Nicolae Paladi

dblp:73/7373 · DBLP profile ↗
← Back
11ranked-venue papers
6as first author
5since 2021 · last 2025
0000-0003-0132-857XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 5 first-author · 3 since 2021Systems, architecture and hardware · 3 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2025 TAPShield: Securing Trigger-Action Platforms against Strong Attackers
abstract
Automation apps enable seamless connection of IoT devices and services to provide useful functionality for end-users. Apps are typically executed on cloud-based Trigger-Action Platforms (TAPs) such as IFTTT and Node-RED, supporting both single- and multi-tenant models. Such models raise security and privacy concerns in the face of cloud attackers and malicious app makers, resulting in massive and uncontrolled exfiltration of sensitive user data.To address these concerns, we design TAPShield, an architecture that uses confidential computing and language-level sandboxing to protect user data against untrustworthy TAPs and malicious apps. TAPShield targets JavaScript-driven TAPs built on the Node.js environment and uses trusted execution environments implemented with Intel SGX to protect against cloud attackers. It further uses language-level sandboxes such as vm2 and SandTrap to protect against malicious apps. We implement TAPShield for two popular TAPs, Node-RED and IFTTT, and report on the security, performance, and compatibility trade-offs on a range of real-world apps. Our results show clear security benefits with acceptable performance overhead, while adhering to existing development practices of production-scale TAPs.
Mojtaba Moazen, Nicolae Paladi, Adnan Jamil Ahsan, Musard Balliu
EuroS&P2
2022 SGX-Bundler: speeding up enclave transitions for IO-intensive applications
abstract
Process-based confidential computing enclaves such as Intel SGX can be used to protect the confidentiality and integrity of workloads, without the overhead of virtualisation. However, they introduce a notable performance overhead, especially when it comes to transitions in and out of the enclave context. Such overhead makes the use of enclaves impractical for running IO-intensive applications, such as network packet processing or biological sequence analysis. We build on earlier approaches to improve the IO performance of work-loads in Intel SGX enclaves and propose the SGX-Bundler library, which helps reduce the cost of both individual single enclave transitions well as of the total number of enclave transitions in trusted applications running in Intel SGX enclaves. We describe the implementation of the SGX-Bundler library, evaluate its performance and demonstrate its practicality using the case study of Open vSwitch, a widely used software switch implementation.
Jakob Svenningsson, Nicolae Paladi, Arash Vahidi
CCGRID2
2022 Chuchotage: In-line Software Network Protocol Translation for (D)TLS
Pegah Nikbakht Bideh, Nicolae Paladi
ICICS2
2021 Evolving 5G: ANIARA, an edge-cloud perspective
abstract
ANIARA (https://www.celticnext.eu/project-ai-net) attempts to enhance edge architectures for smart manufacturing and cities. AI automation, orchestrated lightweight containers, and efficient power usage are key components of this three-year project. Edge infrastructure, virtualization, and containerization in future telecom systems enable new and more demanding use cases for telecom operators and industrial verticals. Increased service flexibility adds complexity that must be addressed with novel management and orchestration systems. To address this, ANIARA will provide en-ablers and solutions for services in the domains of smart cities and manufacturing deployed and operated at the network edge(s).
Ian Marsh, Nicolae Paladi, Henrik Abrahamsson, Jonas Gustafsson, Johan Sjöberg, Andreas Johnsson, Pontus Sköldström, Jim Dowling, Paolo Monti 0001, Melina Vruna, Mohsen Amiribesheli
CF2
2021 Flowrider: Fast On-Demand Key Provisioning for Cloud Networks
Nicolae Paladi, Marco Tiloca, Pegah Nikbakht Bideh, Martin Hell
SecureComm (2)1
2019 SDN Access Control for the Masses
Nicolae Paladi, Christian Gehrmann 0001
Comput. Secur.1
2018 Trust Anchors in Software Defined Networks
Nicolae Paladi, Linus Karlsson, Khalid Elbashir
ESORICS (2)1
2017 Providing User Security Guarantees in Public Infrastructure Clouds
abstract
The infrastructure cloud (IaaS) service model offers improved resource flexibility and availability, where tenants - insulated from the minutiae of hardware maintenance - rent computing resources to deploy and operate complex systems. Large-scale services running on IaaS platforms demonstrate the viability of this model; nevertheless, many organizations operating on sensitive data avoid migrating operations to IaaS platforms due to security concerns. In this paper, we describe a framework for data and operation security in IaaS, consisting of protocols for a trusted launch of virtual machines and domain-based storage protection. We continue with an extensive theoretical analysis with proofs about protocol resistance against attacks in the defined threat model. The protocols allow trust to be established by remotely attesting host platform configuration prior to launching guest virtual machines and ensure confidentiality of data in remote storage, with encryption keys maintained outside of the IaaS domain. Presented experimental results demonstrate the validity and efficiency of the proposed protocols. The framework prototype was implemented on a test bed operating a public electronic health record system, showing that the proposed protocols can be integrated into existing cloud environments.
Nicolae Paladi, Christian Gehrmann 0001, Antonis Michalas
IEEE Trans. Cloud Comput.1
2016 TruSDN: Bootstrapping Trust in Cloud Network Infrastructure
Nicolae Paladi, Christian Gehrmann 0001
SecureComm1
2014 Security aspects of e-Health systems migration to the cloud
abstract
As adoption of e-health solutions advances, new computing paradigms - such as cloud computing - bring the potential to improve efficiency in managing medical health records and help reduce costs. However, these opportunities introduce new security risks which can not be ignored. Based on our experience with deploying part of the Swedish electronic health records management system in an infrastructure cloud, we make an overview of major requirements that must be considered when migrating e-health systems to the cloud. Furthermore, we describe in-depth a new attack vector inherent to cloud deployments and present a novel data confidentiality and integrity protection mechanism for infrastructure clouds. This contribution aims to encourage exchange of best practices and lessons learned in migrating public e-health systems to the cloud.
Antonis Michalas, Nicolae Paladi, Christian Gehrmann 0001
Healthcom2
2014 Trusted Geolocation-Aware Data Placement in Infrastructure Clouds
abstract
Data geolocation in the cloud is becoming an increasingly pressing problem, aggravated by incompatible legislation in different jurisdictions and compliance requirements of data owners. In this work we present a mechanism allowing cloud users to control the geographical location of their data, stored or processed in plaintext on the premises of Infrastructure-as-a Service cloud providers. We use trusted computing principles and remote attestation to establish platform state. We enable cloud users to confine plaintext data exclusively to the jurisdictions they specify, by sealing decryption keys used to obtain plaintext data to the combination of cloud host geolocation and platform state. We provide a detailed description of the implementation as well as performance measurements on an open source cloud infrastructure platform using commodity hardware.
Nicolae Paladi, Mudassar Aslam, Christian Gehrmann 0001
TrustCom1