VLDB 2026 Research / reviewers in the wild / expert
Rodrigo Roman
dblp:63/6414 · also Rodrigo Roman Castro, Rodrigo Román
· DBLP profile ↗
37ranked-venue papers
11as first author
4since 2021 · last 2025
0000-0002-4099-1422ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 19 · 2 first-author · 2 since 2021Computer networks · 11 · 6 first-authorSystems, architecture and hardware · 3 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Digital Twin for Adaptive Adversary Emulation in IIoT Control Networks
Javier Parada, Cristina Alcaraz, Javier López 0001, Juan Caubet, Rodrigo Roman |
ESORICS (3) | 5 |
| 2024 | A survey on IoT trust model frameworksabstractAbstract Trust can be considered as a multidisciplinary concept, which is strongly related to the context and it falls in different fields such as Philosophy, Psychology or Computer Science. Trust is fundamental in every relationship, because without it, an entity will not interact with other entities. This aspect is very important especially in the Internet of Things (IoT), where many entities produced by different vendors and created for different purposes have to interact among them through the internet often under uncertainty. Trust can overcome this uncertainty, creating a strong basis to ease the process of interaction among these entities. We believe that considering trust in the IoT is fundamental, and in order to implement it in any IoT entity, it is fundamental to consider it through the whole System Development Life Cycle. In this paper, we propose an analysis of different works that consider trust for the IoT. We will focus especially on the analysis of frameworks that have been developed in order to include trust in the IoT. We will make a classification of them providing a set of parameters that we believe are fundamental in order to properly consider trust in the IoT. Thus, we will identify important aspects to be taken into consideration when developing frameworks that implement trust in the IoT, finding gaps and proposing possible solutions. Davide Ferraris, Carmen Fernández Gago, Rodrigo Roman, Javier López 0001 |
J. Supercomput. | 3 |
| 2023 | A survey on the (in)security of trusted execution environmentsabstractAs the number of security and privacy attacks continue to grow around the world, there is an ever increasing need to protect our personal devices. As a matter of fact, more and more manufactures are relying on Trusted Execution Environments (TEEs) to shield their devices. In particular, ARM TrustZone (TZ) is being widely used in numerous embedded devices, especially smartphones, and this technology is the basis for secure solutions both in industry and academia. However, as shown in this paper, TEE is not bullet-proof and it has been successfully attacked numerous times and in very different ways. To raise awareness among potential stakeholders interested in this technology, this paper provides an extensive analysis and categorization of existing vulnerabilities in TEEs and highlights the design flaws that led to them. The presented vulnerabilities, which are not only extracted from existing literature but also from publicly available exploits and databases, are accompanied by some effective countermeasures to reduce the likelihood of new attacks. The paper ends with some appealing challenges and open issues. Antonio Muñoz 0001, Ruben Rios, Rodrigo Roman, Javier López 0001 |
Comput. Secur. | 3 |
| 2021 | Guest Editorial Introduction of the Special Issue on Edge Intelligence for Internet of VehiclesabstractEmpowered with advanced computation units, autonomous sensing platforms and various wireless access capabilities, connected and autonomous vehicles evolve over time and become tightly coupled and closely cooperative. Being one of the most active research fields in both academic and industry, the Internet of Vehicles (IoV) enables various types of vehicular applications, such as autonomous driving, precise fleet management, and real-time video analytics, which contribute significantly to bring us traffic efficiency, driving safety, and ride comfort. However, these powerful applications always require intensive computation and very large size caching services under ultra-low latency constraints, and thus pose significant challenges on resource-constrained vehicles. Yan Zhang 0002, Celimuge Wu, Rodrigo Roman, Hong Liu 0006 |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2020 | Distributed Detection of APTs: Consensus vs. Clustering
Juan E. Rubio, Cristina Alcaraz, Ruben Rios, Rodrigo Roman, Javier López 0001 |
ESORICS (1) | 4 |
