VLDB 2026 Research / reviewers in the wild / expert
Marcos A. Simplício Jr.
dblp:79/2420 · also Marcos Antonio Simplicio Junior
· DBLP profile ↗
44ranked-venue papers
12as first author
13since 2021 · last 2026
0000-0001-5227-7165ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 8 · 5 first-authorSecurity and privacy · 8 · 3 first-author · 3 since 2021Systems, architecture and hardware · 7 · 2 since 2021Software engineering, systems software and programming languages · 3Applied, interdisciplinary, general and emerging computing · 2 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 1Theory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SchoCo: Schnorr signature concatenation for extensible tokens
Marco A. Marques, Lucas C. Cardoso, Pedro Henrique Barcha Correia, Charles Miers, Marcos A. Simplício Jr. |
J. Inf. Secur. Appl. | 5 |
| 2025 | Next-Generation SPIFFE/SPIRE Identity Management Systems with Post-Quantum Cryptography AlgorithmsabstractQuantum transition reached a new level of importance since NIST standardized post-quantum cryptographic algorithms in late 2024. Consequently, several studies addressed the required changes in existing technologies and systems embracing post-quantum algorithms to face an imminent quantum threat. Cloud-based environments are no different, especially when assuring correct authentication and authorization. We address the usage of post-quantum primitives embedded in identitymanagement systems, a crucial entity inside distributed systems. Our proposal is based on SPIFFE / SPIRE, an open-source framework for secure identity production, integrating postquantum and classical primitives in a hybrid manner. Moreover, we discuss using X.509 certificates as part of our infrastructure and their performance, combining different digital signature algorithms. Lucas C. Cardoso, Marco A. Marques, Pedro Henrique Barcha Correia, Henrique Zanela Cochak, Charles Miers, Marcos A. Simplício Jr. |
CCGrid | 6 |
| 2025 | Container Orchestration Impact on SPIFFE Identity Artifacts: A Performance Analysis of Docker vs KubernetesabstractContainer orchestration platforms are essential for deploying microservices, yet their impact on security-intensive workloads remains largely misunderstood. This work presents a systematic performance comparison of SPIFFE-based identity artifacts across Docker Compose and Kubernetes, evaluating four identity modes through fine-grained instrumentation of token minting and validation operations. Our results reveal orchestration overhead depends critically on connection management: operations employing connection pooling exhibit minimal overhead (0.8-4.9 %), while repeated connection establishment incurs substantial penalties (up to 26.6%). Kubernetes demonstrates 2-10x higher performance variability than Docker Compose, indicating platform selection affects predictability beyond mean latency. These findings, obtained using minimal Container Network Interface (CNI) configuration, represent a conservative baseline for production deployments and provide empirical guidance for platform selection and security architecture design. Henrique Zanela Cochak, Charles Miers, Marco A. Marques, Marcos A. Simplício Jr. |
CloudCom | 4 |
| 2025 | Between Generation and Judgment: A Cloud-Native Framework for Adversarial Evaluation of LLM AlignmentabstractWe present a cloud-native, end-to-end pipeline that unifies automated attack generation with a modular LLM-as-a-Judge, supports static/adaptive corpora across open and proprietary models, enables calibrated multi-judge consensus, and emits audit-ready cost/latency telemetry-addressing gaps from non-cloud-native scripts, decoupled attack/judgment, and single-judge bias. Evaluated under two budgets (MAX_PROMPTS$=10,32)$on three targets-Llama 3.3 70B Instruct, Mix-tral$8\times 7\mathrm{B}$Instruct, DeepSeek-V3-ASR spans 0-37.5% (10) and 0-26.6% (32); judge accuracy ranges from 92.93% (open Llama 3.3 70B Instruct) to 98.94% (proprietary GPT-4o); mean judgment latency is 1.2-5.6 s$\text { (GPT-4o DeepSeek-V3) }$; and unit cost is $0.10-$2.18 per lk adjudications$(\text{Mixtral}8\times 7\mathrm{B} \rightarrow \text{GPT}-40)$. These results motivate a tiered policy-lightweight open-family judges for high-throughput triage and cross-family/ensemble judges for low-confidence cases-offering a practical blueprint for continuous, auditable adversarial eval-uation of LLM alignment at cloud scale. Diego E. G. C. de Oliveira, Charles Miers, Marcos A. Simplício Jr., Victor Takashi Hayashi |
CloudCom | 3 |
| 2025 | Incompleteness in Number-Theoretic Transforms: New Tradeoffs and Faster Lattice-Based Cryptographic ApplicationsabstractLattices are the basis of most NIST-recommended post-quantum cryptography (PQC) schemes, required to thwart the threat posed by the eventual construction of large-scale quantum computers. At the same time, lattices enable more advanced cryptographic constructions, such as fully homomorphic encryption (FHE), which is increasingly used for privacy-preserving applications like machine learning. This work delves into the efficiency and trade-off assessment of polynomial multiplication algorithms and their applications to PQC, FHE, and other schemes. Such algorithms are at the core of lattice-based cryptography and may become a critical bottleneck when deploying PQC-and FHE-based solutions on resource-constrained devices. We propose a formal analysis of so-called incompleteness in the Number Theoretic