VLDB 2026 Research / reviewers in the wild / expert
Diego R. López
dblp:78/1845
· DBLP profile ↗
40ranked-venue papers
1as first author
11since 2021 · last 2026
0000-0002-8326-2000ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 14 · 1 first-author · 3 since 2021Security and privacy · 6 · 2 since 2021Software engineering, systems software and programming languages · 5 · 3 since 2021Systems, architecture and hardware · 4 · 1 since 2021Artificial intelligence and machine learning · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Making IBN Tractable by Enhanced Policy Verification: The NIPOV Algorithm
Pedro Martinez-Julia, Ved P. Kafle, Hitoshi Asaeda, Diego R. López, Antonio F. Skarmeta |
NetSoft | 4 |
| 2026 | Quantum resistant software Defined-Networking IPsec, enabling ITS communication over IP networks on real telco infrastructuresabstract• The first functional implementation that integrates SDN, QKD, and IPsec technologies within a unified architecture, enabling dynamic establishment of IPsec tunnels protected with Quantum Key Distribution. • The proposed solution is based on the implementation of IPsec in accordance with QKD-related standards defined by ETSI, specifically adhering to the specifications ETSI GS QKD 004 and ETSI GS QKD 015. This approach ensures interoperability and alignment with current best practices for quantum secure network deployments. • Experimental results were obtained from a field-deployed QKD network operating over a hybrid quantum-classical infrastructure, providing empirical validation of the proposed approach in a production-grade environment laying a solid foundation for future large-scale deployments. The importance of digital communications makes protecting data in transit a critical priority. Internet Protocol Security (IPsec) plays a central role in this protection, by ensuring data confidentiality, integrity, and authenticity. However, quantum computing threatens the foundations of IPsec. Its ability to efficiently solve mathematical problems such as factoring and discrete logarithms could break the public-key cryptography used for IPsec key exchange. Quantum Key Distribution (QKD) is one of the most promising solutions to this problem, offering a security layer immune to both classical and quantum computational attacks. This work proposes a solution that integrates emerging quantum technologies into existing security and communication infrastructures to ensure long-term protection. We combine IPsec with Software-Defined Networking and QKD to build a novel network security infrastructure. It is designed to resist both classical and quantum threats. It is based on recent standardization efforts and operational tools for QKD integration. We demonstrate advanced capabilities such as rekeying and secure key transport on a field deployed QKD network operating within a shared quantum-classical production infrastructure. Rubén B. Mendez, Jaime S. Buruaga, Juan Pedro Brito, Antonio Pastor 0001, Diego R. López, Vicente Martín |
Comput. Networks | 5 |
| 2026 | Trust-based intent management for 6G: A level of trust assessment functionabstract• Trust as a new intent for orchestrating the future 6G networks. • Continuous network assurance for cloud continuum services. • The Level of Trust framework monitors and double checks trust level agreements. • Trust-oriented ontology for Cloud Continuum and intent-based scenarios. Intent-Based Networking (IBN) has gained prominence from both industry and research communities for boosting network automation and reducing network complexity in multi-stakeholder scenarios. IBN helps service and network providers understand and translate high-level business goals by escaping from technical details. Nevertheless, the rapid evolution of service requirements in dynamic multi-stakeholder environments needs to be considered by suppliers in order to meet the continuous demands of their customers. In this regard, trustworthiness is recognized as a key feature to assess reliability, compliance, and user perception of 6G services. In that spirit, this article aims to pave the way for encompassing trustworthiness, or Level of Trust (LoT), as a new intent to properly deliver service provisioning in 6G solutions. In particular, the LoT framework introduces a set of functionalities to guarantee a proper definition of requirements (Trust Level Agreements, TLAs), their interpretation, translation, consistency, and assurance during an ongoing relationship. To this end, this article presents a trust-based intent management approach with an ad-hoc interpreter that is, in turn, powered by a trust-based ontology for Cloud Continuum scenarios. Besides, a Level of Trust Assessment Function (LoTAF) is designed to monitor and report updates and events regarding LoT continuously. Such a monitoring engine follows the IETF basics of service assurance for IBN architecture. Last but not least, experiments in a collaborative robot warehouse scenario showcase that LoTAF enables workload allocation to the most trustworthy compute nodes, improving confidence in service orchestration, while introducing negligible overheads (1.40 % RAM, 5.01 % CPU, and 0.1069s latency). José María Jorquera Valero, Alfonso Serrano Gil, Javier Paredes Serrano, Ignacio Dominguez Martinez-Casanueva, Lucía Cabanillas Rodríguez, Riccardo Nicolicchia, Diego R. López, Manuel Gil Pérez, Vasiliki Lamprousi, Sokratis Barmpounakis, Panagiotis Demestichas |
Comput. Networks | 7 |