| 2020 | Integration of a Threat Traceability Solution in the Industrial Internet of ThingsabstractIn industrial Internet of Things (IIoT) scenarios, where a plethora of IoT technologies coexist with consolidated industrial infrastructures, the integration of security mechanisms that provide protection against cyber-security attacks becomes a critical challenge. Due to the stealthy and persistent nature of some of these attacks, such as Advanced Persistent Threats, it is crucial to go beyond traditional intrusion detection systems (IDSs) for the traceability of these attacks. In this sense, opinion dynamics poses a novel approach for the correlation of anomalies, which has been successfully applied to other network security domains. In this article, we aim to analyze its applicability in the IIoT from a technical point of view, by studying its deployment over different IIoT architectures and defining a common framework for the acquisition of data considering the computational constraints involved. The result is a beneficial insight that demonstrates the feasibility of this approach when applied to upcoming IIoT infrastructures. Juan E. Rubio, Rodrigo Roman, Javier López 0001 |
IEEE Trans. Ind. Informatics | 2 |
| 2019 | Current cyber-defense trends in industrial control systems
Juan E. Rubio, Cristina Alcaraz, Rodrigo Roman, Javier López 0001 |
Comput. Secur. | 3 |
| 2019 | Edge-Assisted Vehicular Networks SecurityabstractEdge computing paradigms are expected to solve some major problems affecting current application scenarios that rely on cloud computing resources to operate. These novel paradigms will bring computational resources closer to the users and by doing so they will not only reduce network latency and bandwidth utilization but will also introduce some attractive context-awareness features to these systems. In this paper we show how the enticing features introduced by edge computing paradigms can be exploited to improve security and privacy in the critical scenario of vehicular networks (VNs), especially existing authentication and revocation issues. In particular, we analyze the security challenges in VN and describe three deployment models for vehicular edge computing, which refrain from using vehicular-to-vehicular communications. The result is that the burden imposed to vehicles is considerably reduced without sacrificing the security or functional features expected in vehicular scenarios. Jose Antonio Onieva, Ruben Rios, Rodrigo Roman, Javier López 0001 |
IEEE Internet Things J. | 3 |
| 2019 | Immune System for the Internet of Things Using Edge TechnologiesabstractThe Internet of Things (IoT) and edge computing are starting to go hand in hand. By providing cloud services close to end-users, edge paradigms enhance the functionality of IoT deployments, and facilitate the creation of novel services such as augmented systems. Furthermore, the very nature of these paradigms also enables the creation of a proactive defense architecture, an immune system, which allows authorized immune cells (e.g., virtual machines) to traverse edge nodes and analyze the security and consistency of the underlying IoT infrastructure. In this paper, we analyze the requirements for the development of an immune system for the IoT, and propose a security architecture that satisfies these requirements. We also describe how such a system can be instantiated in edge computing infrastructures using existing technologies. Finally, we explore the potential application of immune systems to other scenarios and purposes. Rodrigo Roman, Ruben Rios, Jose Antonio Onieva, Javier López 0001 |
IEEE Internet Things J. | 1 |
| 2019 | Tracking APTs in industrial ecosystems: A proof of conceptabstractIn recent years, Advanced Persistent Threats (APTs) have become a major issue for critical infrastructures that are increasingly integrating modern IT technologies. This requires the development of advanced cyber-security services that can holistically detect and trace these attacks, beyond traditional solutions. In this sense, Opinion Dynamics has been proven as an effective solution, as they can locate the most affected areas within the industrial network. With this information, it is possible to put in place accurate response techniques to limit the impact of attacks on the infrastructure. In this paper, we analyze the applicability of Opinion Dynamics to trace an APT throughout its entire life cycle, by correlating different anomalies over time and accounting for the persistence of threats and the criticality of resources. Moreover, we run various experiments with this novel technique over a testbed that models a real control system, thereby assessing its effectiveness in an actual industrial scenario. Juan E. Rubio, Rodrigo Roman, Cristina Alcaraz, Yan Zhang 0002 |
J. Comput. Secur. | 2 |
| 2018 | Tracking Advanced Persistent Threats in Critical Infrastructures Through Opinion Dynamics