Transform (NTT). Although this concept is not new, our systematization shows how to optimize polynomial multiplication in quotient rings, considering factors such as the degree of incompleteness, the associated prime moduli, constraints of the target platform, and target security level. Besides efficiency, we formally show that the systematized family of incomplete NTT variants supports a larger set of prime moduli. This property enables new trade-offs for algorithms like the FIPS-approved module-lattice-based key encapsulation mechanism (ML-KEM) and faster amortized bootstrapping in FHE schemes. Our results include shorter ciphertexts in ML-KEM with only a modest hit in performance and a 6 – 42% performance boost in the NTT computation of a state-of-the-art FHE solution. Syed Mahbub Hafiz, Bahattin Yildiz, Marcos A. Simplício Jr., Thales B. Paiva, Henrique S. Ogawa, Gabrielle De Micheli, Eduardo Lopes Cominetti |
EuroS&P | 3 |
| 2025 | Testing the limits of SPDM: Authentication of intermittently connected devices
Renan C. A. Alves, Otávio F. Freitas, Bruno de Carvalho Albertini, Marcos A. Simplício Jr. |
Comput. Secur. | 4 |
| 2024 | DVID: Adding Delegated Authentication to SPIFFE Trusted Domains
Andrew Jessup, Henrique Zanela Cochak, Guilherme P. Koslovski, Maurício Aronne Pillon, Charles Miers, Pedro Henrique Barcha Correia, Marco A. Marques, Marcos A. Simplício Jr. |
AINA (4) | 8 |
| 2024 | Enhancing SPIFFE/SPIRE Environment with a Nested Security Token Model
Henrique Zanela Cochak, Milton P. Pagliuso Neto, Charles Miers, Marco A. Marques, Marcos A. Simplício Jr. |
CLOSER | 5 |
| 2024 | Lightweight SPIFFE Verifiable Identity Document (LSVID): A Nested Token Approach for Enhanced Security and Flexibility in SPIFFEabstractService identities are crucial for authentication and access control, ensuring that only authorized services access specific resources. The SPIFFE framework addresses workload identity management and authentication effectively but needs support for solutions (e.g., extensible tokens) that fine-granular authorization mechanisms in distributed scenarios can use. In this context, we present the Lightweight SVID (LSVID), an identity document in JSON format that can be extended and used as a token. As an extensible token, Lightweight SVID (LSVID) enables features such as delegation, attenuation, and traceability, enhancing its flexibility and applicability. Our approach provides efficient handling of token extensions and validations, demonstrated through a proof-of-concept implemented in Go. Baseline results indicate that LSVID critical operations are efficient, with processing times in the microsecond range, offering significant functional advantages over the traditional JWT-SVIDs, one of two key security documents from SPIFFE. Henrique Zanela Cochak, Charles Miers, Pedro Henrique Barcha Correia, Marco A. Marques, Marcos A. Simplício Jr. |
CloudCom | 5 |
| 2023 | Performance analysis of the Raft consensus algorithm on Hyperledger Fabric and Ethereum on cloudabstractThe use of private or consortium blockchains in organizations’ applications is growing. A relevant aspect of blockchains is the choice of consensus mechanism. This decision delimits which blockchain solutions are suitable for the private scenario. Once the consensus mechanism is chosen, more than one blockchain may be enabled. However, this decision making is not trivial and requires detailed experimental indicators about algorithms and blockchains performance. In this context, we provide a comprehensive performance analysis of the Raft consensus mechanism based on its implementation in Hyperledger Fabric and Ethereum blockchain solutions. We performed our experiments on an OpenStack private cloud using each blockchain developer’s default settings for virtual machines. Our findings show how the implementation of each solution can impact the application’s performance under certain conditions. Joao Henrique Faes Battisti, Vitor E. Batista, Guilherme P. Koslovski, Maurício Aronne Pillon, Charles Miers, Marco A. Marques, Marcos A. Simplício Jr., Diego Kreutz |
CloudCom | 7 |
| 2021 | Container Allocation and Deallocation Traceability using Docker Swarm with Consortium Hyperledger Blockchain
Marco A. Marques, Charles Miers, Marcos A. Simplício Jr. |
CLOSER | 3 |
| 2021 | Schnorr-Based Implicit Certification: Improving the Security and Efficiency of Vehicular CommunicationsabstractIn the implicit certification model, the process of verifying the validity of the signer's public key is combined with the verification of the signature itself. When compared to traditional, explicit certificates, the main advantage of the implicit approach lies in the shorter public key validation data. This property is particularly important in resource-constrained scenarios where public key validation is performed very often, which is common in vehicular communications (V2X) that employ pseudonym certificates. In this article, we show an alternative Schnorr-based implicit certification procedure that can improve the efficiency of a popular V2X-oriented Vehicular Public Key Infrastructure (VPKI), the Security Credential Management System (SCMS). As an additional contribution, we show that SCMS's underlying certificate provisioning procedure, based on butterfly keys, is vulnerable to existential forgery attacks under certain conditions. We then discuss how this issue can be fixed in an effective and efficient manner. Paulo S. L. M. Barreto, Marcos A. Simplício Jr., Jefferson E. Ricardini, Harsh Kupwade Patil |