| 2025 | Transparent Notary Service: A Transparency Framework for Secure and Verifiable Network EvidenceabstractEnsuring data integrity and traceability poses a significant challenge in contemporary network environments, particularly in the context of cloud-native architectures, SoftwareDefined Networks (SDN), Internet of Things (IoT), and imminent 6G technologies. Conventional data collection and verification methodologies have deficiencies in terms of transparency and auditability, limiting decision-making processes and their automation. To address these issues, we propose the application of a Transparent Notary Service (TNS), a digital notarization framework that enables the secure registration and assessment of evidence statements on network elements, using append-only logs and cryptographic signatures. The proposed system leverages efficient digital signatures and verifiable and immutable records to provide a trusted evidence registry, enabling entities to register signed statements while ensuring their integrity without the need for content validation. This approach enhances Zero Trust Architectures (ZTA) by providing cryptographically verifiable data that can support access control decisions, network orchestration, and forensic auditing. This paper presents a conceptual framework and an initial design approach for the TNS, outlining its key components and potential implementation paths rather than a fully deployed system. The proposed framework ensures secure, efficient, and transparent evidence registration, offering a lightweight alternative to traditional blockchain-based solutions. Future work will explore extended format support, enhanced storage optimization, and automated integrity verification mechanisms. Ana Méndez, Lucía Cabanillas Rodríguez, Diego R. López |
NetSoft | 3 |
| 2025 | CyberNEMO: Enhancing End-to-End Cybersecurity and Privacy in the IoT-Edge-Cloud ContinuumabstractAccording to the EU State of Cybersecurity report by the European Union Agency for Cybersecurity (ENISA), the number of cybersecurity-related incidents will increase by 24 percent by 2025, with ransomware and DoS/DDoS attacks being the most common. The emergence of new threats [1] and the consolidation of existing ones require doubling of efforts in proactive prevention and a decisive increase in research dedicated to cybersecurity. CyberNEMO (End-to-end Cybersecurity to NEMO meta-OS) project emerges as an evolution of the NEMO (Next Generation Meta Operating System) platform, designed to provide a secure, trustworthy, and robust execution environment across the IoT-Edge-Cloud computing continuum. Leveraging NEMO modular meta-operating system (mOS) framework, CyberNEMO introduces advanced cybersecurity and privacy-preserving mechanisms, emphasizing Zero Trust principles. This paper presents the CyberNEMO architecture, details its core innovative technologies, and describes its validation strategy through diverse living labs-including Smart Energy, Smart Water, Smart Manufacturing, Healthcare, Multimedia Distribution, and Smart Farming scenarios-demonstrating end-to-end cybersecurity and real-time threat mitigation capabilities, aligned with Europe's strategic cybersecurity goals. Theodore B. Zahariadis, Artemis C. Voulkidis, Ilias Nektarios Seitanidis, Andreas E. Papadakis, Alberto del Río, Javier Serrano 0003, David Jiménez, Antonio Pastor 0001, Diego R. López, Alejandro Muñiz, Mattin Antartiko Elorza Forcada, Ana Méndez, Wafa Ben Jaballah, Rosaria Rossini, Maria Belesioti, Ioannis P. Chochliouros, Marco Angelini, Vasileios Megalooikonomou, Carmela Occhipinti, Luigi Briguglio, Alexandru Plesa, Vladut Dinu, Mohammad Ghoreishi, Mostafa Jabari, Dimitrios Skias, Konstantinos Sakatis, Ioannis Papaefstathiou |
SRDS | 9 |
| 2024 | PQ-REACT: Post Quantum Cryptography Framework for Energy Aware ContextsabstractPublic key cryptography is nowadays a crucial component of global communications which are critical to our economy, security and way of life. The quantum computers are expected to be a threat and the widely used RSA, ECDSA, ECDH, and DSA cryptosystems will need to be replaced by quantum safe cryptography. The main objective of the HORIZON Europe PQ-REACT project is to design, develop and validate a framework for a faster and smoother transition from classical to quantum safe cryptography for a wide variety of contexts and usage domains that could have a potential interest for defence purposes. This framework will include Post Quantum Cryptography (PQC) migration paths and cryptographic agility methods and will develop a portfolio of tools for validation of post quantum cryptographic systems using Quantum Computing. A variety of real-world pilots using PQC and Quantum Cryptography, i.e., Smart Grids, 5G and Ledgers will be deployed to validate the defined framework. Marta Irene García Cid, Michail-Alexandros Kourtis, David Domingo Martín, Nikolay Tcholtchev, Evangelos Markakis 0002, Marcin Niemiec, Javier Faba, Laura Ortíz, Vicente Martín, Diego R. López, Georgios Xilouris, Maria Gagliardi, Miguel García 0003, Giovanni Comandè, Nikolai Stoianov |
ARES | 10 |
| 2024 | Framework for the development of a Network Digital TwinabstractNetwork Digital Twin (NDT) has emerged as a groundbreaking paradigm, revolutionizing the modeling of modern and complex networks. NDTs are emulation of real-world networks that can be used for a variety of purposes, such as network experimentation, optimization and security. NDTs achieve reproducibility by consistently producing results under identical conditions and repeatability by facilitating controlled variation experiments.The NDT proposed in this work is designed to be a versatile and adaptable platform, capable of supporting a wide range of network experimentation and optimization tasks, going beyond the limitations of existing solutions.This paper introduces our proposal for developing a NDT framework, providing insight into our ongoing work and the exploration, analysis, and conclusions we have reached in this context. In essence, this paper outlines our vision for a NDT in contrast to the NDT proposed in the literature. Ángela Burgaleta, Ignacio Dominguez Martinez-Casanueva, Amit Karamchandani, Diego R. López, Antonio Pastor 0001 |
NOMS | 4 |
