures, while being able to maintain the access to content during this movement. In order to support such scenarios, this paper proposes an inter-network architecture mobility framework that allows MNs to move across different network architectures without losing access to the contents being accessed. The usage of the proposed framework is exemplified and evaluated in a mobility scenario targeting IP and NDN network architectures in a content retrieval use case. The obtained results validate the proposed framework while highlighting the impact on the overall communication between the MN and content source.
Carlos Guimarães, José Quevedo, Rui Ferreira 0001, Daniel Corujo, Rui L. Aguiar
ISCC5
2019 Mobility-Optimized Dynamic Content Placement for Fast Vehicles in 5G Networks
abstract
This paper presents a framework for improved mobile video delivery in high speed vehicles, integrating Network Function Virtualization, Software Defined Networking and Multi-access Edge Computing (MEC), with user mobility and service consumption context for enabling the dynamic instantiation of video services in edge-positioned virtualized Content Delivery Network (vCDN) nodes. Based on the estimated vehicle (current and future) position, the solution determines: where the video should be dynamically cached and at what time; and which chunks of the video need to be cached at the target location. This "location-aware predictive caching" mechanism is able to operate in a transparent way to both the user and the video service, by handling the necessary flow-based mobility procedures. A proof of concept was implemented and compared with a static caching service and a regular MEC-based vCDN, enabling the assessment of the contributions and impacts of the mechanism. Results show that our solution minimized the number of cache misses in mobility scenarios while reducing backhaul and core network traffic.
David Santos, Daniel Corujo, Rui L. Aguiar, Sérgio Figueiredo, Bruno Parreira
PIMRC4
2019 BDFIS: Binary Decision Access Control Model Based On Fuzzy Inference Systems
abstract
Access control is a ubiquitous feature in almost all computer systems, and as data becomes more and more of an important asset for organizations, so do the associated access control policies. However, with the increase in the amount of data being produced, e.g. in IoT and social networks, the interest in simpler access control is increasing as well since more subjects (public, researchers, etc.) are now requesting access to it. Defining the exact conditions to allow each subject to access the data can be difficult, especially when vaguely defined conditions such as "expertise of a researcher" come into play. Fuzzy Inference Systems (FIS) allow to process these vague conditions and enables access control mechanisms to be more easily applied. The contribution of this paper lies in showing how a FIS can be used to output binary access control decisions (grant/deny) and what are the differences in the inference process that stems from restricting the output to these two output values.
Diogo Domingues Regateiro, Óscar Mortágua Pereira, Rui L. Aguiar
SEKE3
2019 Repositioning privacy concerns: Web servers controlling URL metadata
Rui Ferreira 0001, Rui L. Aguiar
J. Inf. Secur. Appl.2
2019 Exploring interoperability assessment for Future Internet Architectures roll out
Carlos Guimarães, José Quevedo, Rui Ferreira 0001, Daniel Corujo, Rui L. Aguiar
J. Netw. Comput. Appl.5
2019 Network-Cloud Slicing Definitions for Wi-Fi Sharing Systems to Enhance 5G Ultra Dense Network Capabilities
abstract
Ultradense Networks (UDNs) seek to scale the 5th-Generation mobile network systems at unforeseen amounts of networks, users, and mobile traffic. We believe that the Wi-Fi sharing service is an asset in expanding 5G UDN capacity requirements for higher coverage and ubiquitous wireless broadband connectivity. However, the limitations of the Wi-Fi sharing pioneer deployment, along with other related works, has led our team to carry out further research. As a result, it was found that FOg CloUd Slicing for Wi-Fi sharing (FOCUS) is a suitable means of expanding 5G UDN capacities. FOCUS applies end-to-end Network-Cloud slice definitions on top of the Wi-Fi sharing technology, with the aim of offering multitenancy and multiservice support for a wide range of services, while meeting carrier-grade requirements and resource control at runtime and making full use of a “softwarized” approach. The feasibility of the FOCUS system is assessed in a real testbed deployment prototype, which allows an accurate view to be obtained of the basic functional principles and system-level proof-of-concept alongside the FON de facto Wi-Fi sharing service. The results suggest that FOCUS offers much greater benefits than FON, owing to its capacity to provide end-to-end Network-Cloud Slices while ensuring independent/isolated service delivery with resource adaptation at runtime.
Maxweel Carmo, Felipe Sampaio Dantas da Silva, Augusto Neto 0001, Daniel Corujo, Rui L. Aguiar
Wirel. Commun. Mob. Comput.5
2018 A Flexible Network and Compute-Aware Orchestrator to Enhance QoS in NFV-Based Multimedia Services
abstract
People and organizations around the globe are using multimedia applications to communicate. By evolving their networks, network operators are taking advantage of the convergence of voice and data. QoS metrics are usually based on parameters from the user side or network side. In this context, NFV and SDN can improve the communication experience and offers an abstraction layer to the deployment of flexible multimedia applications provided on the cloud. In this work, we propose an approach to mitigate globally manage network and computing resources for multimedia applications. To this end, we come up with a control plane entity capable of orchestrating compute and network resources for the multimedia application scenario, relying on SIP control messages. Our solution brings QoS enhancement to the user through resiliency, load balancing, packet inspection, scaling on demand and the separation of control and data planes.
Rodrigo Moreira, Flávio Oliveira Silva 0001, Pedro Frosi Rosa, Rui L. Aguiar
AINA4
2018 Slicing WiFi WLAN-Sharing Access Infrastructures to Enhance Ultra-Dense 5G Networking
abstract
The rise of 5th Generation (5G) based network systems provide the prospect for an unprecedented technological revolution in different aspects of current network infrastructures to fully satisfy the high demands of smart space. This work addresses the challenges that raise in exploiting the potential of WiFi WLAN-sharing technology in 5G Ultra-Dense Networking (UDN) use cases. We investigate new complementary aspects of emerging 5G technologies such as Network Function Virtualization (NFV) and Fog computing to design a unique WiFi WLAN-sharing ecosystem to allow complying with 5G UDN critical requirements. In the resulting approach, we empower WiFi WLAN-sharing infrastructures with Fog computing capabilities and follow a slice-defined approach, aiming to provide differentiated services at unprecedented levels, on top of the same infrastructure through customized, isolated and independent building blocks. The solution also enables slices to accommodate applications besides networking functions, seeking to provide ultra-low latency rates by leveraging direct linkage to data producer entities. A proof of concept was conducted by carrying out experiments in a real laboratory testbed, allowing insights into the feasibility and suitability of slicing WiFi WLAN-sharing systems.
Maxweel Carmo, Sandino Jardim, Augusto Neto 0001, Rui L. Aguiar, Daniel Corujo, Joel J. P. C. Rodrigues
ICC4
2018 The Impact of Clustering for Learning Semantic Categories
Mário Antunes 0001, Diogo Gomes 0001, Rui L. Aguiar
IoTBDS3
2018 Discovery of Newsworthy Events in Twitter
abstract
The new communication paradigm established by Social Media, along with its growing popularity in recent years contributed to attract an increasing interest by several research fields. One such research field is the field of event detection in Social Media. The purpose of this work is to implement a system to detect newsworthy events in Twitter. A similar system proposed in the literature is used as the base of this implementation. For this purpose, a segmentation algorithm implemented using a dynamic programming approach is proposed in order to split the tweets into segments. Wikipedia is then leveraged as an additional factor in order to rank these segments. The top k segments in this ranking are then grouped together according to their similarity using a variant of the Jarvis-Patrick clustering algorithm. The resulting candidate events are filtered using an SVM model trained on annotated data, in order to retain only those related to real-world newsworthy events. The implemented system was tested with three months of data, representing a total of 4,770,636 tweets created in Portugal and mostly written in the Portuguese language. The precision obtained by the system was 76.9 % with a recall of 41.6%.
Fernando Fradique Duarte, Óscar Mortágua Pereira, Rui L. Aguiar
IoTBDS3
2018 An SFC-enabled approach for processing SSL/TLS encrypted traffic in Future Enterprise Networks
abstract
In this paper, we propose an architecture based on NFV and SDN which allows to balance traffic analysis techniques using a Classifier. It steers flows to the appropriate Service Function Chaining (to open traffic or not) according to network requirements (such as, effectiveness, flexibility, scalability, performance, and privacy). The SSL/TLS traffic processing is carried-out by the centerpiece of this work, the SFC-enabled MITM. A Proof-of-Concept was conducted (focusing on our SFC-enabled MITM) which showed that functionalities lost due to encryption (Content Optimization, Caching, Network Anti-virus, and Content Filter) were recovered when processing opened traffic within its Service Function Chains. We also evaluated its impact on performance. The results show that cipher suite overhead plays a role but can be mitigated, the Classifier can alleviate the performance overhead of different traffic analysis techniques, network functions have lower impact to performance, and Service Function Chaining length influences page load time.
Vitor A. Cunha, Marcio Barbosa de Carvalho, Daniel Corujo, João Paulo Barraca, Diogo Gomes 0001, Alberto E. Schaeffer Filho, Carlos Raniery Paula dos Santos, Lisandro Z. Granville, Rui L. Aguiar
ISCC9
2018 ETArch-SG - A SDN-based Architecture to Support the Communication Requirements of Future Smart Grids
abstract
The future use of smart grid scenarios with massive amounts of data poses stringent requirements to the communication protocols. IEC 61850, the standard regarding communication within power systems, defines the minimum requirements by the technology supporting smart grids. Considering the new scenarios and their requirements, support to multicast communication can fulfill the time constraints. Current networking technologies based on the TCP/IP architecture have limitations to support multicast inside the network. Based on the Entity Title Architecture (ETArch), an SDN based network architecture, capable of satisfying requirements such as multicast, this work proposes ETArch-SG to support future smart grid communication requirements. By using an experimental approach, ETArch-SG was compared to the current TCP/IP architecture. Our results demonstrate that ETArch-SG can configure IED with lower latencies and communicate PMUs with better performance when compared to IP Multicast, reaching the IEC 61850 time constraints.
Alex Dias, Flávio Oliveira Silva 0001, Pedro Frosi Rosa, Rui L. Aguiar
ISCC4
2018 Handover Initiation Comparison in Virtualised SDN-based Flow Mobility Management
abstract
This paper presents a framework that integrates Software Defined Networks (SDN) and Network Functions Virtualisation (NFV) to migrate operational aspects of both the network's Points of Attachment (PoA) and Mobile Nodes (MN) into the cloud. The SDN Controller is used as an enhanced mobility management entity by integrating the capability to instantiate in the cloud a virtual representation of the MNs (vMN). These vMNs not only act as anchors for the handover process of the physical MNs, but also act as proxies for the delivery of context information about the physical MNs wireless surroundings. Such information can be further used by the Controller for optimised handover decisions, resulting in a technology-agnostic flow mobility management mechanism for heterogeneous networks. A video delivery scenario was selected for evaluation in an experimental testbed, where the video is offloaded between wireless networks towards a dual-interfaced MN, considering different handover initiation procedures. With a handover delay of about 60ms, the results shown that virtualising the end-points reduces 67% of the OpenFlow signalling in the physical network, while as a trade-off, the Open Flow control communication packet size and delay of the MN are incremented.
Flavio Meneses, Carlos Guimarães, Daniel Corujo, Rui L. Aguiar
ISCC4
2018 Using SDN and Slicing for Data Offloading over Heterogeneous Networks Supporting non-3GPP Access
abstract
The foreseen exploding number of devices connected to the mobile network has been pushing operators to look for mechanisms to transparently offload their data. However, such procedures need to consider the different demands from users' traffic and involved access networks. Towards that end, Network Slicing has been proposing a logical partition of the network to better serve different verticals requirements, while providing isolation, achieved by using Software Defined Networking (SDN) and Network Function Virtualisation (NFV) mechanisms. In this paper, we explore the realization of a mobile traffic offloading framework that is able to dynamically instantiate a non-3GPP slice and use SDN mechanisms to seamlessly handover existing flows into the new connection point. For this, we virtualized both the mobile Core Network components as well as the User Equipment, allowing the mobility procedure to be handled in the cloud and become transparent to the physical endpoints. A prototype of our proposal was deployed in a physical testbed, and evaluated in a mobile video offloading scenario where the operator strategically deploys Wi-Fi access points around the city, with results showing that the user is able to continuously visualize the video while switching access technology.