Juan E. Rubio, Rodrigo Roman, Cristina Alcaraz, Yan Zhang 0002 |
ESORICS (1) | 2 |
| 2018 | Mobile edge computing, Fog et al.: A survey and analysis of security threats and challenges
Rodrigo Roman, Javier López 0001, Masahiro Mambo |
Future Gener. Comput. Syst. | 1 |
| 2017 | Analysis of Cybersecurity Threats in Industry 4.0: The Case of Intrusion Detection
Juan E. Rubio, Rodrigo Roman, Javier López 0001 |
CRITIS | 2 |
| 2017 | Analysis of Intrusion Detection Systems in Industrial Ecosystems
Juan E. Rubio, Cristina Alcaraz, Rodrigo Roman, Javier López 0001 |
SECRYPT | 3 |
| 2014 | Protecting the internet of thingsabstractThe vision of the Internet of Things (IoT), supported by industrial companies and governments all over the world, marks an evolution that will surely have a great impact on our environments and our lives. The central element of this vision is the existence of a network of interconnected objects (electrical appliances, wearable devices, industrial machinery, etc). Under the context of the IoT, these objects not only can exchange data anytime and anywhere, but also collaborate in the provisioning of novel services. In fact, some of these services are already available: web-based portals that enable the creation of aggregated services using world-wide sensor data, industrial systems that enable the development of preventive maintenance processes, and many others. However, protecting the IoT is a complex and difficult task. The current Internet is already under constant attack due to a mixture of several factors: technical (e.g. vulnerable systems, unsecure protocols), legal (e.g. jurisdiction problems), and human (e.g. targeted attacks, usability problems).The Internet of Things will not only inherit these problems, but will also have some important issues of its own. The heterogeneity of protocols and devices will make the development of interoperable, fault-tolerant security services a daunting task. The connectivity that is crucial to the IoT will make critical infrastructures extremely vulnerable against cascade failures. Moreover, as the IoT will process countless bits of personal data, the management of personal privacy might become a nightmare. The purpose of this special issue is to introduce six research articles whose goal is to provide solutions to some of the most urgent problems related to IoT security: secure communications, authentication and authorization, user privacy, and security assessment. Moreover, in line with the inherent heterogeneity of the IoT, this special issue will not focus on one single technology, but will provide an analysis of several protocols and systems (RFID systems, sensor networks, critical infrastructures). The contributions of these papers are outlined in the succeeding text. As Radio Frequency Identification (RFID) systems can be considered as one of the foundational stones of the IoT, it is important to develop a communication system that enables RFID tags to securely connect to the Internet. That is precisely the goal of the article entitled “Secure communication with RFID tags in the internet of things”, by Dominikus and Kraxberger. In this article, the authors develop Mobile-IPv6 enabled RFID tags, which can connect to the Internet through RFID readers. Moreover, these tags can also integrate end-to-end IPsec security services, effectively protecting the information exchange between the tags and the remote servers. Wireless sensor networks, or WSN, can also be considered as one of the essential elements of the IoT. These resource-constrained networks usually make use of the IPv6 over Low-power Wireless Personal Area Networks (6LoWPAN) protocol to connect to external Internet hosts. However, this protocol does not explicitly define an IPsec extension. Therefore, Shahid et al. analyzed how IPsec could be successfully integrated in 6LoWPAN in their article “Secure communication for the Internet of Things - A comparison of Link-Layer security and IPsec for 6LoWPAN”. Their analysis shows how IPsec can be a feasible option for securing the IoT in terms of performance and scalability. As aforementioned, privacy is one of the most important research challenges in the context of the IoT. More specifically, in the case of RFID systems, it is essential to develop security mechanisms that avoid user data to be leaked to unauthorized parties. This special issue introduces two mechanisms that provide efficient solutions to this particular problem. In “How to protect security and privacy in the IoT: A policy-based RFID tag management protocol”, Rekleitis, Rizomiliotis and Gritzalis provide a desirable set of management operations (from delegation of querying rights to ownership transfer) that