| 2024 | Design of an AI-driven Network Digital Twin for advanced 5G-6G network managementabstractThe Network Digital Twin (NDT) developed in the B5GEMINI project is presented in this article, highlighting its architecture, objectives, functionalities, and practical applications. The design of the NDT architecture is detailed, including the establishment of the foundational infrastructure, developed as part of B5GEMINI-INFRA. The integration of artificial intelligence techniques for network management tasks within B5GEMINI-AIUC is illustrated with relevant use cases, such as the detection of cybersecurity attacks and the simulation and optimization of virtual reality applications, to demonstrate the usefulness and potential of the proposed NDT solution. The platform enables controlled experimentation and data collection for training Machine Learning (ML) models, addressing challenges associated with realistic network traffic datasets and cybersecurity experiments without disrupting live networks. The infrastructure supporting the NDT allows for creating virtual scenarios, isolating traffic between experiments, on-demand traffic generation, and capture, ensuring repeatability and enabling evaluation of different detection and mitigation tools under identical conditions. Additionally, an in-depth use case focusing on ML-based detection of a simulated denial of service attack through DNS over HTTPS within a 5G network framework showcases the NDT’s potential to provide a secure environment for testing and validating ML-based solutions without disrupting live networks. Amit Karamchandani, Mario Sanz Rodrigo, Ángela Burgaleta, Luis De La Cal, Alberto Mozo, José Ignacio Moreno, Antonio Pastor 0001, Diego R. López |
NOMS | 8 |
| 2024 | CANDIL: A federated data fabric for network analyticsabstractThe availability of data sources during the Big Data era provides the opportunity for new analytical applications in the networking domain, which are envisioned as one of the main enablers of the future autonomous networks. But the proliferation of heterogeneous data sources has resulted into a sea of data silos, in which finding data, understanding data, and dealing with the complexities of each data source becomes a challenge. Aiming to tackle the connection of data silos, the data fabric has appeared as a new paradigm that provides a uniform access to all the data, abstracting consumers from the underlying complexities of the data sources. In this regard, the knowledge graph has raised as a promising solution that can integrate data from heterogeneous silos based on common concepts captured in ontologies. Building upon knowledge graph standards, this paper introduces CANDIL, a federated data fabric to support the integration of data from distributed systems, mainly focused on networking domain aspects. CANDIL defines an ontology that captures network topology and interface concepts, along with a reference architecture to ingest and integrate data in a federated knowledge graph that spans across the Edge-Cloud continuum. The proposal is validated with a prototype implementation and two example use cases of network analytics. Ignacio Dominguez Martinez-Casanueva, Luis Bellido, Daniel González-Sánchez, Diego R. López |
Future Gener. Comput. Syst. | 4 |
| 2023 | A Multi-domain Testbed for Collaborative Research on the IoT-Edge-Cloud ContinuumabstractThis poster showcases an industry-academia collaboration between Telefónica and Universidad Carlos III de Madrid, aiming to establish a testbed to support research and experimentation with novel IoT, edge, and cloud computing technologies. The testbed has been deployed at the 5G Telefonica Open Network Innovation Centre (5TONIC), and enables the seamless integration of IoT/Edge/Cloud infrastructure domains using virtual and hardware components that can be made available both within 5TONIC and external premises. The design of the testbed is based on key enabling technologies in 5G/6G networking, including Network Function Virtualization (NFV), Software Defined Networking (SDN), and cloud-native computing, as well as on a Secure Infrastructure Abstraction (SIA) that facilitates automation and secure network communications. Iván Vidal, Luis F. Gonzalez, Francisco Valera, Borja Nogales, Raul Martin, Dulce N. de M. Artalejo, Diego R. López, Jose Manuel Manjón, Antonio Pastor 0001 |
SECON | 7 |
| 2022 | Model-Driven Network Monitoring Using NetFlow Applied to Threat DetectionabstractIn recent years, several research works have proposed the analysis of network flow information using machine learning in order to detect threats or anomalous activities. In this sense, NetFlow-based systems stand out as one of the main sources of network flow information. In these systems, NetFlow collectors provide the flow monitoring information to be analyzed, but the particular information structure and format provided by different collector implementations is a recurring problem. In this paper, a new YANG data model is proposed as a standard model to use NetFlow-based monitoring data. In order to validate the proposal, a NetFlow collector incorporating the proposed NetFlow YANG model has been developed, to be integrated in a network scenario in which network flows are analyzed to detect malicious cryptomining activity. This collector extends an existing one, and provides design patterns to incorporate other existing collectors into this common data model. Our results show how, by using the YANG modeling language, network flow information can be handled and aggregated in a formal and unified way that provides flexibility and facilitates data analysis applied to threat detection. Daniel González-Sánchez, Ignacio Dominguez Martinez-Casanueva, Antonio Pastor 0001, Luis Bellido, Cristina Pinar Muñoz Zamarro, Alejandro Antonio Moreno Sancho, David Fernández 0002, Diego R. López |
NetSoft | 8 |
