Florina Almenárez

dblp:64/5968 · also Florina Almenáres, Florina Almenáres Mendoza, Florina Almenárez Mendoza · DBLP profile ↗
← Back
26ranked-venue papers
6as first author
11since 2021 · last 2026
0000-0002-5232-2031ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 13 · 1 first-author · 9 since 2021Security and privacy · 5 · 1 first-authorHuman-computer interaction and ubiquitous computing · 3 · 3 first-authorSystems, architecture and hardware · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 Zero-trust token authorization with trapdoor hashes for scalable distributed firewalls
abstract
Massive Internet of Things (IoT) deployments expose networks to severe risks, as a single compromised device can facilitate lateral movements across the entire infrastructure. Traditional firewalls, based on static rules, are fragile, difficult to synchronize across domains, and poorly suited for Zero Trust principles. In this work, we propose a scalable authorization architecture where each flow carries a cryptographically protected token that incorporates a signed and immutable policy, verifiable in a non-interactive manner. The tokens are issued based on attestation evidence, and the messages are reinforced using trapdoor chameleon hashes , which allows for flexible delegation and transferability without invalidating the original policy. Through key aggregation techniques, we enable collaborative issuance, optional anonymity, and multi-party governance. The experimental evaluation in a real testbed demonstrates that the verification of this embedded authorization incurs a fixed and predictable cost—higher than that of rule lookups, but constant regardless of network size, rule growth, or concurrency. This balance eliminates the burden of distributing and maintaining large rule tables while ensuring granular per-flow authorization, privacy preservation, and interoperability between providers. The proposal materializes a Zero Trust model resistant to impersonation, replay, and lateral attacks, and lays the groundwork for future optimizations through the progressive incorporation of post-quantum primitives.
Daniel Díaz Sánchez, Florina Almenárez, Celeste Campo-Vázquez, Carlos García-Rubio
Future Gener. Comput. Syst.2
2025 QKD-KEM: Hybrid QKD Integration into TLS with OpenSSL Providers
abstract
Quantum Key Distribution (QKD) promises information-theoretic security, yet integrating QKD into existing protocols like TLS remains challenging due to its fundamentally different operational model. In this paper, we propose a hybrid QKD-KEM protocol with two distinct integration approaches: a client-initiated flow compatible with both ETSI 004 and 014 specifications, and a server-initiated flow similar to existing work but limited to stateless ETSI 014 APIs. Unlike previous implementations, our work specifically addresses the integration of stateful QKD key exchange protocols (ETSI 004) which is essential for production QKD networks but has remained largely unexplored. By adapting OpenSSL’s provider infrastructure to accommodate QKD’s pre-distributed key model, we maintain compatibility with current TLS implementations while offering dual layers of security. Performance evaluations demonstrate the feasibility of our hybrid scheme with acceptable overhead, showing that robust security against quantum threats is achievable while addressing the unique requirements of different QKD API specifications.
Javier Blanco-Romero, Pedro Otero-García, Daniel Sobral-Blanco, Florina Almenárez, Ana Fernández Vilas, Rebeca P. Díaz Redondo
ISCC4
2025 Onion Routing Key Distribution for QKDN
abstract
The advance of quantum computing poses a significant threat to classical cryptography, compromising the security of current encryption schemes such as RSA and ECC. In response to this challenge, two main approaches have emerged: quantum cryptography and post-quantum cryptography (PQC). However, both have implementation and security limitations. In this paper, we propose a secure key distribution protocol for Quantum Key Distribution Networks (QKDN), which incorporates encapsulation techniques in the key-relay model for QKDN inspired by onion routing and combined with PQC to guarantee confidentiality, integrity, authenticity and anonymity in communication. The proposed protocol optimizes security by using post-quantum public key encryption to protect the shared secrets from intermediate nodes in the QKDN, thereby reducing the risk of attacks by malicious intermediaries. Finally, relevant use cases are presented, such as critical infrastructure networks, interconnection of data centers and digital money, demonstrating the applicability of the proposal in critical highsecurity environments.