Flavio Meneses, David Santos, Daniel Corujo, Rui L. Aguiar
PIMRC5
2018 SeqBAC: A Sequence-Based Access Control Model (S)
abstract
Access control, when used in the context of database applications, is aimed to supervise the requests made by legitimate users to access sensitive data.These requests represent actions that a user can perform on a database and they typically read or write data.While this supervision can be formalized at a higher level, e.g. using an access control model such as RBAC, in the end, the data access is done through each authorized action.Therefore, the current access control models enforce their policies on an action by action basis, being unable to support relations of order between them.In many database applications, access to data is not done randomly, but by following very specific sequences of actions which are not supervised.This paper argues that a better security policy can be achieved by supervising these sequences.Thus, previous research is leveraged to propose a formalized model, capable of enforcing access control over the sequences of actions that can complement existing access control models.
Diogo Domingues Regateiro, Óscar Mortágua Pereira, Rui L. Aguiar
SEKE3
2018 Wireless Outdoor Network Planning for a Smart City Pilot
abstract
This paper detail the process of radio frequency network planning and design for PASMO pilot project, an open living lab for cooperative ITS and smart cities, starting from analyzing the network and users requirements, going through choosing the appropriate technologies and equipments, and finally testing and validating the feasibility of the proposed deployment plan. Other important outcome of this work is a detailed map of the data rates and signal strength for different radio technologies, supporting the design of robust locationaware communication mechanisms.
Hadeel Abdah, Fatma Marzouk, Akeem O. Mufutau, Joaquim Ferreira 0001, Rui L. Aguiar
VTC Fall5
2018 Towards IoT data classification through semantic features
Mário Antunes 0001, Diogo Gomes 0001, Rui L. Aguiar
Future Gener. Comput. Syst.3
2018 Resource discovery for distributed computing systems: A comprehensive survey
Javad Zarrin, Rui L. Aguiar, João Paulo Barraca
J. Parallel Distributed Comput.2
2017 SPDC: Secure Proxied Database Connectivity
abstract
In the business world, database applications are a predominant tool where data is generally the most important asset of a company. Companies use database applications to access, explore and modify their data in order to provide a wide variety of services. When these applications run in semi-public locations and connect directly to the database, such as a reception area of a company or are connected to the internet, they can become the target of attacks by malicious users and have the hard-coded database credentials stolen. To prevent unauthorized access to a database, solutions such as virtual private networks (VPNs) are used. However, VPNs can be bypassed using internal attacks, and the stolen credentials used to gain access to the database. In this paper the Secure Proxied Database Connectivity (SPDC) is proposed, which is a new methodology to enhance the protection of the database access. It pushes the credentials to a proxy server and separates the information required to access the database between a proxy server and an authentication server. This solution is compared to a VPN using various attack scenarios and we show, with a proof-of concept, that this proposal can also be completely transparent to the user.
Diogo Domingues Regateiro, Óscar Mortágua Pereira, Rui L. Aguiar
DATA3
2017 Supporting Pre-shared Keys in Closed Implementations of TLS
abstract
In the business world, data is generally the most important asset of a company that must be protected. However, it must be made available to provide a wide variety of services, and so it can become the target of attacks by malicious users. Such attacks can involve eavesdropping the network or gaining unauthorized access, allowing such an attacker to access sensitive information. Secure protocols, such as Transport Layer Security (TLS), are usually used to mitigate these attacks. Unfortunately, most implementations force applications to use digital certificates, which may not always be desirable due to trust or monetary issues. Furthermore, implementations are usually closed and cannot be extended to support other authentication methods. In this article a methodology is proposed to slightly modify closed implementations of the TLS protocol that only support digital certificates, so pre-shared keys are used to protect the communication between two entities instead. A performance assessment is carried out on a proof-of-concept to demonstrate its feasibility and performance.
Diogo Domingues Regateiro, Óscar Mortágua Pereira, Rui L. Aguiar
DATA3
2017 Click-on-OSv: A platform for running Click-based middleboxes
abstract
In this paper, we present a modern platform for running Virtualized Network Functions based on the Click Modular Router. The proposed platform leverages of current technologies - such as DPDK, OSv, and REST Web Services - to fulfill the ETSI requirements for Network Functions Virtualization. The obtained results show the feasibility of the platform to consolidate disparate network functions, while demonstrating flexibility from a management point-of-view.
Leonardo da Cruz Marcuzzo, Vinicius Fulber-Garcia, Vitor A. Cunha, Daniel Corujo, João Paulo Barraca, Rui L. Aguiar, Alberto E. Schaeffer Filho, Lisandro Z. Granville, Carlos Raniery Paula dos Santos
IM6
2017 On the Prospect of using Cognitive Systems to Enforce Data Access Control
abstract
Data access control is a field that has been a subject of a lot of research for many years, which has resulted in many models being designed. Many of these models are deterministic in nature, following set rules to allow or deny access to a given user. These are sufficient in fairly static environments, but they fall short in dynamic and collaborative settings where permission needs may change or user attributes may be missing. Risk-based and probabilistic models were designed to mitigate some of these issues. These take a user profile to determine the risk associated with a particular transaction or fill in any missing attributes. However, they need to be maintained as new security threats emerge. It is argued in this paper that cognitive systems, as part of a more general Cognitive Driven Access Control approach, can close this gap by learning security threats on their own and enhancing the security of data in these environments. The benefits and considerations to be made when deploying cognitive systems are also discussed.
Fernando Fradique Duarte, Diogo Domingues Regateiro, Óscar Mortágua Pereira, Rui L. Aguiar
IoTBDS4
2017 Extracting Knowledge from Stream Behavioural Patterns
abstract
The increasing number of small, cheap devices full of sensing capabilities lead to an untapped source of information that can be explored to improve and optimize several systems. Yet, as this number grows it becomes increasingly difficult to manage and organize all this new information. The lack of a standard context representation scheme is one of the main difficulties in this research area (Antunes et al., 2016b). With this in mind we propose a stream characterization model which aims to provide the foundations of a new stream similarity metric. Complementing previous work on context organization, we aim to provide an automatic organizational model without enforcing specific representations.
Ricardo Jesus, Mário Antunes 0001, Diogo Gomes 0001, Rui L. Aguiar
IoTBDS4
2017 The XACML Standard - Addressing Architectural and Security Aspects
abstract
The OASIS XACML (eXtensible Access Control Markup Language) standard defines a language for the definition of access control requests and policies. It is intended to be used with ABAC (Attribute Based Access Control). Along with the language, the standard defines an architecture, workflow and evaluation mechanism. When implementing real scenarios, developers can come across with the missing of several issues not addressed by the standard. For example, the architecture proposed defines the workflow but does not define the way components should be distributed over different machines. Additionally, the standard does not include any information about how securing communications between components. This paper proposes a solution to deal with the aforementioned gaps. A proof of concept is also presented in an IoT use case in the context of the European project: SMARTIE – secure and smarter cities data management.
Óscar Mortágua Pereira, Vedran Semenski, Diogo Domingues Regateiro, Rui L. Aguiar
IoTBDS4
2017 CREDENCE: A Carrier Grade Software Defined Networking control environment based on the JAIN SLEE component model
abstract
Software Defined Networking (SDN) and Network Function Virtualization (NFV) are catching the attention of telecom operators. Telecom environments establish a set of Carrier Grade requirements such as high availability, high throughput and low latency. To address these challenges SDN deploys logically-centralized controllers, such as ONOS and OpenDayLight. Based on the JAIN SLEE component model, which is a Carrier Grade component already deployed at telecom operators, and the Libfluid OpenFlow driver, this work presents the CREDENCE, a carrier grade SDN controller, which in our evaluation shows that it offers a higher throughput and a lower latency when compared to ONOS, OpenDayLight, Ryu and POX.
Jhon Martinez, Pedro Frosi Rosa, Flávio Oliveira Silva 0001, Caio César Ferreira, Pedro Bispo, Daniel Corujo, Rui L. Aguiar
ISCC7
2017 NERV: A constraint-free network resources manager for virtualized environments
abstract
In this work, we present NERV, a constraint free network resource manager for virtualized environments capable of supporting multiple network architectures simultaneously. Using a protocol agnostic forwarding element, programmed with the P4 language, and the design principles of MicroServices architectures, we built a framework composed of small applications, each one responsible for manipulating a group of resources of the network, allowing the implementation of different policies to manage systems with different protocol stacks and control strategies. Also, we promote the reuse of these applications creating a Standard API that expose generic functions to manipulate network resources, permitting the combination of low-level applications to compose high-level network manipulation services.
Mauro Moura, Flávio Oliveira Silva 0001, Pedro Frosi Rosa, Rui L. Aguiar
ISCC4
2017 Towards fog-based slice-defined WLAN infrastructures to cope with future 5G use cases
abstract
The advent of future 5th Generation (5G) use cases, such as ultra-dense networking and ultra-low latency propelled by Smart Cities and IoT projects will demand revolutionary network infrastructures. The need for low latency, high bandwidth, scalability, ubiquitous access and support for IoT resource-constrained devices are some of the prominent issues that networks have to face to support future 5G use cases, which arise since current wireless and mobile infrastructures are not able to fulfill. In particular, the pervasiveness and high-density of Wireless Local Area Networks (WLAN) at urban centers, together with their growing capacity and evolving standards, can be leveraged to support such demand. We argue that the integration of key 5G cornerstone technologies, such as Network Function Virtualization (NFV) and softwarization, fill some of the abovementioned gaps in regards to proper WLAN management and service orchestration. In this paper, we present a solution for slicing WLAN infrastructures, aiming to provide differentiated services on top of the same substrate through customized, isolated and independent digital building blocks. Through this proposal, we aim at efficiently handling ultra-dense networking 5G use cases to achieve benefits at unprecedented levels. Towards this goal, we present proof of concept realised over a real testbed and assess its feasibility.
Maxweel Carmo, Sandino Jardim, Augusto Neto 0001, Rui L. Aguiar, Daniel Corujo
NCA4
2017 An abstraction framework for flow mobility in multi-technology 5G environments using virtualization and SDN
abstract
The increasing number of mobile devices exploring wireless data through different technologies has been developing the potential for interoperability scenarios in mobile operators. However, each technology operates distinctively, creating a complex integration challenge. As such, 5G research has been exploring different concepts for bringing more dynamic and flexible network operation. Mechanisms such as Software Defined Networking (SDN), Network Function Virtualization (NFV) and the integration of network procedures in the cloud allow operators to efficiently address new operational scenarios. In our proposal, we define a framework where mobility management procedures are abstractedly handled, by virtualizing network entities such as access points and mobile devices. These virtual representations enhance the capabilities of their physical counterparts, and couple the necessary logic allowing them to interoperate or be controlled by network control processes, independently of the access technologies. We have implemented a proof-of-concept where such principles are deployed in a multi-interface wireless environment, exploring both make-before-break and break-before-make mobility scenarios.
Flavio Meneses, Daniel Corujo, Carlos Guimarães, Rui L. Aguiar
NetSoft4
2017 On the Application of Fuzzy Set Theory for Access Control Enforcement
abstract
Access control is a vital part of any computer system. When it comes to access to data, deterministic access control models such as RBAC are still widely used today, but they lack the flexibility needed to support some recent scenarios. These include scenarios where users and data can be dynamically added to a system, which emerged from IoT and big data contexts. Such scenarios include data from network operators, smart cities, etc. Thus, models that are able to adapt to these dynamic environments are necessary. Non-deterministic access control models fall into this approach, as they introduce new ways of mapping users to permissions and resources, but lack the auditing capabilities of deterministic models. In this paper, the usage of these models will be defended and argued for. In particular, a solution based on fuzzy set theory is proposed as it is thought to be able to provide some flexibility benefits of non-deterministic models, while giving some assurance to security experts that the resources are not accessed by unexpected users.