| 2020 | INSPIRE-5Gplus: intelligent security and pervasive trust for 5G and beyond networksabstractThe promise of disparate features envisioned by the 3GPP for 5G, such as offering enhanced Mobile Broadband connectivity while providing massive Machine Type Communications likely with very low data rates and maintaining Ultra Reliable Low Latency Communications requirements, create a very challenging environment for protecting the 5G networks themselves and associated assets. To overcome such complexity, future 5G networks must employ a very high degree of network and service management automation, which is a security challenge by itself as well as an opportunity for smarter and more efficient security functions. In this paper, we present the smart, trustworthy and liable 5G security platform being designed and developed in the INSPIRE-5Gplus1 project. This platform takes advantage of new techniques such as Machine Learning (ML), Artificial Intelligence (AI), Distributed Ledger Technologies (DLT), network softwarization and Trusted Execution Environment (TEE) for closed-loop and end-to-end security management following a zero-touch model in 5G and Beyond 5G networks. To this end, we specifically elaborate on two key aspects of our platform, namely security management with Security Service Level Agreements (SSLAs) and liability management, in addition to the description of the overall architecture. Jordi Ortiz 0001, Ramon Sanchez-Iborra, Jorge Bernal Bernabé, Antonio F. Skarmeta, Chafika Benzaid, Tarik Taleb, Pol Alemany, Raul Muñoz 0001, Ricard Vilalta, Chrystel Gaber, Jean-Philippe Wary, Dhouha Ayed, Pascal Bisson, Maria Christopoulou, Georgios Xilouris, Edgardo Montes de Oca, Gürkan Gür, Gianni Santinelli, Vincent Lefebvre, Antonio Pastor 0001, Diego R. López |
ARES | 21 |
| 2020 | Exploiting Case Based Reasoning to Automate Management of Network SlicesabstractNetwork softwarization is a transformation trend for networks to converge in programmable service platforms able to host different requirements from multiple tenants. The concept of network slicing plays a key role in this trend. It offers isolated logical networks to different tenants over the same underlying infrastructure. Network slices hosting missioncritical services require fast reactions to changes in environment, adapting their capacity as needed to avoid service disruption and performance degradation. This represents a key challenge for the management plane, traditionally under the direct operation of human administrators, unable to provide a nimble enough response rate. To support tenants in driving lifecycle management operations over their network slices in a timely manner, datadriven, closed-loop mechanisms must be designed. In this paper we introduce a solution that takes advantage of events occurring outside the boundaries of a tenant-managed network slice to guide those adaptations. We finally demonstrate the feasibility of the proposal and describe an experimentation scenario to exploit such results. Pedro Martinez-Julia, Jose A. Ordonez-Lucena, Ved P. Kafle, Hitoshi Asaeda, Diego R. López |
NOMS | 5 |
| 2019 | Adding Support for Automatic Enforcement of Security Policies in NFV NetworksabstractThis paper introduces an approach toward the automatic enforcement of security policies in network functions virtualization (NFV) networks and dynamic adaptation to network changes. The approach relies on a refinement model that allows the dynamic transformation of high-level security requirements into configuration settings for the network security functions (NSFs), and optimization models that allow the optimal selection of the NSFs to use. These models are built on a formalization of the NSF capabilities, which serves to unequivocally describe what NSFs are able to do for security policy enforcement purposes. The approach proposed is the first step toward a security policy aware NFV management, orchestration, and resource allocation system-a paradigm shift for the management of virtualized networks-and it requires minor changes to the current NFV architecture. We prove that our approach is feasible, as it has been implemented by extending the OpenMANO framework and validated on several network scenarios. Furthermore, we prove with performance tests that policy refinement scales well enough to support current and future virtualized networks. Cataldo Basile, Fulvio Valenza, Antonio Lioy, Diego R. López, Antonio Pastor 0001 |
IEEE/ACM Trans. Netw. | 4 |
| 2018 | The Mouseworld, a security traffic analysis lab based on NFV/SDNabstractMachine Learning (ML) technologies applied to Cybersecurity, especially in the area of network cyber threat detection, are a promising choice, but they require additional research in the applicability of a wide range of available algorithms. Such algorithms usually require training using good-quality and quantitatively significant datasets, which are rarely publicly available. To this end, in this paper we describe a novel experimental framework, that we call the Mouseworld, that combines NFV and SDN to create an environment able to (1) blend and transmit real and synthetic traffic and (2) collect and label this traffic in order to be utilised for training and validating ML algorithms that will be applied to the detection of cybersecurity threats. The Mouseworld framework includes a set of traffic generation, collection and labelling modules, jointly with analytics and algorithm training and visualization components. The OSM open-source network orchestrator is utilized to control and manage the framework and to deploy the training and validation scenarios. We present a preliminary result on the area of Security threat detection as a demonstration of the framework viability. Antonio Pastor 0001, Alberto Mozo, Diego R. López, Jesús Folgueira, Angeliki Kapodistria |
ARES | 3 |
| 2018 | LightMANO: Converging NFV and SDN at the edges of the networkabstractNetwork Function Virtualization (NFV) has raised tremendous attention in the academic and industrial communities alike. The former have been attracted by the service centric orchestration challenges. The latter have found that, by decoupling network functions from the underling hardware, significant savings can be obtained by means of infrastructure homogenization and service automation. As opposed to the initial NFV solutions, which heavily relied on a centralized cloud model, the emerging Multi-access Edge Computing trend is calling for a distribution of computational capacity at the customers' sites. This change of paradigm could result in the deployment of tens of thousands or even millions of Points-of-Presence. In this article we discuss the fundamental challenges of deploying NFV in scattered environments, then we introduce the Light-MANO framework, a Multi-access Network Operating System converging SDN and NFV into a single lightweight platform for management and orchestration of network services over distributed NFV infrastructure. Finally, we report on a proof- of-concept implementation of LightMANO and on its evaluation. Roberto Riggio, Shah Nawaz Khan, Tejas Subramanya, Imen Grida Ben Yahia, Diego R. López |