Pedro Otero-García, Javier Blanco-Romero, Ana Fernández Vilas, Daniel Sobral-Blanco, Manuel Fernández-Veiga, Florina Almenárez
ISCC6
2025 Implementing and Evaluating Post-Quantum DNSSEC in CoreDNS
abstract
The emergence of quantum computers poses a significant threat to current secure service, application and/or protocol implementations that rely on RSA and ECDSA algorithms, for instance DNSSEC, because public-key cryptography based on number factorization or discrete logarithm is vulnerable to quantum attacks. This paper presents the integration of post-quantum cryptographic (PQC) algorithms into CoreDNS to enable quantum-resistant DNSSEC functionality for the first time. We have developed a plugin that extends CoreDNS with support for five PQC signature algorithm families: ML-DSA, FALCON, SPHINCS+, MAYO, and SNOVA. Our implementation maintains compatibility with existing DNS resolution flows while providing on-the-fly signing using quantum-resistant signatures. A benchmark has been performed and performance evaluation results reveal significant trade-offs between security and efficiency. The results indicate that while PQC algorithms introduce operational overhead, several candidates offer viable compromises for transitioning DNSSEC to quantum-resistant cryptography.
Julio Gento Suela, Javier Blanco-Romero, Florina Almenárez, Daniel Díaz Sánchez
MSWiM3
2025 Beyond PKI: A DNSSEC Delegation Approach for Scalable Dynamic Credential Management in IoT
abstract
Internet of Things (IoT) systems that manage data across cloud, fog, and edge environments—and the devices that consume those services—face substantial challenges in confidentiality, privacy, and authentication. However, traditional Public Key Infrastructure (PKI) is too rigid and costly for massive, ephemeral IoT deployments. Moreover, device authentication is often overlooked in favor of service authentication, neglecting the security of the entire ecosystem. DNSSEC combined with DANE introduces a new paradigm in which service authentication can be managed globally, extending trust to locally generated, type-agnostic credentials. This framework can accommodate PKI certificates, self-signed credentials, and local keys, all of which can be verified by any client, local or remote. However, DNSSEC’s signature proofs grow linearly with the number of secured records, inflating communication overhead and energy consumption—an issue aggravated by the larger sizes of post-quantum signatures. Additionally, current DNSSEC delegation mechanisms lack the flexibility needed for secure load balancing and isolation. In this article, we present a collision-based DNSSEC signature-delegation mechanism designed to overcome these scalability limitations. By allowing a central DNS authority to delegate signing responsibilities to local DNS servers, our approach reduces certificate-management overhead and enables a dynamic, hierarchical trust model. It supports both service and device authentication in a unified DNS-name-based security context. Our evaluation shows that the proposed mechanism maintains a stable computational cost irrespective of credential count, a critical benefit for large-scale, resource-constrained IoT deployments. By leveraging existing DNS infrastructure and standards, this solution enhances scalability and efficiency compared to traditional PKI and DNSSEC, while promoting interoperability and ease of deployment. It also opens the adoption of future post quantum trapdoor systems still under research and development.
Daniel Díaz Sánchez, Florina Almenárez, Celeste Campo, Carlos García-Rubio, Robert Simon Sherratt
IEEE Internet Things J.2
2024 Integrating Post-Quantum Cryptography into CoAP and MQTT-SN Protocols
abstract
Post-Quantum Cryptography (PQC) is a practical and cost-effective solution to defend against emerging quantum computing threats. So, leading worldwide security agencies and standardization bodies strongly advocate for the proactive integration of PQ cryptography into underlying frameworks to support applications, protocols, and services. The current research predominantly addresses the incorporation of PQC in Internet communication protocols such as HTTP and DNS; nevertheless, the focus on embedded devices has been limited to evaluating PQC’s integration within TLS/DTLS in isolation. Hence, there is a notable gap in understanding how PQC impacts IoT-specific communication protocols. This paper presents the integration of PQC into two communication protocols specifically tailored for IoT devices, the Constrained Application Protocol (CoAP) and MQTT for Sensor Networks (MQTT-SN), via the wolfSSL library. These two integrations contribute to the understanding of PQC’s implications for IoT communication protocols.
Javier Blanco-Romero, Vicente Lorenzo, Florina Almenárez, Daniel Díaz Sánchez, Celeste Campo, Carlos García-Rubio
ISCC3
2024 Inferring mobile applications usage from DNS traffic
abstract
In the digital era, our lives are intrinsically linked to the daily use of mobile applications. As a consequence, we generate and transmit a large amount of personal data that puts our privacy in danger. Despite having encrypted communications, the DNS traffic is usually not encrypted, and it is possible to extract valuable information from the traffic generated by mobile applications. This study focuses on the analysis of the DNS traffic behavior found in mobile application traces, developing a methodology capable of identifying mobile applications based on the domains they query. With this methodology, we were able to identify apps with 98% accuracy. Furthermore, we have validated the effectiveness of the characterization obtained with one dataset by identifying traces from other independent datasets. The evaluation showed that the methodology provides successful results in identifying mobile applications.