Diogo Domingues Regateiro, Óscar Mortágua Pereira, Rui L. Aguiar
SECRYPT3
2017 Concurrent Call Level Interfaces Based on an Embedded Thread Safe Local Memory Structure
abstract
Performance is traditionally considered one of the most significant concerns in intensive database applications.Several architectural tactics may be taken to minimize the possibility of coming across with any performance bottleneck.One of them is the usage of Call Level Interfaces (CLI).C LI are low level API that provide a high performance environment to execute SQL statements on relational and also on some NoSQL database servers.In spite of this, CLI are not thread safe, this way preventing distinct threads from sharing datasets retrieved from databases through Select statements.Thus, in situations where two or more threads need to access datasets retrieved from the same Select statement, there is no other alternative than providing each thread with its own dataset, this way consuming important computational resources.In this paper we propose a new design for CLI to overcome the aforementioned drawback.Unlike current implementations of CLI, now they are natively thread-safe.The implementation herein presented is based on a thread safe updatable local memory structure where data retrieved from databases is kept.A proof of concept based on Java Database Connectivity type 4 (JDBC) for S QL Server 2008 is presented and also a performance assessment.
Óscar Mortágua Pereira, Rui L. Aguiar
SEKE2
2017 Enhancing Call-Level Interfaces with Thread-Safe Local Memory Structures
abstract
Database applications are being increasingly under pressure to respond effectively to ever more demanding performance requirements. Software architects can resort to several well-known architectural tactics to minimize the possibility of coming across with any performance bottleneck. The usage of call-level interfaces (CLIs) is a strategy aimed at reducing the overhead of business components. CLIs are low-level APIs that provide a high-performance environment to execute standard SQL statements on relational and also on some NoSQL database (DB) servers. In spite of these valuable features, CLIs are not thread-safe when distinct threads need to share datasets retrieved through Select statements from databases. Thus, even in situations where two or more threads could share a dataset, there is no other possibility than providing each thread with its own dataset, this way leading to an increased need of computational resources. To overcome this drawback, in this paper we propose a new natively thread-safe architecture. The implementation herein presented is based on a thread-safe updatable local memory structure (LMS) where the data retrieved from databases is kept. A proof of concept based on Java Database Connectivity type 4 (JDBC) for SQL Server 2008 is presented and also a performance assessment.
Óscar Mortágua Pereira, Rui L. Aguiar
Int. J. Softw. Eng. Knowl. Eng.2
2017 HARD: Hybrid Adaptive Resource Discovery for Jungle Computing
Javad Zarrin, Rui L. Aguiar, João Paulo Barraca
J. Netw. Comput. Appl.2
2016 Fault Tolerance Logging-based Model for Deterministic Systems
abstract
Fault tolerance allows a system to remain operational to some degree when some of its components fail. One of the most common fault tolerance mechanisms consists on logging the system state periodically, and recovering the system to a consistent state in the event of a failure. This paper describes a general fault tolerance logging-based mechanism, which can be layered over deterministic systems. Our proposal describes how a logging mechanism can recover the underlying system to a consistent state, even if an action or set of actions were interrupted mid-way, due to a server crash. We also propose different methods of storing the logging information, and describe how to deploy a fault tolerant master-slave cluster for information replication. We adapt our model to a previously proposed framework, which provided common relational features, like transactions with atomic, consistent, isolated and durable properties, to NoSQL database management systems.
Óscar Mortágua Pereira, David Simões 0001, Rui L. Aguiar
DATA3
2016 Mediator framework for inserting xDRs into Hadoop
abstract
During the last decades, we assisted to what is called “information explosion”. With the advent of the new technologies and new contexts, the volume, velocity and variety of data has increased exponentially, becoming what is known today as big data. Among them, we emphasize telecommunications operators, which gather, using network monitoring equipment, millions of network event records, the Call Detail Records (CDRs) and the Event Detail Records (EDRs), commonly known as xDRs. These records are stored and later processed to compute network performance and quality of service metrics. With the ever increasing number of collected xDRs, its generated volume needing to be stored has increased exponentially, making the current solutions based on relational databases not suited anymore. To tackle this problem, the relational data store can be replaced by Hadoop File System (HDFS). However, HDFS is simply a distributed file system, this way not supporting any aspect of the relational paradigm. To overcome this difficulty, this paper presents a framework that enables the current systems inserting data into relational databases, to keep doing it transparently when migrating to Hadoop. As proof of concept, the developed platform was integrated with the Altaia - a performance and QoS management of telecommunications networks and services.
Óscar Mortágua Pereira, Micael Capitao, Diogo Domingues Regateiro, Rui L. Aguiar, Joao Bica Osorio
ISCC4
2016 Protecting Databases from Schema Disclosure - A CRUD-Based Protection Model
abstract
Database schemas, in many organizations, are considered one of the critical assets to be protected. From database schemas, it is not only possible to infer the information being collected but also the way organizations manage their businesses and/or activities. One of the ways to disclose database schemas is through the Create, Read, Update and Delete (CRUD) expressions. In fact, their use can follow strict security rules or be unregulated by malicious users. In the first case, users are required to master database schemas. This can be critical when applications that access the database directly, which we call database interface applications (DIA), are developed by third party organizations via outsourcing. In the second case, users can disclose partially or totally database schemas following malicious algorithms based on CRUD expressions. To overcome this vulnerability, we propose a new technique where CRUD expressions cannot be directly manipulated by DIAs any more. Whenever a DIA starts-up, the associated database server generates a random codified token for each CRUD expression and sends it to the DIA that the database servers can use to execute the correspondent CRUD expression. In order to validate our proposal, we present a conceptual architectural model and a proof of concept.
Óscar Mortágua Pereira, Diogo Domingues Regateiro, Rui L. Aguiar
SECRYPT3
2016 On the application of contextual IoT service discovery in Information Centric Networks
José Quevedo, Mário Antunes 0001, Daniel Corujo, Diogo Gomes 0001, Rui L. Aguiar
Comput. Commun.5
2016 Scalable semantic aware context storage
Mário Antunes 0001, Diogo Gomes 0001, Rui L. Aguiar
Future Gener. Comput. Syst.3
2016 A secure IoT management architecture based on Information-Centric Networking
Javier Suárez, José Quevedo, Iván Vidal, Daniel Corujo, Jaime García-Reinoso, Rui L. Aguiar
J. Netw. Comput. Appl.6
2015 Multi-purpose Adaptable Business Tier Components based on Call Level Interfaces
abstract
Call Level Interfaces (CLI) play a key role in business tiers of relational and on some NoSQL database applications whenever a fine tune control between application tiers and the host databases is a key requirement. Unfortunately, in spite of this significant advantage, CLI are low level API, this way not addressing high level architectural requirements. Among the examples we emphasize two situations: a) the need to decouple or not to decouple the development process of business tiers from the development process of application tiers and b) the need to automatically adapt business tiers to new business and/or security needs at runtime. To tackle these CLI drawbacks, and simultaneously keep their advantages, this paper proposes an architecture relying on CLI from which multi-purpose business tiers components are built, herein referred to as Adaptable Business Tier Components (ABTC). Beyond the reference architecture, this paper presents a proof of concept based on Java and Java Database Connectivity (an example of CLI).
Óscar Mortágua Pereira, Rui L. Aguiar
ICIS2
2015 Predicting model for identifying the malicious activity of nodes in MANETs
abstract
For many applications based on Mobile Ad Hoc Networks (MANETs), the position of the nodes is generally hard to be determined. In sensor networks, for instance, such information may be critical for the MANETs. Additionally, one problem to be faced in this scenario is the fake parameters broadcasted by misbehaving/malicious nodes, which can either compromise results about positioning, or deplete power resources of mobile devices. Therefore, in this paper we propose a model for (1) identifying the fake parameters broadcasted in the network, and for (2) detecting the malicious/misbehaving nodes. The Linear Regression and Variance Analysis (LRVA) are both the basis for the multi-step-ahead predictions in this paper. Through NS-2 and Avrora, we simulated the movement and energy consumption of nodes in a MANET, analyzing the time series of beacon-packets exchanged in the network. As a result of the LRVA employment, the fake parameters broadcasted in the network were detected, with the malicious/misbehaving nodes identified. The simulations presented in this paper show low power consumption, which allows the jointly employment of LRVA with other security techniques in the MANETs.
Anderson A. A. Silva, Elvis Pontes, Adilson Eduardo Guelfi, I. Caproni, Rui L. Aguiar, Fen Zhou 0001, Sergio Takeo Kofuji
ISCC5
2015 Big Data, IoT, .... Buzz Words for Academia or Reality for Industry?
abstract
The concepts of Big Data have became intertwined with those of the Internet of Things, creating mental pictures of a fully connected, all-encompassing, cyber-physical world, where each and every object will contribute with information to a "fully aware" society. Academic works are presenting this as the natural evolution for our current technologies. The panel looks at these promises from the hard perspective of reality: what is being done, how much it cost, what needs to be developed, and what can be expected in the near and mid-term.
Rui L. Aguiar, Nora Benhabiles, Tobias Pfeiffer, Pablo Rodriguez 0001, Harish Viswanathan, Jia Wang 0001, Hui Zang
MobiCom1
2015 Seamless integration of Cloud and Fog networks
abstract
This work provides a way to merge Cloud Computing infrastructures with traditional or legacy network deployments, leveraging the best in both worlds and enabling a logically centralized control for it. A solution is proposed to extend existing Cloud Computing software stacks so they are able to manage networks outside the Cloud Computing infrastructure, by extending the internal, virtualized network segments. This is useful in a variety of use cases such as incremental Legacy to Cloud network migration, hybrid virtual/traditional networking, centralized control of existing networks, bare metal provisioning, and even offloading of advanced services from typical home gateways into the operator. By using what is called External Drivers, any organization can develop their own driver to support new, specific networking equipment. Our concept solution is prototyped on top of OpenStack, including changes to the API, command line interface and other mechanisms. Test results indicate that there are low penalties on latency and throughput, and that provisioning times are reduced in comparison with similar maintenance operations on traditional computer networks.
Igor Duarte Cardoso, João Paulo Barraca, Carlos Goncalves, Rui L. Aguiar
NetSoft4
2015 Secure, Dynamic and Distributed Access Control Stack for Database Applications
abstract
In database applications, access control security layers are mostly developed from tools provided by vendors of database management systems and deployed in the same servers containing the data to be protected.This solution conveys several drawbacks.Among them we emphasize: 1) if policies are complex, their enforcement can lead to performance decay of database servers; 2) when modifications in the established policies implies modifications in the business logic (usually deployed at the client-side), there is no other possibility than modify the business logic in advance and, finally, 3) malicious users can issue CRUD expressions systematically against the DBMS expecting to identify any security gap.In order to overcome these drawbacks, in this paper we propose an access control stack characterized by: most of the mechanisms are deployed at the client-side; whenever security policies evolve, the security mechanisms are automatically updated at runtime and, finally, client-side applications do not handle CRUD expressions directly.We also present an implementation of the proposed stack to prove its feasibility.This paper presents a new approach to enforce access control in database applications, this way expecting to contribute positively to the state of the art in the field.
Óscar Mortágua Pereira, Diogo Domingues Regateiro, Rui L. Aguiar
SEKE3
2015 Endowing NoSQL DBMS with SQL Features Through Standard Call Level Interfaces
abstract
To store, update and retrieve data from database management systems (DBMS), software architects use tools, like call-level interfaces (CLI), which provide standard functionalities to interact with DBMS.However, the emerging of NoSQL paradigm, and particularly new NoSQL DBMS providers, lead to situations where some of the standard functionalities provided by CLI are not supported, very often due to their distance from the relational model or due to design constraints.As such, when a system architect needs to evolve, namely from a relational DBMS to a NoSQL DBMS, he must overcome the difficulties conveyed by the features not provided by NoSQL DBMS.Choosing the wrong NoSQL DBMS risks major issues with components requesting non-supported features.This paper focuses on how to deploy features that are not so commonly supported by NoSQL DBMS (like Stored Procedures, Transactions, Save Points and interactions with local memory structures) by implementing them in standard CLI.