NOMS | 5 |
| 2018 | Insights from SONATA: Implementing and integrating a microservice-based NFV service platform with a DevOps methodologyabstractIn pursuit of a flexible, resource efficient and high- performant 5G infrastructure, many operators, vendors and research consortia are currently developing, testing and integrating their NFV platform with associated management and orchestration (MANO) functionality. The SONATA NFV platform follows a micro-service design, which involves a tight coupling between an SDK, monitoring and MANO functionality, targeting a secure and stable software foundation. This experience paper gives a thorough overview on the encountered challenges, insights and resulting learnings when implementing and integrating the SONATA Service Platform using a continuous integration and delivery DevOps methodology. This is the result of a strong cooperation between prominent equipment vendors, network operators, software companies and universities, providing a set of constructive recommendations in hope of catalysing the development and deployment of NFV platforms. Thomas Soenen, Steven van Rossem, Wouter Tavernier, Felipe Vicens, Dario Valocchi, Panagiotis Trakadas, Panagiotis Karkazis, Georgios Xilouris, Philip Eardley, Stavros Kolometsos, Michail-Alexandros Kourtis, Daniel Guija, Muhammad Shuaib Siddiqui, Peer Hasselmeyer, José Bonnet, Diego R. López |
NOMS | 16 |
| 2018 | Mobility management in RINA networks: Experimental validation of architectural propertiesabstractMobility management is a challenging problem in current networks, typically requiring dedicated, specialised protocols that manage the lifetime of a series of tunnels that follow mobile hosts as they roam through the network. The fundamental issue that complicates the mobility management problem is the lack of a complete naming and addressing schema in the current Internet architecture. This paper analyses what properties such schema needs to have, and discusses how Internet mobility solutions are missing parts of it. Then it looks at RINA, a network architecture with a complete naming scheme. Theoretical analysis backed up by experimental validation of the main properties for mobility support shows that managing mobility in RINA networks not only is simpler and easier to scale compared to the Internet situation, but also that no special protocols or mechanisms need to be added to RINA in order to support mobility. Eduard Grasa, Leonardo Bergesio, Miquel Tarzan-Lorente, Diego R. López, Sven van der Meer, John Day 0001, Lubomir T. Chitkushev |
WCNC | 4 |
| 2018 | SCoT: A secure content-oriented transportabstractThe evolution of the Internet has resulted in the deployment of new applicationlevel solutions to enhance the scalability and efficiency of content dissemination (e.g., content delivery networks and peer-to-peer systems).However, despite of this improvement on performance, the utilization of this type of solutions introduces new security concerns, as a content provider must necessarily delegate the role of distributing the content to third parties, and current security solutions, such as TLS and IPsec, do not allow authenticating the original content provider or the content itself in these scenarios.In this paper, we present SCoT, a transport-layer protocol that allows a content provider to bind protection to content, enabling content authentication at receivers regardless of any third party infrastructures that have been used to disseminate the content.Content authentication procedures are executed transparently to end-user applications.We implemented a fully operational prototype of the protocol in Java, including an API to support the development of SCoT applications.We utilized it to configure an experimentation scenario that served to validate a theoretical analysis of the SCoT throughput and to illustrate the performance that can be achieved in a practical deployment.The paper concludes describing a set of use cases of the protocol. Iván Vidal, Jaime García-Reinoso, Ignacio Soto, Francisco Valera, Diego R. López |
J. Netw. Comput. Appl. | 5 |
| 2017 | A unifying operating platform for 5G end-to-end and multi-layer orchestrationabstractHeterogeneity of current software solutions for 5G is heading for complex and costly situations, with high fragmentation, which in turn creates uncertainty and the risk of delaying 5G innovations. This context motivated the definition of a novel Operating Platform for 5G (5G-OP), a unifying reference functional framework supporting end-to-end and multi-layer orchestration. 5G-OP aims at integrated management, control and orchestration of computing, storage, memory, networking core and edge resources up to the end-user devices and terminals (e.g., robots and smart vehicles). 5G-OP is an overarching architecture, with agnostic interfaces and well-defined abstractions, offering the seamless integration of current and future infrastructure control and orchestration solutions (e.g., OpenDaylight, ONOS, OpenStack, Apache Mesos, OpenSource MANO, Docker, LXC, etc.) The paper provides also the description of a prototype that can be seen as a simplified version of a 5G-OP, whose feasibility has been demonstrated in Focus Group IMT2020 of ITU-T. Antonio Manzalini, Diego R. López, Håkon Lønsethagen, Lucian Suciu, Roberto Bifulco, Marie-Paule Odini, Giuseppe Celozzi, Barbara Martini, Fulvio Risso, Jokin Garay, Vassilis Foteinos, Panagiotis Demestichas, Giuliana Carullo, Marco Tambasco, Gino Carrozzo |
NetSoft | 2 |