Celeste Campo, Carlos García-Rubio, Andrea Jimenez-Berenguel, Marta Moure-Garrido, Florina Almenárez, Daniel Díaz Sánchez
Ad Hoc Networks5
2024 Evaluating integration methods of a quantum random number generator in OpenSSL for TLS
abstract
The rapid advancement of quantum computing poses a significant threat to conventional cryptography. Whilst post-quantum cryptography (PQC) stands as the prevailing trend for fortifying the security of cryptographic systems, the coexistence of quantum and classical computing paradigms presents an opportunity to leverage the strengths of both technologies, for instance, nowadays the use of Quantum Random Number Generators (QRNGs) – considered as True Random Number Generators (TRNGs) – opens up the possibility of discussing hybrid systems. In this paper, we evaluate both aspects, on the one hand, we use hybrid TLS (Transport Layer Security) protocol that leverages the widely used secure protocol on the Internet and integrates PQC algorithms, and, on the other hand, we evaluate two approaches to integrate a QRNG, i.e., Quantis PCIe-240M, in OpenSSL 3.0 to be used by TLS. Both approaches are compared through a Nginx Web server, that uses OpenSSL’s implementation of TLS 1.3 for secure web communication. Our findings highlight the importance of optimizing such integration method, because while direct integration can lead to performance penalties specific to the method and hardware used, alternative methods demonstrate the potential for efficient QRNG deployment in cryptographic systems.
Javier Blanco-Romero, Vicente Lorenzo, Florina Almenárez, Daniel Díaz Sánchez, Carlos García-Rubio, Celeste Campo, Andrés Marín López
Comput. Networks3
2023 Integrating an optimised PUF-based authentication scheme in OSCORE
Jaime Pérez Díaz, Florina Almenárez
Ad Hoc Networks2
2023 Kriper: A blockchain network with permissioned storage
abstract
Blockchain has been a revolution in the past few years. Beyond the new currencies that were created around different incarnations of the blockchain concept, there are many other contributions that provide interesting services as a data linked structure using a decentralized network that provide a high level of security. Companies have developed many projects to incorporate blockchain into their business logic pursuing to incorporate other related services as persistence of large volumes of data, privacy or anonymity of transactions, distributed data processing, security (confidentiality, integrity, and availability), document management or micro messages in real time. Nevertheless, as it will be discussed in this article, current blockchains do not meet the needs of companies in many aspects, leading to a scarce or superficial adoption. This article introduces Kriper, a blockchain that aims at meeting corporate world needs by responding with a community-based, open blockchain that may also be segregated and private for certain uses whereas it provides a permissioned distributed storage and micro message lightweight services.
María Isabel Rojo-Rivas, Daniel Díaz Sánchez, Florina Almenárez, Andrés Marín López
Future Gener. Comput. Syst.3
2021 Performance evaluation of CoAP and MQTT with security support for IoT environments
abstract
World is living an overwhelming explosion of smart devices: electronic gadgets, appliances, meters, cars, sensors, camera and even traffic lights, that are connected to the Internet to extend their capabilities, constituting what is known as Internet of Things (IoT). In these environments, the application layer is decisive for the quality of the connection, which has dependencies to the transport layer, mainly when secure communications are used. This paper analyses the performance offered by these two most popular protocols for the application layer: Constrained Application Protocol (CoAP) and Message Queue Telemetry Transport (MQTT). This analysis aims to examine the features and capabilities of the two protocols and to determine their feasibility to operate under constrained devices taking into account security support and diverse network conditions, unlike the previous works. Since IoT devices typically show battery constraints, the analysis is focused on bandwidth and CPU use, using realistic network scenarios, since this use translates to power consumption.