Óscar Mortágua Pereira, David Simões 0001, Rui L. Aguiar
SEKE3
2015 Analysis and Enhancements to Probabilistic Caching in Content-Centric Networking
abstract
In this paper, we first further investigate the use of random decision policies for caching schemes, or probabilistic caching, in Content-Centric Networking (CCN). Our main objective is to provide a mathematical model for the combination of random cache decision and least recently used (LRU) replacement policy in the content store of CCN, called LRU-PC (LRU with probabilistic caching). This analytical model contributes to the improvement on proper caching selection probability per content router, in order to achieve a good performance considering different parameters, such as the popularity of the files, cache size and others. Based on these results, the paper further contributes by extending the LRU-PC with a secondary list holding a wider view of the names of content packets that transverse a CCN node. In this case, a segment is stored in the cache with a given probability when its name is stored in this secondary list, dubbing this mechanism LRU-PCSL (LRU with probabilistic caching and a secondary list). As LRU-PC, LRU-PCSL has a constant time complexity, is scan-resistant, presents low memory requirements and is possible to implement in hardware. Evaluation results show that LRU-PCSL increases overall cache performance compared with LRU and LRU-PC.
Jaime García-Reinoso, Iván Vidal, David Díez, Daniel Corujo, Rui L. Aguiar
Comput. J.5
2015 Comprehensive performance evaluation of distributed and dynamic mobility routing strategy
Seil Jeon, Namhi Kang, Daniel Corujo, Rui L. Aguiar
Comput. Networks4
2015 Dynamic, scalable and flexible resource discovery for large-dimension many-core systems
Javad Zarrin, Rui L. Aguiar, João Paulo Barraca
Future Gener. Comput. Syst.2
2015 Secure, Dynamic and Distributed Access Control Stack for Database Applications
abstract
In database applications, access control security layers are mostly developed from tools provided by vendors of database management systems and deployed in the same servers containing the data to be protected. This solution conveys several drawbacks. Among them we emphasize: (1) if policies are complex, their enforcement can lead to performance decay of database servers; (2) when modifications in the established policies implies modifications in the business logic (usually deployed at the client-side), there is no other possibility than modify the business logic in advance and, finally, 3) malicious users can issue CRUD expressions systematically against the DBMS expecting to identify any security gap. In order to overcome these drawbacks, in this paper we propose an access control stack characterized by: most of the mechanisms are deployed at the client-side; whenever security policies evolve, the security mechanisms are automatically updated at runtime and, finally, client-side applications do not handle CRUD expressions directly. We also present an implementation of the proposed stack to prove its feasibility. This paper presents a new approach to enforce access control in database applications, this way expecting to contribute positively to the state of the art in the field.
Óscar Mortágua Pereira, Diogo Domingues Regateiro, Rui L. Aguiar
Int. J. Softw. Eng. Knowl. Eng.3
2015 D3M: Multicast listener mobility support mechanisms over distributed mobility anchoring architectures
Sérgio Figueiredo, Seil Jeon, Diogo Gomes 0001, Rui L. Aguiar
J. Netw. Comput. Appl.4
2014 A case for ICN usage in IoT environments
abstract
Information-Centric Networking (ICN) has recently emerged as a promising Future Internet architecture that aims to cope with the increasing demand for highly scalable and efficient distribution of content. Moving away from the Internet communication model based in addressable hosts, ICN leverages in-network storage for caching, multi-party communication through replication, and interaction models that decouple senders and receivers. This novel networking approach has the potential to outperform IP in several dimensions, besides just content dissemination. Concretely, the rise of the Internet of Things (IoT), with its rich set of challenges and requirements placed over the current Internet, provide an interesting ground for showcasing the contribution and performance of ICN mechanisms. This work analyses how the in-network caching mechanisms associated to ICN, particularly those implemented in the Content-Centric Networking (CCN) architecture, contribute in IoT environments, particularly in terms of energy consumption and bandwidth usage. A simulation comparing IP and the CCN architecture (an instantiation of ICN) in IoT environments demonstrated that CCN leads to a considerable reduction of the energy consumed by the information producers and to a reduction of bandwidth requirements, as well as highlighted the flexibility for adapting current ICN caching mechanisms to target specific requirements of IoT.
José Quevedo, Daniel Corujo, Rui L. Aguiar
GLOBECOM3
2014 Context storage for M2M scenarios
abstract
As the number of environmental sensors grows, it becomes increasingly difficult to manage, store and process all these sources of information. Several context representation schemes try to standardize this information, however none of them have been widely adopted. Instead of proposing yet another context representation scheme, we discuss efficient ways to deal with this diversity of representation schemes. We defined the basic requirements for flexible context storage systems, proposed an implementation and compared our implementation against two other approaches. Our solution provides more value than the remaining solutions without suffering a significant decrease in performance.
Mário Antunes 0001, Diogo Gomes 0001, Rui L. Aguiar
ICC3
2014 Enhancing openflow with Media Independent Management capabilities
abstract
The evergrowing availability of access technologies, on-line services and connected devices has been motivating the development of novel networking solutions, fostering new deployments of cloud computing, Network Function Virtualization and even mobile accesses. One of the core aspects supporting these innovative solutions is the Software Defined Networking (SDN) concept, which brings added configuration and management capabilities to the network fabric, aiding the support and introduction of new technologies and protocols. However, the base operations of SDN do not consider link conditions when employing their controlling mechanisms and mostly target fixed core links. These link conditions are important to optimizations involving wireless access links, which are paramount in today's plethora of wireless and mobile accesses. This paper enhances SDN mechanisms with Media Independent Management capabilities, deployable in both wired and wireless environments, optimizing link connectivity establishment and offering new perspectives to network developers for building new capabilities in the networks. The resulting framework was implemented over open-source software in a physical testbed, with results showing the benefits that this solution brings in terms of path optimization, featuring different monitoring schemes and allowing energy efficient scenarios.
Carlos Guimarães, Daniel Corujo, Rui L. Aguiar
ICC3
2014 Energy efficient interference-aware resource allocation in LTE-D2D communication
abstract
Interference management is an important subject in Device to Device (D2D) communication when underlying a LTE-A cellular band. By default, in LTE-A there is negligible intra-cell interference due to the orthogonality of the subcarriers but this orthogonality will be lost when D2D communication takes place under cellular users (CU). Therefore, one of the key aspects of D2D communication is the set of spectrum bands in which D2D communication takes place. Hence, in this paper we will propose two novel resource allocation (RA) schemes: the first RA scheme (cell level) mitigates the interference between D2D and CU and the second RA scheme (user level or scheduling) schedules the resources in an energy efficient way between D2D and CU. These RA schemes increase the throughput and reduce the overall energy cost per bit of the system. Afterwards, these schemes are compared with the conventional methods and the simulation results show that the proposed schemes obtain higher throughput and save significant amount of energy per bit.
Shahid Mumtaz, Kazi Mohammed Saidul Huq, Ayman Radwan, Jonathan Rodriguez 0001, Rui L. Aguiar
ICC5
2014 Message from the general co-chairs
abstract
Welcome to the 19th IEEE Symposium on Computers and Communications (ISCC), which is being held on the beautiful island of Madeira, Portugal. In the past, this conference has been held in Croatia, Egypt, France, Greece, Italy, Morocco, Portugal, Spain, Tunisia, and Turkey. The 12th ISCC was held in Aveiro, Portugal in 2007, and we are excited to return to Portugal after 7 years. Madeira, known as the “Pearl of the Atlantic”, is a place with such a diversity of environments, from the sun to the mountains, from the night life to the cuisine, from the wonderful nature to the friendliness of its people, can cater to all tastes. We hope you will be able to sample some of the delights of this truly fascinating place.
Rui L. Aguiar, Sartaj Sahni
ISCC1
2014 Energy efficiency optimization in MU-MIMO system with spectral efficiency constraint
abstract
Multiuser MIMO (MU-MIMO), in which the base station transmits multiple streams to multiple users, has received significant importance as a way of achieving spectral efficiency (SE) and energy efficiency (EE). However, these two important design criteria conflict with each other and a careful study of their trade-off is mandatory for designing future wireless communication systems. This paper investigates the trade-off between EE and SE in downlink MU-MIMO system which is adopted by 3GPP LTE-Advanced to meet IMT-Advanced targets. The EE is measured as, “throughput (bits) per Joule” while both RF transmit power and circuit power consumptions are considered. In this paper, given the SE requirement, a constrained optimization problem where constraints redefined with cubic inequality is formulated to maximize EE. Then, a novel resource allocation algorithm is proposed to achieve maximum EE. Simulation results demonstrate the effectiveness of the proposed scheme and illustrate the fundamental trade-offs between energy efficient and spectral efficient transmission. Our analytical results shed light on future “green” network planning in downlink MU-MIMO systems.
Kazi Mohammed Saidul Huq, Shahid Mumtaz, Jonathan Rodriguez 0001, Rui L. Aguiar
ISCC4
2014 Role-Based Access control mechanisms
abstract
Most of the security threats in relational database applications have their source in client-side systems when they issue requests formalized by Create, Read, Update and Delete (CRUD) expressions. If tools such as ODBC and JDBC are used to develop business logics, then there is another source of threats. In some situations the content of data sets retrieved by Select expressions can be modified and then committed into the host databases. These tools are agnostic regarding not only database schemas but also regarding the established access control policies. This situation can hardly be mastered by programmers of business logics in database applications with many and complex access control policies. To overcome this gap, we extend the basic Role-Based Access policy to support and supervise the two sources of security threats. This extension is then used to design the correspondent RBAC model. Finally, we present a software architectural model from which static RBAC mechanisms are automatically built, this way relieving programmers from mastering any schema. We demonstrate empirical evidence of the effectiveness of our proposal from a use case based on Java and JDBC.
Óscar Mortágua Pereira, Diogo Domingues Regateiro, Rui L. Aguiar
ISCC3
2014 Entity title architecture extensions towards advanced quality-oriented mobility control capabilities
abstract
The emergence of new technologies, in addition with the popularization of mobile devices and wireless communication systems, demands a variety of requirements that current Internet is not able to comply adequately. In this scenario, the innovative information-centric Entity Title Architecture (ETArch), a Future Internet (FI) clean slate approach, was design to efficiently cope with the increasing demand of beyond-IP networking services. Nevertheless, despite all ETArch capabilities, it was not projected with reliable networking functions, which limits its operability in mobile multimedia networking, and will seriously restrict its scope in Future Internet scenarios. Therefore, our work extends ETArch mobility control with advanced quality-oriented mobility functions, to deploy mobility prediction, Point of Attachment (PoA) decision and handover setup meeting both session quality requirements of active session flows and current wireless quality conditions of neighbouring PoA candidates. The effectiveness of the proposed additions were confirmed through a preliminary evaluation carried out by MATLAB, in which we have considered distinct applications scenario, and showed that they were able to outperform the most relevant alternative solutions in terms of performance and quality of service.
Felipe Sampaio Dantas da Silva, José Castillo Lema, Augusto Neto 0001, Flávio Oliveira Silva 0001, Pedro Frosi Rosa, Daniel Corujo, Carlos Guimarães, Rui L. Aguiar
ISCC8
2014 A self-organizing and self-configuration algorithm for resource management in service-oriented systems
abstract
With the ever increasing deployment of service-oriented distributed systems in large-scale and heterogeneous computing environments, clustering and communication overlay topology design has become more and more important to address several challenging issues and conflicting requirements, such as efficient scheduling and distribution of services among computing resources, reducing communication cost between services, high performance service and resource discovery while considering both inter-service and inter-node properties and also increasing the load distribution and the load balance. In this paper, a four-stage hierarchical clustering algorithm is proposed which automates the process of the optimally composing communicating groups in a dynamic way while preserving the proximity of the nodes. The simulation results show the performance of the algorithm with respect to load balance, scalability and efficiency.
Javad Zarrin, Rui L. Aguiar, João Paulo Barraca
ISCC2
2014 Extending RBAC Model to Control Sequences of CRUD Expressions
Óscar Mortágua Pereira, Diogo Domingues Regateiro, Rui L. Aguiar
SEKE3
2014 IEEE 802.21-enabled Entity Title Architecture for handover optimization
abstract
The explosion of demanding on-line services, such as video, is increasingly stressing the Internet architecture, requiring new solutions to support future usage scenarios. New Future Internet approaches targeting Information Centric Networking, such as the Entity Title Architecture (ETArch), provide new optimizations for these scenarios, using novel mechanisms such as Software Defined Networking (SDN). However, these are not targeted to address another growing Internet challenge reflecting the increase in multi-technology wireless mobile access. In this work, we empowered ETArch with Media-Independent mechanisms from the IEEE 802.21 standard, optimizing content delivery in wireless mobile scenarios. The resulting framework was implemented in a physical testbed of the OFELIA project, with results showing that the defined mechanisms supported seamless handover avoiding packet loss at a reduced overhead cost, when compared with the base ETArch. Moreover, the media-independent nature of these enhancements allows the framework to be deployed in different access technologies, in a flexible way.