| 2016 | Benefits of Programmable Topological Routing Policies in RINA-Enabled Large-Scale DatacentersabstractWith the proliferation of cloud computing and the expected requirements of future Internet of Things (IoT) and 5G network scenarios, more efficient and scalable Data Centers (DCs) will be required, offering very large pools of computational resources and storage capacity cost-effectively. Looking at todays' commercial DCs, they tend to rely on well-defined leaf-spine Data Center Network (DCN) topologies that not only offer low latency and high bisectional bandwidth, but also enhanced reliability against multiple failures. However, routing and forwarding solutions in such DCNs are typically based on IP, thus suffering from its limited routing scalability. In this work, we quantitatively evaluate the benefits that the Recursive InterNetwork Architecture (RINA) can bring into commercial DCNs. To this goal, we propose rule-based topological routing and forwarding policies tailored to the characteristics of publicly available Google's and Facebook's DCNs. These policies can be programmed in a RINA-enabled environment, enabling fast forwarding decisions in most scenarios with merely neighboring node information. Upon DCN failures, invalid forwarding rules are overwritten by exceptions. Numerical results show that the scalability of our proposal depends on the number of concurrent failures in the DCN rather than its size (e.g., number of nodes/links), dramatically reducing the total amount of routing and forwarding information to be stored at nodes. Furthermore, as routing information is only disseminated upon failures across the DCN, the associated communication cost of our proposals largely outperforms that of the traditional IP-based solutions. Sergio Leon Gaixas, Jordi Perelló, Eduard Grasa, Diego R. López, Pedro A. Aranda-Gutiérrez, Davide Careglio |
GLOBECOM | 4 |
| 2016 | Towards self-adaptive network management for a recursive network architectureabstractTraditionally, network management tasks manually performed by system administrators include monitoring alarms based on collected statistics across many heterogeneous systems, correlating these alarms to identify potential problems or changes to management policies and responding by performing system re-configurations to ensure optimal performance of network services. System administrators have a narrow focus of factors impacting network service provisioning and performance due to the heterogeneity and scale of generated underlying network events. However, self-adaption principles are conceptual approaches for autonomously managing such complex distributed systems. Network management systems that harness such principles can dynamically and autonomously optimise the operation of network services, responding quickly to changes in user requirements and underlying network conditions. In this paper, we present a novel self-adaptive network management framework that takes advantage of a recursive network architecture for a simpler and more comprehensive application of ontologies, semantic web rules and machine learning to automatically adjust network configuration parameters to provide more optimal QoS management of network services. We demonstrate the applicability of the approach using a content distribution network (CDN) operating over such a recursive network architecture. Jason Barron, Micheal Crotty, Ehsan Elahi 0005, Roberto Riggio, Diego R. López, Miguel Ponce de Leon |
NOMS | 5 |
| 2016 | Can machine learning aid in delivering new use cases and scenarios in 5G?abstract5G represents the next generation of communication networks and services, and will bring a new set of use cases and scenarios. These in turn will address a new set of challenges from the network and service management perspective, such as network traffic and resource management, big data management and energy efficiency. Consequently, novel techniques and strategies are required to address these challenges in a smarter way. In this paper, we present the limitations of the current network and service management and describe in detail the challenges that 5G is expected to face from a management perspective. The main contribution of this paper is presenting a set of use cases and scenarios of 5G in which machine learning can aid in addressing their management challenges. It is expected that machine learning can provide a higher and more intelligent level of monitoring and management of networks and applications, improve operational efficiencies and facilitate the requirements of the future 5G network. Teodora Sandra Buda, Haytham Assem, Danny Raz, Udi Margolin, Elisha J. Rosensweig, Diego R. López, Marius Iulian Corici, Mikhail I. Smirnov, Robert Mullins 0002, Olga Uryupina, Alberto Mozo, Bruno Ordozgoiti Rubio, Ángel Martín, Alaa Alloush, Pat O'Sullivan, Imen Grida Ben Yahia |
NOMS | 7 |
| 2015 | An open NFV and cloud architectural framework for managing application virality behaviourabstractOne of the key goals of Network Functions Virtualization (NFV) is achieving energy efficiency through workload consolidation. A good example for maximizing energy savings is the Virtualization of Content Delivery Networks (vCDNs) NFV use case where the video streaming workloads exhibit significant difference between prime-time and non-prime-time usage of the infrastructure. This paper examines the practical challenges in maximizing energy efficiency for vCDN workloads. This paper proposes an open NFV architectural framework for conveying content virality information from Cloud applications such as YouTube, Twitter and mechanisms for leveraging it to maximize the energy efficiency for vCDN workloads. This paper also proposes a more general architecture for any Cloud/NFV application that may experience virality. Dilip Krishnaswamy, Ram Krishnan, Diego R. López, Peter Willis 0001, Asif Qamar |
CCNC | 3 |