allow users to manage their own set of RFID tags. On the other hand, in “A context-aware approach to defend against unauthorized reading and relay attacks in RFID systems”, Ma and Saxena make use of on-board sensors to provide contextual information to the RFID tags. This contextual information can be used to develop enhanced authorization policies, such as selective unlocking according to location. These two functions, authorization and context awareness, are also studied by Bai et al. in “Context-Aware Usage Control for Web of Things”. In this article, the authors develop a model that enables users to define their own context-aware security policies. Such policies are then applied to Internet-connected “intranet of things” environments, like smart homes. In fact, the authors provide an example of a working prototype, which enables users to control the appliances of their smart home in an intelligent and secure way. Finally, in “Assessing the Security of Internet Connected Critical Infrastructures”, Ghani et al. develop a set of security metrics that can be used to monitor the integrity of Internet-connected Critical Infrastructures (CIs). In particular, the authors first define a set of metric-based Service-Level Agreements (SLAs), which capture the user requirements of all CIs. Afterwards, a metrics monitoring system receives the measures from various sensors, which are then compared to the SLAs. Consequently, the system can detect potential problems before they happen – and act before a cascade event further damages the integrity of the CIs. We would like to express our gratitude to Professor Hsiao-Hwa Chen and Professor Hamid R. Sharif, Editors-in-Chief of the Security and Communication Networks journal, for their support before and during the development of this special issue. We would also like to thank the authors that chose to publish their research findings in this special issue. The Internet of Things is in dire need of strong security foundations, and we believe these research results will help to build a more secure future. Finally, we would like to thank all the reviewers that, with their time and their comments, helped the authors to strengthen their security protocols and mechanisms. James Clarke, Stefanos Gritzalis, Jianying Zhou 0001, Rodrigo Roman |
Secur. Commun. Networks | 4 |
| 2014 | Security in a completely interconnected worldabstractThe convergence of multiple paradigms, visions, and technologies – Internet of Things (IoT) and Web of Things (WoT); Ambient Intelligence (AmI); Machine-to-Machine (M2M); and many others – is giving birth to a world of interconnected things. A world where any entity (be it a machine, an object, a person, or anything) can collaborate with each other, anytime and anywhere, in the provisioning of services. This concept of a truly interconnected world is at its infancy, yet there are various commercial players pushing previously envisioned services to the real world: from centralized Big Data repositories to “intranet of things” systems, from industrial information services to personal wearable sensor systems. Moreover, this evolution does not stop here, as the scientific community is constantly researching new advances in this area. Additionally, there is a factor that must not be overlooked in the development of this interconnected world: security. To truly understand the importance of this factor, we just need to check the state of another interconnected infrastructure: the current Internet. While functional and resilient, the current Internet is still a target of malicious attacks that affect both its users and its infrastructure. However, the scope of a truly interconnected world goes well beyond the current Internet: encompassing a global interoperable connectivity and accessibility by a myriad of heterogeneous entities, with countless data streams that can be aggregated and processed when necessary. Without the proper fault-tolerant security mechanisms, all this wealth of services and information might be not only accessed by users but also manipulated by malicious attackers. Precisely, due to the existence of such information flows, we also cannot let privacy go unnoticed in the development of security solutions for this particular context. Not only are the personal data of users at stake (e.g. daily life, medical records, private information), but also the confidential information managed by larger entities. Consequently, the purpose of this special issue is to introduce six research articles that study how to protect users and devices in the context of an interconnected world, with a special emphasis on privacy-preserving solutions. The contributions of these papers are outlined in the succeeding text. The