Carlos Guimarães, Daniel Corujo, Flávio Oliveira Silva 0001, Pedro Frosi Rosa, Augusto Neto 0001, Rui L. Aguiar
WCNC6
2014 MI3M: A framework for media independent multicast mobility management
Sérgio Figueiredo, Carlos Guimarães, Daniel Corujo, Rui L. Aguiar
Comput. Networks4
2014 Multicast group membership management in media independent handover services
Carlos Guimarães, Daniel Corujo, Antonio de la Oliva, Yoshihiro Ohba, Rui L. Aguiar
Comput. Networks5
2014 A novel energy efficient packet-scheduling algorithm for CoMP
Kazi Mohammed Saidul Huq, Shahid Mumtaz, Jonathan Rodriguez 0001, Rui L. Aguiar
Comput. Commun.4
2013 Reusable business tier architecture driven by a wide typed service
abstract
Call Level Interfaces (CLI) are difficult to use mainly in intensive database applications with many Create, Read, Update and Delete (CRUD) expressions. As low level API, they are not suited to promote the development process of business tiers as reusable components, leading to the need of writing additional source code whenever a new CRUD expression is needed. To tackle this gap, this paper proposes an architecture for building reusable business tier components herein referred to as Reusable Business Tier Architecture (RBTA). It relies on a single customizable wide typed service to address a business area, such as accounting. The typed service is able to manage all the required CRUD expressions for that business are, which are deployed at runtime in accordance with the user's needs. The only constraint is that the required service to manage each CRUD expression must be a sub-set of the implemented wide typed service. A proof of concept based on Java Database Connectivity (JDBC) is also presented.
Óscar Mortágua Pereira, Rui L. Aguiar, Maribel Yasmina Santos
ICIS2
2013 Recognizing entities across protocols with unified UUID discovery and asymmetric keys
abstract
The Internet-of-Things vision introduces scenarios composed of many devices and protocols, in order to support real world user interactions. This also brought a fractured vision, since it is hard to extend communication over diverse technologies, even for communication with the same devices. In this paper we propose to address the fractured loT ecosystem using a UUID based discovery layer that allows recognising entities across different protocols. By using asymmetric keys as the basis for a UUID device identification namespace, we provide a stable identification layer that enables recognizing entities (devices) across protocols and simultaneously retaining a security context over different protocols. We use this identification and discovery layer as the basis for an integrated framework where communication between devices can happen over any available channel or technology. The framework is instantiated in an experimental prototype, used to assess the pragmatic changes and overall impact of using a cross-protocol identification scheme.
Rui Ferreira 0001, Rui L. Aguiar, Alfredo Matos
GLOBECOM2
2013 Empowering software defined wireless Networks through Media Independent Handover management
abstract
Internet access and service utilization has been exploding in mobile devices, through the leverage of WLAN, 3G and now LTE connections. It is this explosion as well that is stressing the underlying fabric of the Internet, and motivating new solutions, such as Software Defined Networking (SDN), to build the controlling support and extension capabilities of the Future Internet. However, SDN has yet to reach the necessary traction to be deployed, and has been more relayed towards experimentation supporting frameworks and away from wireless environments. This paper explores SDN mechanisms and increments them with Media Independent Handover services from the IEEE 802.21 standard, coupling them in a single framework for the dynamic optimized support of OpenFlow path establishment and wireless connectivity establishment. The framework was implemented over open-source software in a physical testbed, with results showing the benefits that this solution brings in terms of performance and signaling overhead, when compared with more basic approaches.
Carlos Guimarães, Daniel Corujo, Rui L. Aguiar, Flávio Oliveira Silva 0001, Pedro Frosi Rosa
GLOBECOM3
2013 Broadcasting user content over novel mobile networks
abstract
In the "Youtube Era", mobile consumption of video, such as Video on Demand (VoD) and User Generated Content (UGC), has been steadily increasing. However, mobile networks are showing to be unprepared for such phenomenal traffic volume, whereas the devices' multiple interfaces are being exploited to address this problem. As such, the interest in offloading techniques has significantly increased, not only at access level, but also at IP layer — boosting solutions based on Distributed Mobility Management (DMM) technologies. Connectivity management taking into account different applications requirements and multiple interfaces calls for a cross-layer solution, where IEEE 802.21 Media Independent Handover (MIH) may take a crucial role. In this paper, we describe an architecture for the support of UGC over the upcoming mobile networks using DMM and IEEE 802.21 concepts. We develop two entities, the Connection Manager and Flow Manager, for managing the connections throughout all the mobility session for either video producers or consumers. We implemented a real testbed in which we collect throughput and packet loss statistics on usage scenarios. The provided results show how the Connection Manager can be used to automatically take advantage of multiple interfaces and how the Flow Manager can be used to trigger multicast context transfer, with added performance results.
Sérgio Figueiredo, Carlos Guimarães, Rui L. Aguiar, Liron Yadin, Tien-Thinh Nguyen, Nuno Carapeto, Carlos Parada
ICC3
2013 Runtime Values Driven by Access Control Policies - Statically Enforced at the Level of Relational Business Tiers
Óscar Mortágua Pereira, Rui L. Aguiar, Maribel Yasmina Santos
SEKE2
2012 Breaching location privacy in XMPP based messaging
abstract
Privacy is an increasingly important theme in communications. With increasing mobile users, previously neglected aspects as location privacy become important in our social life. Currently, Instant Messaging applications are considered to have a strong privacy model between users, because all communications are mediated by the service. In this paper, we analyse IM under the light of location privacy. We devise a set of potential attacks, and analyse the behaviour of many systems under these attacks. Our results show that while not all implementations are vulnerable, some popular IMs are breachable by one or more of these location privacy attacks. With browser based and mobile implementations being less vulnerable because they tend to provide a reduced set of features, thus reducing the attack surface.
Rui Ferreira 0001, Rui L. Aguiar
GLOBECOM2
2012 Evaluation of discovery mechanisms for Media Independent Handover services
abstract
The proliferation of mobile terminals coupled with multiple wireless interfaces has created complex scenarios where network operators need to provide connectivity in heterogeneous environments. To facilitate handover procedures in these scenarios, the 802.21 standard has been specified, providing Media Independent Handover (MIH) services allowing control and information gathering from different access interfaces. However, accessing these procedures requires the discovery of supporting nodes and their capabilities. This paper provides a description and performance comparison of different available MIH discovery schemes and proposes a novel local discovery procedure for automatically detecting link interfaces in MIH-enabled entities, showing by evaluation that its deployment increases performance and requires less information exchange.
Daniel Corujo, Carlos Guimarães, Rui L. Aguiar
ICC3
2012 Furthering media independence mechanisms for Future Internet enablement
abstract
The utilization of Media Independent Handover (MIH) mechanisms, such as the ones provided by the IEEE802.21 standard, allow the abstraction of control and information querying primitives of different wireless access technologies, using a common interface. This not only simplifies the design of high-level entities interfacing with said technologies, but by providing a transport protocol for that interface, such primitives can be used to extend controlling mechanisms towards remote entities. However, the standard only employs such flexible and abstraction capabilities towards handover optimization and facilitation scenarios. In this paper, we take advantage of the flexible design of the MIH mechanisms, and propose evolutions over their base design, allowing their integration into the areas of Internet Multimedia Optimization and the Internet of Things.
Daniel Corujo, Marcelo Lebre, Diogo Gomes 0001, Rui L. Aguiar
ICC4
2012 Low-latency privacy-enabled Context Distribution Architecture
abstract
As personal information and context sharing applications gain traction more attention is drawn to the associated privacy issues. These applications address privacy using an unsatisfactory “whitelist” approach, similar to social networks “friends”. Some of them also link location publishing with user interaction which is also a form of privacy control - the user has to explicitly say where he is. There are a few automatic location based-services (LBS) that track the user, but without more adequate privacy protection mechanisms they enable even bigger threats to the user. On previous work, an XMPP-based Context Distribution Architecture was defined, more suitable for the distribution of frequently changing context than other systems because it is based on the publish-subscribe pattern. In this paper the authors present an extension to this architecture that allows for the introduction of a complex degree of access control in context distribution. The devised changes enable the system to consider a number of interesting context privacy settings for context distribution control. Also, this control must be enforced in a way that it doesn't interfere with the real-time nature of the distribution process. After describing the enhancements to the architecture, a prototype of the system is presented. Finally, the delivery latency and additional processing introduced by the access control components is estimated by testing it against the existing system.
João M. Gonçalves, Diogo Gomes 0001, Rui L. Aguiar
ICC3
2012 Comparison of energy-efficiency in bits per joule on different downlink CoMP techniques
abstract
Coordinated MultiPoint (CoMP) transmission / reception techniques have been adopted by the 3GPP community for LTE-Advanced (Long Term Evolution-Advanced) to increase spectral efficiency and cell-edge throughput. Energy efficiency (EE) was previously ignored by most research efforts and was not considered by 3GPP as an important performance indicator until very recently. EE concerns have spurred considerable research in recent years as they enable both energy consumption and CO2 reduction over conventional cellular systems. As the “green evolution” becomes a major trend, energy-efficient transmission becomes more and more important. In this paper we investigate energy efficiency i.e., the number of corrected bits that can be transmitted throughout the channel per joule of energy consumed of different downlink CoMP techniques in LTE-Advanced. In addition, we use system level simulation to evaluate the performance.
Kazi Mohammed Saidul Huq, Shahid Mumtaz, Jonathan Rodriguez 0001, Rui L. Aguiar
ICC4
2012 Dynamic and scalable provisioning in wireless mesh networks to efficiently support multi-user killer-applications with high-demand of resources
abstract
The success of mobile and ubiquitous computing, coupled with the increasing demand for applications with high Quality of Service (QoS) and Quality of Experience (QoE) requirements, has brought great challenges to the future access networks. Thus, wireless mesh networks distinguish due to its flexibility, redundancy, low-cost and broadband capacity. However, aspects as scalability, availability and reliability, are still challenging. Following the limitations of existing solutions, this paper proposes the Multi-Service Resource Allocation in Wireless Mesh Networks (MIRA-WMN) for provisioning resources of wireless mesh networks compliant with IEEE 802.11e/s standard. The MIRA-WMN proposes a single solution to integrate QoS and connectivity resource control to efficiently support multi-user sessions. The MIRA-WMN was evaluated by simulations, which demonstrated its benefits in the data and control plane, as well as user's perception.
Augusto Neto 0001, Eric Patrick, Eduardo Cerqueira, Danielo Goncalves Gomes, Rui L. Aguiar
ICC5
2012 BTA: Architecture for Reusable Business Tier Components with Access Control
Óscar Mortágua Pereira, Rui L. Aguiar, Maribel Yasmina Santos
ICCSA (3)2
2012 Figures of merit for the placement (in) efficiency of interconnected CDNs
abstract
CDN interconnection is currently being debated across industry, academia and standards organizations, both in terms of proposing mechanisms for inter-CDN cooperation, such as architectures and protocols, and in terms of the conditions under which cooperation is advantageous. In this paper we focus on the second part and provide contributions to the fundamental problem of when two CDNs should cooperate. Given two CDNs, we aim at quantifying the loss in provisioning efficiency that arises from inter-CDN cooperation. We solve a CDN placement problem in interconnection scenarios, in order to compare the cost of centrally provisioning a network with the joint cost of provisioning the same topology but partitioned and with both sub-topologies independently and only locally optimally provisioned. Given the complexity of the topic (particularly the computational cost) but also aiming at general figures of merit, we use a non-capacitated K-median problem and solve the problem for a large number of topologies. Among other results, we show that the incurred inefficiency of provisioning the same topology partitioned in two independent CDNs, but locally optimal, can raise up to 30%. Overall, we demonstrate with exact solutions that interconnection may not be straightforwardly advantageous.