| 2015 | Multi-Context TLS (mcTLS): Enabling Secure In-Network Functionality in TLSabstractA significant fraction of Internet traffic is now encrypted and HTTPS will likely be the default in HTTP/2. However, Transport Layer Security (TLS), the standard protocol for encryption in the Internet, assumes that all functionality resides at the endpoints, making it impossible to use in-network services that optimize network resource usage, improve user experience, and protect clients and servers from security threats. Re-introducing in-network functionality into TLS sessions today is done through hacks, often weakening overall security. David Naylor, Kyle Schomp, Matteo Varvello, Ilias Leontiadis, Jeremy Blackburn, Diego R. López, Konstantina Papagiannaki, Pablo Rodriguez 0001, Peter Steenkiste |
SIGCOMM | 6 |
| 2015 | Operational, organizational and business challenges for network operators in the context of SDN and NFV
Luis M. Contreras 0001, Paul Doolan, Håkon Lønsethagen, Diego R. López |
Comput. Networks | 4 |
| 2013 | vRGW: Towards network function virtualization enabled by software defined networkingabstractIt has been a significant challenge for network carriers to deploy and provision a large number of Customer-Premises Equipment (CPE) devices located at subscribers' premises and connected to a carrier's network infrastructure. In this paper, we make a first systematic attempt to fundamentally re-shape the access networks into a software defined networking architecture by virtualizing the network functionality of residential gateways (vRGW). Our approach can be generalized to other CPE such as set-top boxes. Our analysis suggests that vRGW can achieve significant economic benefits ranging from up to 90% reduction on the call center cost and up to 46% reduction on the product return cost. Haiyong Xie 0001, Diego R. López, Tina Tsou, Yonggang Wen 0001 |
ICNP | 4 |
| 2013 | A software defined approach to unified IPv6 transitionabstractThe IPv6 transition has been an ongoing process throughout the world due to the exhaustion of the IPv4 address space. However, this transition leads to costly end-to-end network upgrades and poses new challenges of managing a large number of devices with a variety of transitioning protocols. Recognizing these difficulties, we propose an software defined approach to unifying the deployment of IPv6 in a cost-effective, flexible manner. Our deployment and experiments demonstrate significant benefits of this approach, including low complexity, low cost and high flexibility of adopting different existing transition mechanisms. Wenfeng Xia 0002, Tina Tsou, Diego R. López, Qiong Sun, Felix Lu, Haiyong Xie 0001 |
SIGCOMM | 3 |
| 2013 | Integration of the OAuth and Web Service family security standards
Elena Torroglosa-García, Antonio D. Perez-Morales, Pedro Martinez-Julia, Diego R. López |
Comput. Networks | 4 |
| 2012 | Interoperability in large scale cyber-physical systemsabstractWhile the capability for growing on demand is the design foundation of the new generation of software platforms, physical systems always have limited resources. Therefore, there is a need to optimise the existing infrastructures and evolving them building on interoperability. The optimisation of the infrastructure entails not only addressing the computational and storage capabilities but also the network, its associated intelligence and the exchanged information. Therefore, the interoperability requirement in a large scale cyber-system spans from the lowest layers, interfacing with the physical resources, to the software building blocks, client devices and handled data. In this paper, several initiatives addressing interoperability among cloud IaaS layers, IaaS-PaaS, PaaS-SaaS, Cloud-Network and data are presented. Jesús Bermejo Muñoz, Sebastián García Galán, L. R. Lopez, Rocío Pérez de Prado, J. Enrique Muñoz Expósito, Terje Grimstad, Diego R. López |
ETFA | 7 |
| 2012 | Building Network-aware Composite Services with the GEMBus FrameworkabstractThe GEMBus framework is intended to provide the necessary mechanisms to build federated composite services. Thus, it can constitute a key element in achieving cross-stratum optimization by combining network-layer events with service-layer operation knowledge. Taking advantage of the unique service perspective of the high level network operations we can use the GEMBus framework to compose the services with the network elements in order to build an enhanced and network-aware service. In this paper we give a brief description of the GEMBus architecture and discuss how to use it to build such services. We also evaluate the architecture using a proof-of-concept implementation and discuss the obtained results. Pedro Martinez-Julia, Diego R. López, Antonio F. Skarmeta |
ISPA | 2 |
| 2011 | GEMBus as a Service Oriented Platform for Cloud-Based Composable ServicesabstractCloud computing has become a common technology for provisioning infrastructure services on-demand. Modern Cloud platforms can provide cloud-based applications, software, deployment platforms, or general infrastructure services that may include both computational and storage resources. However existing Cloud provisioning models are based on proprietary solutions and don't allow the combination of services from different providers and/or user legacy application that usually are present in user home organizations or campus networks. This paper introduces GEM Bus (GEANT Multi-domain Bus), a service-oriented middleware platform that allows flexible services composition, and their on-demand provisioning and deployment to create new specialized task-oriented services and applications. GEM Bus is built upon state-of-the-art Enterprise Service Bus (ESB) technologies and extend them with new functionalities that allow dynamic component services deployment, composition and management. The current paper discusses the general case for integration of Service-Oriented Architecture (SOA) principles and technologies with the provision and deployment mechanisms of Cloud-based platforms to support on-demand infrastructure services provisioning. It describes the Composable Services Architecture (CSA) that provides a general framework for GEM Bus services design and operation. The paper also presents the current GEM Bus implementation status and discusses how it can be applied as a general SOA platform for Cloud-based service provisioning. Finally, it discusses the practical use case of the federated network monitoring service that can be used as integration component in creating/building GEM Bus based Cloud infrastructure services. Mary Grammatikou, Constantinos Marinos, Yuri Demchenko, Diego R. López, Krzysztof Dombek, Jordi Jofre |