privacy challenges are not only daunting, but also uncharted. Who are the stakeholders? What concrete threats exist, and how can they be defined? What is the impact of these threats? How can the stakeholders react against these threats? The goal of the article entitled “Privacy in the Internet of Things: Threats and Challenges”, by Ziegeldorf, Garcia-Monchon, and Wehrle, is to provide detailed answers to all these questions. Note that, even if the article focuses specifically on the Internet of Things, most of its analysis can be applied to all the other paradigms that compose this interconnected vision – as they share various underlying principles such as heterogeneous connectivity. In an interconnected world, it is essential for the devices to route the information to each other. One possible solution, which has been studied for years in the area of big distributed infrastructures, are P2P overlay networks. Still, there are several challenges in this area, such as how to manage the users’ identities while preserving their anonymity, and the existence of various attacks that can manipulate how identities are assigned (e.g. Sybil, Eclipse, MITM). The purpose of the paper entitled “RIAPPA: a Robust Identity Assignment Protocol for P2P overlays”, by Caubet et al., is to provide a generic, not algorithm-dependant protocol that can deal with these challenges. In the exchange of information between things, it is not only important to provide anonymity when necessary, but also to maintain a certain Quality of Service (QoS) to avoid excessive service degradation. The goal of the paper entitled “On Collaborative Anonymous Communications in Lossy Networks”, by Rebollo-Monedero et al., is to introduce a Crowds-like protocol for anonymous communication that establishes quantifiable metrics of anonymity and QoS. Such metrics enable the authors to perform a detailed mathematical analysis of the protocol, effectively improving the scope of the original Crowds protocol while achieving a reasonable balance between anonymity and QoS. In fact, due to the importance of maintaining a reasonable QoS while applying the security protocols, this special issue includes the paper entitled “Analysis and Taxonomy of Security/QoS tradeoff solutions for the Future Internet”, by Nieto and Lopez. This paper provides a thorough analysis of the coexistence of security and QoS mechanisms within the context of Future Internet scenarios. The paper analyses existing solutions and identifies potential problems, and also describes the major pitfalls in the integration of existing networking models such as Wireless Sensor Networks (WSN) and Cellular networks. Most of the previous papers focus on anonymity. But there are other privacy issues that must be taken into vaccount. For example, by continuously querying the network about several topics, users can be profiled – which in some cases might reveal bits of information even more important and private than our identities. The paper entitled “Enhancing Information Lookup Privacy through Homomorphic Encryption”, by Fotiou et al., provides a broker-based solution to this problem. Such a solution is also optimized, achieving a balance between the complexity of the computations and the communication overhead between the involved parties. Finally, if the networked embedded systems that comprise our interconnected world are not properly designed to comply with various security properties, attackers will surely find their way to break into them – no matter what security and privacy protocols are developed. The article entitled “Integrating security mechanisms into embedded systems by domain-specific modeling”, by Vasilevskaya et al., combine security and software engineering solutions (e.g. Model-based development (MBD), information security ontology) in order to allow system designers to easily integrate security requirements during the design process. We would like to express our gratitude to Professor Hsiao-Hwa Chen and Professor Hamid R. Sharif, Editors-in-Chief of the Security and Communication Networks journal, for their support before and during the development of this special issue. We would also like to thank the authors that chose to publish their research findings in this special issue, as a truly interconnected world is within our grasp – but we must find ways to protect it before it becomes a liability rather than a blessing. Finally, we would like to thank all the reviewers that, with their time, efforts, and their comments, helped the authors to strengthen their security protocols and mechanisms. James Clarke, Stefanos Gritzalis, Jianying Zhou 0001, Rodrigo Roman |
Secur. Commun. Networks | 4 |
| 2013 | Security of industrial sensor network-based remote substations in the context of the Internet of Things