Vitor Jesus, Rui L. Aguiar
ISCC2
2012 Visible light communications in intelligent transportation systems
abstract
Emerging intelligent transportation systems (ITS) are based on several technologies. A new concept of integrating visible light communications (VLC) in ITS is introduced in this paper. VLC in ITS is a cost effective method of implementation. This paper presents a VLC broadcast system considering LED-based traffic lights. It discusses the integration of traffic light road side unit (RSUs) within the existing ITS architecture. A prototype demonstrator of the designed VLC systems is also presented. A robust modulation technique based on direct sequence spread spectrum (DSSS) sequence inverse keying (SIK) has been implemented to minimize the effect of noise sources. Experimental results show data communication range of over 40m with 200mm custom designed traffic light, even during bright sun light.
Nuno Lourenço 0001, Domingos Terra, Luís Nero Alves, Rui L. Aguiar
Intelligent Vehicles Symposium5
2012 Use-cases analysis for multicast listener support in network-based distributed mobility management
abstract
With the explosion in traffic consumption, the limitations of centralized mobility protocols became a concern. As a result, the concept of distributed mobility management (DMM) emerged. Basically, DMM brings the mobility anchors closer to the users, avoiding issues as single point of failure and non-optimal routing. On the other hand, IP multicast, being designed for efficiency, is a key method for alleviating traffic load, but no work has been done in identifying how IP multicast may be supported using this new DMM paradigm. This paper presents different mobility schemes for providing multicast listener support in network-based DMM scenarios. All schemes rely on the usage of MLD Proxy, and differ in distribution and proactivity degrees. The schemes were evaluated from a user perspective by estimating the service disruption time. Moreover, the sensitivity of each of the schemes to three different aspects is shown both qualitatively and by numerical results: users' session to mobility ratio (SMR), host reattachment time after handoff, and tunnel congestion.
Sérgio Figueiredo, Seil Jeon, Rui L. Aguiar
PIMRC3
2012 ACADA: Access Control-driven Architecture with Dynamic Adaptation
Óscar Mortágua Pereira, Rui L. Aguiar, Maribel Yasmina Santos
SEKE2
2012 MINDiT: A framework for media independent access to things
Daniel Corujo, Marcelo Lebre, Diogo Gomes 0001, Rui L. Aguiar
Comput. Commun.4
2012 A dynamic jitter model to evaluate uncertainty trends with technology scaling
Monica Figueiredo, Rui L. Aguiar
Integr.2
2012 Mobility and Network Management in Virtualized Networks
Kostas Pentikousis, Ramón Agüero, Susana Sargento, Rui L. Aguiar
Mob. Networks Appl.4
2012 QoS-RRC: an overprovisioning-centric and load balance-aided solution for future internet QoS-oriented routing
Augusto Neto 0001, Leandro Freitas, Eduardo Cerqueira, Rui L. Aguiar, Danielo Goncalves Gomes
Multim. Tools Appl.4
2012 Virtual network stacks: from theory to practice
abstract
ABSTRACT Privacy is becoming a pressing requirement that spawns across different network layers and user interactions. Using multiple identifiers for the same user, pseudonyms, as means for preserving privacy, is becoming an important approach that has not seen proper discussion or validation. This paper presents formalization on pseudonymity specially considering its influence on the network stack. It presents a study on privacy requirements and its implementation cost, both at theoretical and practical levels, through the support of multiple network stack instantiations and network identifiers per user. We discuss how pseudonyms can be used to preserve users' privacy, and what key issues and requirements are needed, to use, control, and evaluate a pseudonym‐based solution at network level. The paper further presents an architecture that builds a pseudonym‐based solution supported throughout the network stack, describes its implementation in a real testbed, and depicts the results obtained related to both efficiency and costs of such a privacy approach. Finally, it discusses the characteristics of the architecture according to the identified privacy requirements, its impacts and constraints. Copyright © 2011 John Wiley & Sons, Ltd.
Alfredo Matos, Rui Ferreira 0001, Susana Sargento, Rui L. Aguiar
Secur. Commun. Networks4
2011 A Reusable Business Tier Component with a Single Wide Range Static Interface
Óscar Mortágua Pereira, Rui L. Aguiar, Maribel Yasmina Santos
ECSA2
2011 An Adaptable Business Component based on Pre-defined Business Interfaces
Óscar Mortágua Pereira, Rui L. Aguiar, Maribel Yasmina Santos
ENASE2
2011 Waypoint Routing: A Network Layer Privacy Framework
abstract
This paper presents a routing framework that embeds location and communication privacy into the routing mechanisms. It conceals endpoint identification by introducing waypoints, through encrypted routing hints, where each waypoint has knoweldge of the next hop, assuring network privacy over several waypoints. Based on IPv6 extension headers and Onion Routing techniques, the network waypoints comply with normal routing procedures, avoiding explicit tunneling or full packet encryption. By focusing on the network as a cooperative entity for privacy preservation, we propose a lightweight approach that can be easily deployed, establishing a good compromise between privacy and optimal routing.
Alfredo Matos, Susana Sargento, Rui L. Aguiar
GLOBECOM3
2011 Dynamic jitter accumulation in clock repeaters considering power and ground noise correlations
abstract
This paper discusses the mechanism behind dynamic jitter accumulation in clock repeaters, considering the impact of power supply noise correlations. We show that differential and common mode noise have a different impact on jitter accumulation, depending on correlations between cascaded repeater stages. We also propose a simple accumulation model that can be used to replace time-consuming transient noise simulations. Besides providing an useful insight regarding the impact of noise correlations on jitter accumulation, the model's accuracy is shown to be within 10% of SPICE results.
Monica Figueiredo, Rui L. Aguiar
ISCAS2
2011 Network interfaces flying over IP networks
abstract
We propose a novel method to export both interface control and data planes across different hosts, effectively enabling hardware specific control of network interfaces over the Internet, or from a host to its virtualized guests. Our solution is a major step towards distributed environments of heterogeneous communication systems, particularly relevant in the scope of custom system composition, remote development and testing, and is especially relevant when considering embedded or geographically constrained devices. Results obtained by our prototype implementation validate the effectiveness of the solution. We present a preliminary characterization of its impact, when considering traffic generation applications, when applied over an IEEE 802.11g communication medium.
João Paulo Barraca, Alexandre Brito, Rui L. Aguiar
ISCC3
2011 Hint-driven DNS resolution
abstract
A common form of optimisation of DNS name resolution is for authoritative name servers to base their replies on the source IP address of the resolver in order to improve the performance of services in that namespace. In this paper we explore a different approach, where the querying resolver explicitly includes a hint in DNS queries, allowing nameservers to implement optimisations based on hints supplied by the application resolving a DNS query. Our solution differs in purpose and approach, since it explores user handles from the services that own the nameservers as resolution hints, and considers the resolver as explicitly involved in this process. In particular, we explore the case where this hint is identity-related, and discuss the security implications of such a use case.
Rui Ferreira 0001, Alfredo Matos, Rui L. Aguiar
ISCC3
2011 Visible light communication for intelligent transportation in road safety applications
abstract
This paper discusses the implementation of a light emitting diode based visible light communication system, for intelligent transportation in road safety applications. The signal processing of both, transmitter and receiver are realized in a field programmable gate array using two Spartan-3E development kits. The implemented modulation scheme is based on direct sequence spread spectrum techniques. The performance of the overall system is evaluated and results are presented. It is found that the system is well suited for traffic broadcast at low data rate and medium range. The simulation results also show that spread spectrum modulation techniques mitigate the effect of noise produced by ambient artificial light sources.
Domingos Terra, Nuno Lourenço 0001, Luís Nero Alves, Rui L. Aguiar
IWCMC5
2011 Sensor context information for energy-efficient optimization of wireless procedures
abstract
The wide deployment of Wireless Local Area Networks (WLAN) we are witnessing today increases connectivity opportunities for mobile terminal devices, such as smartphones. However, continuous scanning for WLAN points of attachment can be a power exhausting mechanism for such battery-powered devices. These mobile devices, besides being equipped with different wireless access interfaces, are also coupled with sensors such as accelerometer, GPS, luminance and magnetic compass. In fact, sensors are increasingly being coupled into different devices and environments and are able to convey sensing information through networks into decision entities able to optimize different processes. In this paper we propose a framework where media independent sensing information is used to enhance wireless link management towards energy-efficiency. This framework enables the dissemination of sensing information towards local and remote decision entities, enhancing other processes (e.g. mobility) with sensing information in order to provide true Ambient Intelligence scenarios. We introduce this framework into a wireless management scenario able to provide energy-efficient optimal network connectivity.
Daniel Corujo, Marcelo Lebre, Diogo Gomes 0001, Rui L. Aguiar
PIMRC4
2011 Metrics for optimal relay selection in cooperative wireless networks
abstract
A key design issue in relay based cooperative wireless networks is the metrics used for relay selection. Internal operational parameters and network sensing parameters are two categories recently considered as decision factors for cooperation strategies. We focus on the impact of these potential sensing parameters as indicators of the effective cooperation, from the perspective of the network layer, namely: movement, medium access delay and medium delay ratio. Simulation results indicate a strong correlation between network performance and the proposed cooperative metrics. Novel solutions for cooperation should take these metrics into consideration in order to provide better network performance.
Rasool Sadeghi, João Paulo Barraca, Rui L. Aguiar
PIMRC3
2011 IEEE 802.21 Information services deployment for heterogeneous mobile environments
abstract
In the future mobile Internet, a key challenge is how the content is delivered to the mobile user, especially when there are multiple networks belonging to distinct operators. Knowing the network services and conditions available at each one becomes crucial. In order to store information from several networks and operators, the new IEEE 802.21 standard specifies a Media Independent Information Service (MIIS) supporting various information elements (IEs) that provide network information within a geographical area, with the aim of optimising the handover process. Since next-generation wireless devices are expected to support multiple radio access networks, users will be able to maintain connections when switching from one network to another. This article addresses a general approach towards the deployment of a Hierarchical 802.21 Information Service management infrastructure in a heterogeneous mobile environment. Through an NS-2-based simulation, it is shown that the proposed scheme improves the user experience in terms of MIIS server access time and number of optimal handovers in a random mobility scenario.
Fábio Buiati, Luis Javier García Villalba, Daniel Corujo, Susana Sargento, Rui L. Aguiar
IET Commun.5
2011 Topological Implications of Cascading Interdomain Bilateral Traffic Agreements
abstract
The Internet uses a model in which Autonomous Systems (AS) peer bilaterally with each other, resulting in a cascaded connectivity model: the end-to-end service that an end-user sees is the result of this cascade of bilateral traffic agreements. As a result, the routing decisions at each AS beyond the next hop are implicitly delegated, so an AS has limited control over the remaining path. While this may be considered a key feature of the Internet (e.g., helps scalability), the impact of this cascading model on the structure of the Internet is not yet well understood. In this paper, we analyze this cascaded model using concepts of game theory. Although our model cannot capture the full complexity of the real Internet - we actually aim at simplicity and try to only isolate the cascading effect -, our results suggest that cascading bilateral agreements brings order to an arbitrary graph. In particular, it brings forward some well-known properties of the Internet topology, such as the current AS hierarchy and common peering models. Finally, we compare our results with topological and routing data, obtained from CAIDA, looking for experimental evidence of our results, while further exploring the insight obtained from our model.
Vitor Jesus, Rui L. Aguiar, Peter Steenkiste
IEEE J. Sel. Areas Commun.2
2010 Discovery and Composition of Per-Domain Behaviours - a Service Abstraction Approach
abstract
We discuss the problem of composing Quality-of-Service across several administrative domains considering an evolved DiffServ notion of Per-Domain Behavior (PDB). We discuss two components of the problem: path discovery and the effect of composing PDBs. We assume the most general scenario: domains are free to adopt any PDB, as long there are common semantics and a set of well-known QoS parameters (e.g. one-way delay, peak/sustained bandwidth, etc.). Thus we adopt an abstract representation of PDBs. We obtain three main results. First, we show that a distributed path discovery scheme is feasible and more scalable than a centralized one. Second, we show the outcome of inter-domain QoS composition, for general metrics and for Internet-alike topologies. Finally, and as an important practical result, we show that the Internet may not need a centralized governance model, in terms of the definition of inter-domain PDBs.