CloudCom | 4 |
| 2010 | Security Services Lifecycle Management in On-Demand Infrastructure Services ProvisioningabstractModern e-Science and high technology industry require high-performance and complicated network and computer infrastructure to support distributed collaborating groups of researchers and applications that should be provisioned on-demand. The effective use and management of the dynamically provisioned services can be achieved by using the Service Delivery Framework (SDF) proposed by TeleManagement Forum that provides a good basis for defining the whole services life cycle management and supporting infrastructure services. The paper discusses conceptual issues, basic requirements and practical suggestions for provisioning consistent security services as a part of the general e-Science infrastructure provisioning, in particular Grid and Cloud based. The proposed Security Services Lifecycle Management (SSLM) model extends the existing frameworks with additional stages such as “Reservation Session Binding” and “Registration and Synchronisation” that specifically target such security issues as the provisioned resources restoration, upgrade or migration and provide a mechanism for remote executing environment and data protection by binding them to the session context. The paper provides a short overview of the existing standards and technologies and refers to the on-going projects and experience in developing dynamic distributed security services. Yuri Demchenko, Cees T. A. M. de Laat, Diego R. López, Joan Antoni García Espín |
CloudCom | 3 |
| 2008 | Linguistic summarization of network traffic flowsabstractWe address, by means of fuzzy linguistic summaries, two related problems: summarizing network flow statistics and making these statistics human-readable. Two complementary summarization methods are developed. First, a fixed set of protoforms of interest is defined, and the ones with a higher truth value are shown to the user as simple on-line summaries. This first method is suitable for real-time monitoring. Then, an association rules mining process is carried out in order to find hidden relations in flow records. Both approaches are implemented in a tool capable of real-time and off-line processing of network flow records. Experimental results for a number of heterogeneous NetFlow records show the usefulness of linguistic summaries to both network practitioners and users. Federico Montesino-Pouzols, Angel Barriga, Diego R. López, Santiago Sánchez-Solano |
FUZZ-IEEE | 3 |
| 2007 | Extending the Common Services of eduGAIN with a Credential Conversion Service
Gabriel López Millán, Óscar Cánovas Reverte, Diego R. López, Antonio F. Skarmeta |
ESORICS | 3 |
| 2006 | Fuzzy End-to-End Rate Control for Internet Transport ProtocolsabstractEnd-to-end Internet packet dynamics is a complex problem for which models available to date are at best incomplete. A major research problem in Internet transport layer protocols is the development of rate control mechanisms that can cope with the requirements of a growing diversity of technologies, applications and services. This paper describes novel mechanisms for intelligent end-to-end traffic rate control in Internet by means of fuzzy systems. We first outline a fuzzy logic based generalization of TCP (Transport Control Protocol) rate control principles. The design of a fuzzy TCP-like window-based rate controller is then described. A systematic fuzzy systems design methodology is used in order to simulate and implement the system as an experimental tool. A comparative evaluation of simulation and implementation results from the fuzzy rate controller as compared to that of traditional controllers is outlined. Besides being a useful modelling approach, the fuzzy rule based rate controller is shown to outperform other approaches with regards to a number of criteria. Federico Montesino-Pouzols, Diego R. López, Angel Barriga, Santiago Sánchez-Solano |
FUZZ-IEEE | 2 |
| 2006 | AA-RR: working with authentication and authorization infrastructuresabstractThe implementation of an Authentication and Authorization Federated Infrastructure (AAFI) is a solution to the demand for inter-organizational access to networked services, which has been constantly growing over the years. But the integration of these services into the infrastructure is not a trivial process, normally having a high cost for the organization, which has to update applications for working properly with the federated infrastructure. To help in this integration, the authors present Authentication and Authorization Requester Responder (AA-RR), a tool conceived to help in the validation of the interoperability of a certain Authentication and Authorization (AA) component with other(s). Candido Rodriguez, Ajay Daryanani, Diego R. López, Jose M. Macias |
PST | 3 |
| 2001 | The PAPI system: point of access to providers of information
Rodrigo Castro-Rojo, Diego R. López |
Comput. Networks | 2 |
| 1999 | Providing secure mobile access to information servers with temporary certificates
Diego R. López, Marcelo Reina |
Comput. Networks | 1 |
| 1998 | XFVHDL: A Tool for the Synthesis of Fuzzy Logic ControllersabstractA tool for the synthesis of fuzzy controllers is presented in this paper. This tool takes as input the behavioral specification of a controller and generates its VHDL description according to a target architecture. The VHDL code can be synthesized by means of two implementation methodologies, ASIC and FPGA. The main advantages of using this approach are rapid prototyping, and the use of well-known commercial design environments like Synopsys, Mentor Graphics, or Cadence. E. Lago, Carlos Jesús Jiménez-Fernández, Diego R. López, Santiago Sánchez-Solano, Angel Barriga |
DATE | 3 |