Cristina Alcaraz, Rodrigo Roman, Pablo Najera, Javier López 0001 |
Ad Hoc Networks | 2 |
| 2013 | On the features and challenges of security and privacy in distributed internet of things
Rodrigo Roman, Jianying Zhou 0001, Javier López 0001 |
Comput. Networks | 1 |
| 2013 | Smart control of operational threats in control substations
Javier López 0001, Cristina Alcaraz, Rodrigo Roman |
Comput. Secur. | 3 |
| 2013 | User-centric secure integration of personal RFID tags and sensor networksabstractABSTRACT A personal network (PN) should enable the collaboration of user's devices and services in a flexible, self‐organizing, and friendly manner. For such purpose, the PN must securely accommodate heterogeneous technologies with uneven computational and communication resources. In particular, personal radio frequency identification (RFID) tags can enable seamless recognition of user's context, provide user authentication, and enable novel services enhancing the quality and quantity of data handled by the PN. However, the highly constrained features of common RFID tags and their passive role in the network highlights the need of an adequate secure communication model with personal tags, which enables their participation as a member of the PN. In this paper, we present our concept of PN, with special emphasis on the role of RFID and sensor networks, and define a secure architecture for PNs including methods for the secure access to context‐aware technologies from both local PN members and the Internet of Things. The PN architecture is designed to support differentiated security mechanisms to maximize the level of security for each type of personal device. Furthermore, we analyze which security solutions available in the literature can be adapted for our architecture, as well as the challenges and security mechanisms still necessary in the secure integration of personal tags. Copyright © 2013 John Wiley & Sons, Ltd. Pablo Najera, Rodrigo Roman, Javier López 0001 |
Secur. Commun. Networks | 2 |
| 2012 | Selecting key management schemes for WSN applications
Cristina Alcaraz, Javier López 0001, Rodrigo Roman, Hsiao-Hwa Chen |
Comput. Secur. | 3 |
| 2012 | On the energy cost of authenticated key agreement in wireless sensor networksabstractAbstract Wireless sensors are battery‐powered devices which are highly constrained in terms of computational capabilities, memory and communication bandwidth. While battery life is their main limitation, they require considerable energy to communicate data. Due to this, it turns out that the energy saving of computationally inexpensive primitives (like symmetric key cryptography (SKC)) can be nullified by the bigger amount of data they require to be sent. In this work, we study the energy cost of key agreement protocols between peers in a network using asymmetric key cryptography. Our main concern is to reduce the amount of data to be exchanged, which can be done by using special cryptographic paradigms like identity‐based and self‐certified cryptography. The main news is that an intensive computational primitive for resource‐constrained devices, such as non‐interactive identity‐based authenticated key exchange, performs comparably or even better than traditional authenticated key exchange (AKE) in a variety of scenarios. Moreover, protocols based in this primitive can provide better security properties in real deployments than other simple protocols based on symmetric cryptography. Our findings illustrate to what extent the latest implementation advancements push the efficiency boundaries of public key cryptography (PKC) in wireless sensor networks (WSNs). Copyright © 2010 John Wiley & Sons, Ltd. David Galindo, Rodrigo Roman, Javier López 0001 |
Wirel. Commun. Mob. Comput. | 2 |
| 2011 | Secure SCADA framework for the protection of energy control systemsabstractAbstract Energy distribution systems are becoming increasingly widespread in today's society. One of the elements that are used to monitor and control these systems are SCADA (Supervisory Control and Data Acquisition) systems. In particular, these control systems and their complexities, together with the emerging use of the Internet and wireless technologies, bring new challenges that must be carefully considered. Examples of such challenges are the particular benefits of the integration of those new technologies, and also the effects they may have on the overall SCADA security. The main task of this paper is to provide a framework that shows how the integration of different state‐of‐the‐art technologies in an energy control system, such as wireless sensor networks, mobilead hocnetworks, and the Internet, can bring some interesting benefits, such as status management and anomaly prevention, while maintaining the security of the whole system. Copyright © 2010 John Wiley & Sons, Ltd. Cristina Alcaraz, Javier López 0001, Jianying Zhou 0001, Rodrigo Roman |