Vitor Jesus, Rui L. Aguiar, Peter Steenkiste
ICC2
2010 CRUD-DOM: A Model for Bridging the Gap between the Object-Oriented and the Relational Paradigms
abstract
Object-oriented programming is the most successful programming paradigm. Relational database management systems are the most successful data storage components. Despite their individual successes and their desirable tight binding, they rely on different points of view about data entailing difficulties on their integration. Some solutions have been proposed to overcome these difficulties, such as Embedded SQL, object/relational mappings (O/RM), language extensions and even Call Level Interfaces (CLI), as JDBC and ADO.NET. In this paper we present a new model aimed at integrating object-oriented languages and relational databases, named CRUD Data Object Model (CRUD-DOM). CRUD-DOM relies on CLI (JDBC) and aims not only at exploring CLI advantages as preserving its performance and SQL expressiveness but also on providing a type state approach for the implementation of the ResultSet interface. The model design aims to facilitate the development of automatic code generation tools. We also present such a tool, called CRUD Manager (CRUD-M), which provides automatic code generation with a complementary support for software maintenance. This paper shows that CRUD-DOM is an effective model to address the aforementioned objectives.
Óscar Mortágua Pereira, Rui L. Aguiar, Maribel Yasmina Santos
ICSEA2
2010 Wireless access architectures for video applications: the approach proposed in the MEDIEVAL project
abstract
Video transmission is expected to be the next big thing in personal communication systems. While text messaging applications have already experienced an explosive growth, the exchange of multimedia content is still lacking architectural solutions which enable it to become the next killer application. The EU project MEDIEVAL (MultimEDia transport for mobIlE Video AppLications) aims at filling this gap. In this paper we describe the approaches envisioned by the project for what concerns the data link layer, with special emphasis on wireless access and its related cross-layer issues. After presenting some general project aspects, we will review the state of the art and enumerate several open issues, concerning the identification of the most suitable radio technologies for video support, as well as their integration and required enhancements to enable efficient video transport.
Leonardo Badia, Rui L. Aguiar, Albert Banchs, Telemaco Melia, Michelle Wetterwald, Michele Zorzi
ISCC2
2010 QoS-RRC: Integrated QoS routing and resource provisioning mechanism for future internet
abstract
Generic Path (GP) is a new connectivity paradigm proposed to facilitate the inclusion of new applications and services abstracting communications between entities, regardless of their location or architectural layer. This paper enhances the GP architecture with a new mechanism integrating QoS-Routing and Resource Control (QoS-RRC) strategies to dynamically control GP session requirements regarding QoS and connectivity. This solution uses over-provisioning and admission control, and is aimed at multi-party time-sensitive sessions. Initial performance evaluation was carried out in Network Simulator v.2 (NS-2), showing capabilities in reducing overall signaling load in comparison with a value-added per-flow approach.
Augusto Neto 0001, Sérgio Figueiredo, Leandro Marçal, Rui L. Aguiar
ISCC4
2010 Managing QoS-Enabled "Information Transport" as any Other Service in NGN Service Platforms
abstract
Transporting information from one end to the other of the network is one of the most prominent services offered by telecommunication operators, what we term the "information transport" service. Its efficient management, considering aspects like tariffs or QoS (Quality of Service), attracts much interest and research efforts. The new "frontier" is to integrate this service in the whole service delivery chain making the different stakeholders in the telecommunication business cooperate. The IMS (IP Multimedia Subsystem) service platform offers solutions embracing the current trend of respecting the Internet paradigm of transport and application layers separation, yet building interfaces between both domains. But IMS approach relegates the "information transport service" to a mere resource. This bundles IMS applicability. We propose that "information transport" regains its service status. Existing service management and composition techniques could be employed resulting on increased flexibility, new business possibilities and a better end service. We show the advantages of our approach compared to existing solutions, we discuss its complexity and analyze if it is feasible in NGN (next generation networks) and whether it is worth.
Antonio Cuevas, José Ignacio Moreno, Rui L. Aguiar
WCNC3
2009 Supporting Dynamic Inter-Domain Network Composition: Domain Discovery
abstract
When two administratively independent domains need to engage in cooperation of some kind, some initial common known point of contact must exist, both in terms of the application topological position (i.e., IP address, transport protocol and port) and in terms of the interface technology (e.g., the protocol suite of the interaction). In a world of many domains of many types (not necessarily autonomous systems in the sense of interdomain routing), manual or single-directory-based operations are not practical (or even feasible); hence, some form of autonomic discovery and handshaking of domains is needed. We propose and evaluate several strategies to allow autonomic bootstrapping of inter-domain operations, all fit to be deployed as BGP extensions. We show the time/message overhead tradeoff: it's possible to obtain the absolute minimum message complexity of O(N) but at the cost of central administrative burden or, for fully distributed schemes, a tradeoff (message/time complexity) of O(N2)/O(N) or O(N2)/O(log2N).
Vitor Jesus, Rui L. Aguiar, Peter Steenkiste
ICC2
2009 An evaluation of network management protocols
abstract
During the last decade several network management solutions have been proposed or extended to cope with the growing complexity of networks, systems and services. Architectures, protocols, and information models have been proposed as a way to better respond to the new and different demands of global networks. However this offer also leads to a growing complexity of management solutions and to an increase in systems' requirements. The current management landscape is populated with a multiplicity of protocols, initially developed as an answer to different requirements. This paper presents a comparative study of currently common management protocols in All-IP networks: SNMP, COPS, Diameter, CIM/XML over HTTP and CIM/XML over SOAP. This assessment was focused on wireless aspect issues, and as such includes measures of bandwidth, packets, round-trip delays, and agents' requirements. We also analyzed the advantages of compression in these protocols.
Pedro Gonçalves 0001, José Luís Oliveira, Rui L. Aguiar
Integrated Network Management3
2009 Time Precision Comparison of Digitally Controlled Delay Elements
abstract
This paper compares the time precision of different digitally controlled delay cells. Other design metrics as delay, signal integrity, power and area are also considered. The precision is evaluated by the cell's uncertainty, given as the ratio between jitter and time delay, considering both thermal and power supply noise. The comparison is based on circuit simulation, in a 180 nm technology, using the SPECTRE tool from Cadence. The comparison results will help the designer to choose the most appropriate delay cell for low uncertainty design.
Monica Figueiredo, Rui L. Aguiar
ISCAS2
2008 Managing community aware Wireless Mesh Networks
abstract
Wireless mesh networks, due to their typical architecture and deployment, are able to respond to user expectations as no other technology allows. Its typical multi-level approach facilitates local interactions by nearby wireless nodes from multiple users. Also, adaptation to user expectations on a dynamic manner is able to of further enhancing the capacity of these networks, while increasing its ubiquity. Nevertheless, these networks have no management model. In the paper we present the foundations for a management model for community aware networking. Design challenges for community management are identified and a management framework supporting the relevant concepts, linking social aspects and technology, is described.
João Paulo Barraca, Rui L. Aguiar
ISCC2
2008 Implementation and experimental evaluation of a fast local mobility protocol
abstract
In the current mobile cellular networks, the terminal mobility support is based on layer-1 and homogenous layer-2 mechanisms. This mobility support is sufficient for a moderate number of mobile terminals. However, in the future it is expected that this number will significantly increase and that distinct layer-2 interfaces will be available and required for the paradigm of ldquoInternet Everywhererdquo of the next generation networks. This paper presents the implementation and the evaluation results of a novel approach for local mobility in next generation networks. This mobility approach, denoted as local-centric mobility system (LMS), was designed to provide scalability, fast and seamless handovers, and efficient exploitation of network resources and reliability. The LMS can provide handover timings smaller than 100 ms in wireless scenarios, negligible packet loss during handover, and reduced signalling overhead.
N. G. Ferreira, Susana Sargento, Rui L. Aguiar
ISCC3
2008 A stateless architectural approach to inter-domain QoS
abstract
QoS provisioning as a generic telecom service is only useful if deployed end-to-end, so it must cover both the access segment and the interdomain segment of routes. This work focuses on the interdomain component of QoS architectures. Although the research community has been discussing several aspects of the problem, integrated architectures for true end-to-end QoS are still largely conceptual, especially if one considers mesh models and not simpler cascaded ones. Our inter-domain proposal combines offline service discovery and registration with real-time congestion notification, allowing us to significantly reduce the number of packets that were not suitably serviced, in the sense of fulfilling required Service Level Agreement constraints. We qualify our approach of dasiastatelesspsila since our proposal doesnpsilat use additional state in forwarding elements which is one of the most dramatic problems for interdomain scenarios.
Vitor Jesus, Rui L. Aguiar, Peter Steenkiste
ISCC2
2008 Any-constraint personalized network selection
abstract
In densely covered areas and with multi-interface terminals, network selection is a complex problem, especially if it takes into account different criteria such as context and signal strength. We present an algorithm that allows a mobility decision manager to consider arbitrary criteria such as user history or preferences. Since a typical mobility module uses quantitative and well-known information (eg., radio signal strength or available resources), qualitative information must be fed into the mobility subsystem only after converting it to a suitable format. Our algorithm uses (up to) three stages to produce a decision: first, it discards unsuitable possibilities; second, it produces a set of possibilities considering resource availability; and third, the feasible possibilities are ranked according to contextual information.
Vitor Jesus, Susana Sargento, Rui L. Aguiar
PIMRC3
2008 Limitations of the Integration of DVB Technologies in a Heterogeneous Environment
abstract
This formulates a solution to integrate broadcast technologies under a localized mobility management protocol. It mainly deals with the technologies' mobility constraints and evaluates how it responds to the proposed requirements. The presented architecture is considered to be of special interest for deployment over proxy driven scenarios such as university campus and, in a near future, even cities or countries. The aim of this work is to deliver multimedia contents using any available uplink channel and DVB (digitial video broadcasting) as the primary downlink technology for high mobility scenarios and further validate the model via an experimental implementation. Finally we address a specific usage case where spontaneous and chaotic networks such as ad-hocs are not seen as a premise for the functional architecture, but rather as a last resource.
Miguel Almeida, Susana Sargento, Rui L. Aguiar
VTC Spring3
2008 QoS for Ad Hoc Networks Using an Empirical Model
abstract
Empirical models are a technique that has been used in research for a long time, and that proved to be capable of describe pseudo-random phenomena. In this paper, we present PREFAIRS, a protocol used to deploy QoS, and that was designed using empirical models. With our empirical model we are able to determine the available capacity of the ad hoc network and the maximum bandwidth of new flows to guarantee a specified QoS. We show that a combination of our network model, PREFAIRS and a empirical model is able to enforce fairness, predictability and stability in ad hoc networks.
Vitor Jesus, Susana Sargento, Rui L. Aguiar
WCNC3
2008 Virtual Network Capacity Expansion through Service Outsourcing
abstract
Roaming agreements in 3G and beyond 3G networks can greatly enhance the delivery of services to end users. The cost of service delivery to the user depends on the price charged on networks traversed by user traffic. In a QoS DiffServ environment, network resources may be sold in aggregate blocks at wholesale prices to competing ISPs. This can influence the cost of delivering services between two points using access networks owned by competing operators. Demand for network services by users varies over time and network capacities are finite; thus a fully loaded network would reject new service requests and an underutilized network will become less productive. In this paper we explore a service outsourcing scheme between competing operators that allows a custodian network operating at full capacity to outsource service provision to a candidate network. Outsourcing would be price-influenced enabling the home (custodian) operator to levy local predictable charges to the end users for services offered on the visited network. This will virtually expand the capacity of the custodian network and boost incomes for both operators.