Victor Seoane, Carlos García-Rubio, Florina Almenárez, Celeste Campo
Comput. Networks3
2019 "I don't see why I would ever want to use it": Analyzing the Usability of Popular Smartphone Password Managers
abstract
Passwords are an often unavoidable authentication mechanism, despite the availability of additional alternative means. In the case of smartphones, usability problems are aggravated because interaction happens through small screens and multilayer keyboards. While password managers (PMs) can improve this situation and contribute to hardening security, their adoption is far from widespread. To understand the underlying reasons, we conducted the first empirical usability study of mobile PMs, covering both quantitative and qualitative evaluations. Our findings show that popular PMs are barely acceptable according to the standard System Usability Scale, and that there are three key areas for improvement: integration with external applications, security, and user guidance and interaction. We build on the collected evidence to suggest recommendations that can fill this gap.
Sunyoung Seiler-Hwang, Patricia Arias Cabarcos, Andrés Marín López, Florina Almenárez, Daniel Díaz Sánchez, Christian Becker 0001
CCS4
2018 RiskLaine: A Probabilistic Approach for Assessing Risk in Certificate-Based Security
abstract
Digital certificates, based on X.509 PKI standard, are located at the core of many security mechanisms implemented in services and applications. However, the usage of certificates has revealed flaws in the certificate validation process (e.g., possibility of unavailable or non-updated data). This fact implies security risks that are not assessed. In order to address these issues that such flaws entail, we propose a novel probabilistic approach for quantitative risk assessment in X.509 PKI, together with trust management when there is uncertainty. We have evaluated our risk assessment approach and demonstrated its usage, considering as a use case the secure installation of mobile applications. The results show that our approach provides more granularity, appropriate values according to the impact, and relevant information in the risk calculation than other approaches.
M. Francisca Hinarejos, Florina Almenárez, Patricia Arias Cabarcos, Josep-Lluís Ferrer-Gomila, Andrés Marín López
IEEE Trans. Inf. Forensics Secur.2
2017 Collaborative eHealth Meets Security: Privacy-Enhancing Patient Profile Management
abstract
Collaborative healthcare environments offer potential benefits, including enhancing the healthcare quality delivered to patients and reducing costs. As a direct consequence, sharing of electronic health records (EHRs) among healthcare providers has experienced a noteworthy growth in the last years, since it enables physicians to remotely monitor patients' health and enables individuals to manage their own health data more easily. However, these scenarios face significant challenges regarding security and privacy of the extremely sensitive information contained in EHRs. Thus, a flexible, efficient, and standards-based solution is indispensable to guarantee selective identity information disclosure and preserve patient's privacy. We propose a privacy-aware profile management approach that empowers the patient role, enabling him to bring together various healthcare providers as well as user-generated claims into an unique credential. User profiles are represented through an adaptive Merkle Tree, for which we formalize the underlying mathematical model. Furthermore, performance of the proposed solution is empirically validated through simulation experiments.
Rosa Sánchez-Guerrero, Florina Almenárez, Daniel Díaz Sánchez, Patricia Arias Cabarcos, Andrés Marín López
IEEE J. Biomed. Health Informatics2
2016 PECEVA: An adaptable and energy-saving credential validation solution for pervasive networks
Florina Almenárez, M. Francisca Hinarejos, Andrés Marín López, Josep-Lluís Ferrer-Gomila, Daniel Díaz Sánchez
Inf. Sci.1
2011 Trust management for multimedia P2P applications in autonomic networking
Florina Almenárez, Andrés Marín López, Daniel Díaz Sánchez, Alberto Cortés-Martín, Celeste Campo, Carlos García-Rubio
Ad Hoc Networks1
2010 Introducing Infocards in NGN to Enable User-Centric Identity Management
abstract
With the rapid evolution of networks and the widespread penetration of mobile devices with increasing capabilities, that have already become a commodity, we are getting a step closer to ubiquity. Thus, we are moving a great part of our lives from the physical world to the online world, i.e. social interactions, business transactions, relations with government administrations, etc. However, while identity verification is easy to handle in the real world, there are many unsolved challenges when dealing with digital identity management, especially due to the lack of user awareness when it comes to privacy. Thus, with the aim to enhance the navigation experience and security in multiservice and multiprovider environments the user must be empowered to control how her attributes are shared and disclosed between different domains.With these goals on mind, we leverage the benefits of the Infocard technology and introduce this usercentric paradigm into the emerging NGN architectures. This paper proposes a way to combine the gains of a SAML federation between service and identity providers with the easiness for the final user of the Inforcard System using the well known architectural schema of IP Multimedia Subsystem.