Concurr. Comput. Pract. Exp. | 4 |
| 2011 | Real-time location and inpatient care systems based on passive RFID
Pablo Najera, Javier López 0001, Rodrigo Roman |
J. Netw. Comput. Appl. | 3 |
| 2011 | A cross-layer approach for integrating security mechanisms in sensor networks architecturesabstractAbstract The wireless sensor networks (WSN) paradigm is especially vulnerable against external and internal attacks. Therefore, it is necessary to develop security mechanisms and protocols to protect them. These mechanisms must become an integral part of the software architecture and network stack of a sensor node. A question that remains is how to achieve this integration. In this paper we check how both academic and industrial solutions tackle this issue, and we present the concept of a transversal layer, where all the different security mechanisms could be contained. This way, all the elements of the architecture can interact with the security mechanisms, and the security mechanisms can have a holistic point of view of the whole architecture. We discuss the advantages of this approach, and also present how the transversal layer concept was applied to a real middleware architecture. Copyright © 2010 John Wiley & Sons, Ltd. Rodrigo Roman, Javier López 0001, Pablo Najera |
Wirel. Commun. Mob. Comput. | 1 |
| 2010 | Trust management systems for wireless sensor networks: Best practices
Javier López 0001, Rodrigo Roman, Isaac Agudo, Carmen Fernández Gago |
Comput. Commun. | 2 |
| 2009 | Adaptive Dispatching of Incidences Based on Reputation for SCADA Systems
Cristina Alcaraz, Isaac Agudo, Carmen Fernández Gago, Rodrigo Roman, Gerardo Fernandez, Javier López 0001 |
TrustBus | 4 |
| 2008 | A Killer Application for Pairings: Authenticated Key Establishment in Underwater Wireless Sensor Networks
David Galindo, Rodrigo Roman, Javier López 0001 |
CANS | 2 |
| 2008 | KeyLED - transmitting sensitive data over out-of-band channels in wireless sensor networksabstractAn ldquoout-of-bandrdquo (OoB) channel can be defined as an extra channel, different from the main wireless channel, that has additional security properties. They are specially suitable for protecting spontaneous interactions and exchanging sensitive data between previously unknown devices. Due to the vulnerable nature of wireless sensor networks (WSN), these kind of channels might be useful for protecting certain sensor network operations. In this paper we analyze the applicability of ldquoout-of-bandrdquo channels to wireless sensor networks, and specify why an optical channel should be a good candidate for implementing an extra channel in sensor nodes. Also, we analyze how the existing security threats may affect this type of channel. Finally, the suitability and usability of optical channels for sensor networks is demonstrated by means of a prototype. Rodrigo Roman, Javier López 0001 |
MASS | 1 |
| 2007 | The role of Wireless Sensor Networks in the area of Critical Information Infrastructure Protection
Rodrigo Roman, Cristina Alcaraz, Javier López 0001 |
Inf. Secur. Tech. Rep. | 1 |
| 2007 | An effective multi-layered defense framework against spam
Jianying Zhou 0001, Wee-Yung Chin, Rodrigo Roman, Javier López 0001 |
Inf. Secur. Tech. Rep. | 3 |
| 2007 | A Survey of Cryptographic Primitives and Implementations for Hardware-Constrained Sensor Network Nodes
Rodrigo Roman, Cristina Alcaraz, Javier López 0001 |
Mob. Networks Appl. | 1 |
| 2006 | Applying intrusion detection systems to wireless sensor networksabstractis a mature area in wired networks, and has also attracted many attentions in wireless ad hoc networks recently. Nevertheless, there is no previous work reported in the literature about IDS architectures in wireless sensor networks. In this paper, we discuss the general guidelines for applying IDS to static sensor networks, and introduce a novel technique to optimally watch over the communications of the sensors ’ neighborhood on certain scenarios. Rodrigo Roman, Jianying Zhou 0001, Javier López 0001 |
CCNC | 1 |
| 2006 | Applying Key Infrastructures for Sensor Networks in CIP/CIIP Scenarios
Cristina Alcaraz, Rodrigo Roman |
CRITIS | 2 |
| 2006 | An anti-spam scheme using pre-challenges
Rodrigo Roman, Jianying Zhou 0001, Javier López 0001 |
Comput. Commun. | 1 |
| 2005 | On the Security of Wireless Sensor Networks
Rodrigo Roman, Jianying Zhou 0001, Javier López 0001 |
ICCSA (3) | 1 |
| 2005 | Protection Against Spam Using Pre-Challenges
Rodrigo Roman, Jianying Zhou 0001, Javier López 0001 |
SEC | 1 |