Vitalis G. Ozianyi, Neco Ventura, Vitor Jesus, Susana Sargento, Rui L. Aguiar
WCNC5
2008 Multicast/broadcast network convergence in next generation mobile networks
Justino Santos, Diogo Gomes 0001, Susana Sargento, Rui L. Aguiar, Nigel Baker, Madiha Zafar, Ahsan Ikram
Comput. Networks4
2007 Preserving Privacy in Mobile Environments With Virtual Network Stacks
abstract
User privacy is a growing requirement in the evolution of communication networks. In this sense, the concept of virtual personae, which corresponds to different identities of the same user, starts getting much attention. However, to provide privacy and non-linkage between these virtual users, a cross-layer approach to identity needs to be supported. This paper proposes a solution to preserve the application layer privacy models by applying the virtual personae concept throughout the network stack. It also proposes mechanisms for non-correlation between identities in 4G mobile environments, and addresses the benefits of the evolving multi-homing characteristics of 4G networks to enrich the non-linkage between identities support of our privacy solution.
Alfredo Matos, Joao Girão, Susana Sargento, Rui L. Aguiar
GLOBECOM4
2007 MobiSplit in a Virtualized, Multi-Device Environment
abstract
This paper details a novel architecture, MobiSplit [17], for managing mobility in future IP based networks. The architecture separates mobility management in two levels, local and global, that are managed in completely independent ways. We describe how such a mobility architecture can be used to support a new paradigm in mobility. By combining the user's identity with a multi physical virtual terminal we treat the movement of people rather than their physical manifestations in one device. We conclude by analyzing the concrete system, built from this new architecture and existing protocols, in terms of scalability, flexibility and security.
Julien Abeillé, Rui L. Aguiar, Joao Girão, Telemaco Melia, Ignacio Soto, Patrick Stupar
ICC2
2007 Who Said That? Privacy at Link Layer
abstract
Wireless LAN and other radio broadcast technologies are now in full swing. However, the widespread usage of these technologies comes at the price of location privacy, be it by observing the communication patterns or the interface identifiers. Although a number of network level solutions have been proposed , this paper describes a novel approach to location privacy at the link layer level. We present a generic mechanism and then map it to a real protocol, IEEE 802.11. The work also provides an analysis of the protocol in terms of privacy and performance considerations.
Frederik Armknecht, Joao Girão, Alfredo Matos, Rui L. Aguiar
INFOCOM4
2007 GVD and PMD Compensation Using a Linear Adjustable Filter Prototype in a 40 Gb/s OSSB System
abstract
This paper presents experimental results on an electrical adjustable linear filter prototype for compensating impairments due to residual group velocity dispersion (GVD) and first-order static polarization mode dispersion (PMD) on 40 Gb/s systems. Optical single-side band (OSSB) modulation is considered and was verified to be responsible for an increase in system tolerance to GVD and superior performance of the electrical filter. The detrimental effect of packaging on the filter prototype electrical characteristics is analyzed. Simulation and measured results are compared for GVD and first-order static PMD compensation, showing the practical applicability of the developed prototype on 40 Gb/s OSSB systems.
Miguel Ângelo M. Madureira, Daniel Fonseca, Adolfo V. T. Cartaxo, Paulo P. Monteiro, Rui L. Aguiar
ISCAS5
2007 A Framework for Best-Effort Service Provisioning in Ad Hoc Networks
abstract
This paper analyses the implementation of best-effort services over mobile ad hoc networks considering that, if no special transport protocols are used, a mobile ad hoc may be rendered useless to conventional applications. The paper develops an analytical model for the capacity of mobile ad hoc networks, which is able to indicate when the ad hoc network is effectively unusable. It was verified by a large scale simulation study. The simulation study also provides empirical rules that can be used to implement algorithms for real-time operation of mobile ad hoc networks. After validating our model, we provide a set of engineering rules for capacity management in such networks.
Vitor Jesus, Rui L. Aguiar
ISCC2
2007 Mobility with QoS Support for Multi-Interface Terminals: Combined User and Network Approach
abstract
In the future, mobile terminals will be equipped with several interfaces to different technologies -such as UMTS, IEEE 802.11, DVB and WiMAX -and will be able to connect simultaneously to the most appropriate access networks. This paper presents a mobility and QoS architecture aiming at supporting intelligent handovers. We introduce the concept of Network-Assisted Mobile terminal Initiated HandOver (NAMIHO), where the handover decision is negotiated between the network and the user, taking into account inputs and decision algorithms running both on the terminal and network. We also present an instantiation of the architecture using IEEE 802.21 and concepts of local/global mobility. We further propose extensions to IEEE 802.21 standard.
Vitor Jesus, Susana Sargento, Daniel Corujo, Nuno Sénica, Miguel Almeida, Rui L. Aguiar
ISCC6
2007 IP Multicast Dynamic Mapping in Heterogeneous Environments
abstract
Multimedia group communication over IP is an advanced service gaining growing interest from broadcast, fixed and mobile network operators. Next Generation Networks (NGN) will require that IP based multimedia services to be efficiently delivered to groups over heterogeneous networks with QoS. Although being acknowledged as the most efficient way of delivering group communication in packet switched networks, IP multicast still faces some problems associated with QoS that have limited its success in the past. Furthermore the nonexistence of true multicast in wireless technologies has led to an inefficient mapping between the IP and wireless layers. This paper proposes a technique for efficient dynamic mapping of IP Multicast, optimizing its usage for NGN. This technique is evaluated by a prototype on a WiFi environment.
Diogo Gomes 0001, Rui L. Aguiar
PIMRC2
2007 Support of Anonymity in VANETs - Putting Pseudonymity into Practice
abstract
Despite great advantages of vehicular ad hoc networks (VANETs), they also introduce challenges with respect to security and privacy. Today, people are more and more concerned about their privacy. Using unique identifiers for communication, a vehicle can easily be located and tracked. Alternatively, a technical solution to protect drivers' privacy is the use of changing pseudonyms. Existing work mainly focuses on algorithms for pseudonym change and neglect practical implications and realizability. For deployment and integration of pseudonymity into a VANET communication system, several issues need to be solved. This paper analyzes the practical challenges and proposes protocol- and implementation-related solutions necessary to turn pseudonymity support into practice. Finally, the paper concludes by means of analysis and measurements that the burden of pseudonymity can be alleviated at reasonable costs and compromises in anonymity support.
Emanuel Fonseca, Andreas Festag, Roberto Baldessari, Rui L. Aguiar
WCNC4
2007 Impact of Heterogeneous Network Controlled Handovers on Multi-Mode Mobile Device Design
abstract
The availability of multiple technologies, with micro and macro wireless cells, for network access combined with terminals capable of exploiting such diversity in wireless access requires the development of new mechanisms for optimized handover procedures. Appealing solutions should support network controlled handovers through heterogeneous technologies, preferably combined with a cross-layers two/three design. The IEEE 802.21 working group is currently standardizing the methods and the protocol potentially able to provide such a solution. In this paper we analyze the impact of signaling timing on network controlled handovers execution and performance in this environment. Through an extensive simulation study, we obtain results, that can be exploited in both terminal and handover procedure designs.
Telemaco Melia, Daniel Corujo, Antonio de la Oliva, Albert Vidal, Rui L. Aguiar, Ignacio Soto
WCNC5
2007 Toward IP converged heterogeneous mobility: A network controlled approach
Telemaco Melia, Antonio de la Oliva, Albert Vidal, Ignacio Soto, Daniel Corujo, Rui L. Aguiar
Comput. Networks6
2006 Privacy through Virtual Hording
abstract
The wireless digital lifestyle comes to the expense of less privacy and security. This environment is prone to be monitored by rogue users, eager to learn from our lifestyle habits and use them for their own profit. The IP protocol provides very few mechanisms, in order to safeguard user privacy and impair efficient data-mining of user habits. This paper will address an identity architecture that makes use of both data (L2) and network (L3) layer identifiers in order to provide a pseudonimization function, based on virtual hoarding concepts. Our proposal is especially interesting when able to exploit the broadcast and promiscuous nature of wireless communications that usually is regarded as a security concern. A prototype implementation has been developed and tested.
Diogo Gomes 0001, Rui L. Aguiar
GLOBECOM2
2006 General model for delayed feedback and its application to transimpedance amplifier's bandwidth optimization
abstract
Delays in real systems can be of two types: i) intrinsic delays - due to the physical principles of operation of each electronic device; ii) designed delays - due to extra circuits used to add the desired delay. Previous work established the possibility of achieving bandwidth improvements using small delays inside the feedback loop of feedback amplifiers. The modeling approach followed on these contributions used only one designed delay element. The bandwidth reduction effect due to intrinsic delays was not considered on these contributions. This paper extends the concept to the general case of feedback amplifiers that incorporates delays of both types. An experimental demonstration using a simple 0.35/spl mu/m BiCMOS transimpedance amplifier further confirms the proposed model.
Luís Nero Alves, Luis Barbosa, E. A. L. Macedo, Rui L. Aguiar
ISCAS4
2006 Support of Real-Time Services over Integrated 802.16 Metropolitan and Local Area Networks
abstract
The growing demand of high bandwidth services and applications, and the increasing will of access to these services anywhere, is motivating the requirement to integrate the current Internet with the mobile networks. However, there will always be remote areas where Internet access will be difficult to achieve. The IEEE 802.16 is an attractive broadband wireless technology for these scenarios, non-withstanding its limitations for dynamic environments. This paper discusses a network architecture able to support real time services using 802.16 networks as a backhaul. We present the modules required to provide an integrated QoS approach over the 802.16 network, and address main implementation results in terms of QoS performance, and in terms of mobility with QoS support for converged networks comprising WiMax and WiFi technologies. We show that our architecture is able to provide end-to-end QoS over the concatenation of metro and local area networks, and that seamless mobility is achieved with high performance measures, thus being able to support real-time services.
Pedro Neves 0001, Susana Sargento, Rui L. Aguiar
ISCC3
2005 The Polynomial-Assisted Ad Hoc Charging Protocol
abstract
The area of trustworthy charging in self-organized environments has been developed quite recently. This paper introduces a new secure charging-protocol, the polynomial-assisted charging protocol, for these environments. The protocol relies on polynomial composition for speeding the identification process in small groups. This protocol is able to provide strict guarantees of cooperative behavior in traffic forwarding, with minimal network overhead. Protocol performance is evaluated in multiple ad-hoc environments and results are compared with previously proposed work. The performance results show the merits of this protocol in multiple types of environments.
João Paulo Barraca, Susana Sargento, Rui L. Aguiar
ISCC3
2005 The 'pure-IP' Moby Dick 4G architecture
Jürgen Jähnert, Rui L. Aguiar, Victor Marques 0001, Michelle Wetterwald, Eric Melin, José Ignacio Moreno, Antonio Cuevas, Marco Liebsch, Ralf Schmitz, Piotr Pacyna, Telemaco Melia, Pascal Kurtansky, Hasan, Davinder Singh, Sebastian Zander, Hans Joachim Einsiedler, Burkhard Stiller
Comput. Commun.3
2005 Evaluation of a mobile IPv6-based architecture supporting user mobility QoS and AAAC in heterogeneous networks
abstract
This paper presents a Mobile IPv6-based overlay network architecture for heterogeneous environments, designed entirely based on IPv6, that aims to be implemented seamlessly irrespectively of the supporting network infrastructure. All transmission technologies are handled at the physical and data-link layers, imposing IPv6-based protocols for all higher layer communications and signaling. The architecture builds on Mobile IPv6 including improved fast handover, and integrates quality-of-service and authentication, authorization, accounting, and charging control per user. The most critical issues of the proposed architecture, mainly related to the handover process, were subject of a performance evaluation via ns-2 simulations. Finally, a field trial of the system was implemented, overlaying part of the GEANT infrastructure between Madrid and Stuttgart, which results are presented here.
Victor Marques 0001, Xavier Pérez Costa, Rui L. Aguiar, Marco Liebsch, A. M. de Oliveira Duarte
IEEE J. Sel. Areas Commun.3
2000 A sectored receiver for infrared wireless networks
abstract
This paper presents an experimental sectored receiver for infrared wireless networks. The receiver comprises two sectors, each with a switched gain front-end and a signal-to-noise ratio estimator. These are then interconnected with a best-sector selector unit, able to compensate the gain switching characteristics of the front-ends. The circuit has been designed in a 0.8 /spl mu/m CMOS technology.
Luís Nero Alves, Rui L. Aguiar, Eduardo de Vasconcelos, José Luis Cura
ISCAS2