Davide Proserpio, Fabio Sanvido, Patricia Arias Cabarcos, Rosa Sánchez-Guerrero, Florina Almenárez, Daniel Díaz Sánchez, Andrés Marín López
GLOBECOM5
2010 Pervasive authentication and authorization infrastructures for mobile users
Jordi Forné, M. Francisca Hinarejos, Andrés Marín López, Florina Almenárez, Javier López 0001, José A. Montenegro, Marc Lacoste, Daniel Díaz Sánchez
Comput. Secur.4
2009 Towards dynamic trust establishment for identity federation
abstract
Federation has emerged as a key concept for identity management, as it is the basis to reduce complexity in the companies and improve user experience. However, the problem of establishing identity federations in dynamic open environments, where it is desirable to speed up the processes of service provisioning and deprovisioning, has not been fully addressed. This paper reviews the existing frameworks for identity federation, analyzing the underlying trust mechanisms and its suitability to be applied in the mentioned environments. Finally, we propose a generic extension for the Security Assertion Markup Language (SAML) standard in order to facilitate the creation of federation relationships in a secure dynamic way between prior unknown parties.
Florina Almenárez, Patricia Arias Cabarcos, Andrés Marín López, Daniel Díaz Sánchez
EATIS1
2008 A Trust-based Middleware for Providing Security to Ad-Hoc Peer-to-Peer Applications
abstract
Trust has emerged as an important facet of inter-domain relationships. Trust management in fixed networks is not functional in ad hoc P2P networks, because these require an autonomous, user-centric and non-static trust management. The trust model is the basis of any security infrastructure. In this paper, we propose a trust-based middleware for secure digital content sharing between pervasive devices. Such middleware allows to enhance security support of pervasive devices. Likewise, we propose a suitable and efficient secure file exchange protocol, WSFEP, for content sharing. Both middleware and file sharing application have been successfuly integrated and tested on PDAs.
Florina Almenárez, Andrés Marín López, Daniel Díaz Sánchez, Alberto Cortés-Martín, Celeste Campo, Carlos García-Rubio
PerCom1
2008 Building an Open Toolkit of Digital Certificate Validation for Mobile Web Services
abstract
Mobile devices can both consume and provide services. They act indeed as a peer, according to the OMA mobile Web services specification. It is a move from simple data sharing to full deliver of application services down to mobile devices. The use of digital certificates to ensure the provision of services is suitable because devices can belong to different trust domains without having previously an established relationship. Besides, by interoperability issues, the use of PKI continues to grow and move into diverse environments. However, applications making use of such certificates are burdened with the overhead of constructing and validating the certification paths. These processes can become more complex and costly than fixed-infrastructure networks due to the wireless communications and restricted processing and power capabilities. The IETF PKIX WG has specified different mechanisms for delegating the certificate validation and making lighter the status information obtaining. However, these are not supported currently by mobile devices. For these reasons, we propose to develop an open toolkit for X.509 public key certificate validating based on OpenSSL. This toolkit is being developed and tested successfully in PDAs.
Florina Almenárez, Andrés Marín López, Daniel Díaz Sánchez, Alberto Cortés-Martín, Celeste Campo, Carlos García-Rubio
PerCom1
2007 Access Control Agnostic Trust Negotiation Decision Engine
abstract
Dynamic open environments demand trust negotiation systems for unknown entities willing to communicate. A security context have to be negotiated gradually in a fair peer to peer basis. Trust negotiation engines are driven by decision engines that lack of flexibility: they depend on the implementation, policies languages or credentials types to be used. In this paper we present a trust negotiation engine agnostic regarding policies and rules. The engine is based on iterative weighted Multidimensional Scaling to assist a mobile device during a trust negotiation.
Daniel Díaz Sánchez, Andrés Marín López, Florina Almenárez
PIMRC3
2007 Smart card-based agents for fair non-repudiation
Andrés Marín López, Daniel Díaz Sánchez, Florina Almenárez, Carlos García-Rubio, Celeste Campo
Comput. Networks3
2006 A Smart Card Solution for Access Control and Trust Management for Nomadic Users
Daniel Díaz Sánchez, Andrés Marín López, Florina Almenárez
CARDIS3
2006 PDP: A lightweight discovery protocol for local-scope interactions in wireless ad hoc networks
Celeste Campo, Carlos García-Rubio, Andrés Marín López, Florina Almenárez
Comput. Networks4
2004 Secure Ad-Hoc mBusiness: EnhancingWindowsCE Security
Florina Almenárez, Daniel Díaz Sánchez, Andrés Marín López
TrustBus1