IEEE Trans. Computers | 2 |
| 2021 | Privacy-Preserving Certificate Linkage/Revocation in VANETs Without Linkage AuthoritiesabstractVehicular communication (V2X) technologies are expected to become common in the future, providing better efficiency and safety in transportation. This envisioned large-scale deployment, however, critically depends on addressing some issues. In special, to prevent abuse by drivers, messages exchanged among authorized vehicles must be authenticated. This implies the need of a Vehicular Public Key Infrastructure (VPKI). Unlike traditional PKIs, though, VPKIs are also expected to preserve the privacy of honest drivers, preventing their vehicles from being easily identified or tracked. One promising VPKI solution, which copes with such requirements and is among the main candidates for standardization in the United States, is the Security Credential Management System (SCMS). In this paper, aiming to enhance and address shortcomings identified in SCMS, we provide two main contributions. First, we describe and fix two birthday attacks against SCMS's certificate revocation process, thus improving the system's long-term privacy. Second, we propose a method that simplifies SCMS's architecture, removing the need for Linkage Authorities (LAs); this approach cuts down deployment costs while reducing the system's attack surface, in particular against some troublesome forms of replay attacks that are hereby unveiled. Marcos A. Simplício Jr., Eduardo Lopes Cominetti, Harsh Kupwade Patil, Jefferson E. Ricardini, Leonardo T. D. Ferraz, Marcos Vinicius Maciel da Silva |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2020 | Fast Additive Partially Homomorphic Encryption From the Approximate Common Divisor ProblemabstractThis paper presents two efficient partially homomorphic encryption schemes built upon the approximate common divisor problem, believed to be resistant to quantum computer attacks. Both proposals, named FAHE1 and FAHE2, are additively homomorphic and have a symmetric nature, meaning that they are useful in scenarios where encryption and decryption are performed by the same entity. This is the case, for example, of encrypted databases stored in a public cloud. We also evaluate the performance of our proposals in comparison with two alternatives displaying additive homomorphism: the traditional Paillier asymmetric cryptosystem, which is not quantum-resistant; and the XPIR algorithm, which is both quantum-resistant and symmetric. Our experimental results show that both solutions provide considerable speed-ups when compared to Paillier. Namely, encryption and decryption with FAHE1 are, respectively, 120 and 25 times faster than Paillier's, while for FAHE2 both operations run more than 1000 times faster. In addition, when compared with a highly optimized XPIR code, our reference implementation remains quite competitive while producing smaller ciphertexts. Eduardo Lopes Cominetti, Marcos A. Simplício Jr. |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2019 | ACPC: Efficient revocation of pseudonym certificates using activation codesabstractVehicular communication (V2X) technologies allow vehicles to exchange information about the road conditions and their own status, and thereby enhance transportation safety and efficiency. For broader deployment, however, such technologies are expected to address security and privacy concerns, preventing abuse by users and by the system’s entities. In particular, the system is expected to enable the revocation of malicious vehicles, e.g., in case they send invalid information to their peers or to the roadside infrastructure; it should also prevent the system from being misused for tracking honest vehicles. Both features are enabled by Vehicular Public Key Infrastructure (VPKI) solutions such as Security Credential Management Systems (SCMS), one of the leading candidates for protecting V2X communication in the United States. Unfortunately, though, SCMS’s original revocation mechanism can lead to large Certification Revocation Lists (CRLs), which in turn impacts the bandwidth usage and processing overhead of the system. In this article, we propose a novel design called Activation Codes for Pseudonym Certificates (ACPC), which can be integrated into SCMS to address this issue. Our proposal is based on activation codes, short bit-strings without which certificates previously issued to a vehicle cannot be used by the latter, which are periodically distributed to non-revoked vehicles using an efficient broadcast mechanism. As a result, the identifiers of the corresponding certificates do no need to remain on the CRL for a long time, reducing the CRLs’ size and streamlining their distribution and verification of any vehicle’s revocation status. Besides describing ACPC in detail, we also compare it to similar-purpose solutions such as Issue First Activate Later (IFAL) and Binary Hash Tree based Certificate Access Management (BCAM). This analysis shows that our proposal not only improves privacy (e.g., in terms of resilience against colluding system authorities), but also leads to processing and bandwidth overheads that are orders of magnitude smaller than those observed in the state of the art. Marcos A. Simplício Jr., Eduardo Lopes Cominetti, Harsh Kupwade Patil, Jefferson E. Ricardini, Marcos Vinicius Maciel da Silva |
Ad Hoc Networks | 1 |
| 2019 | Faster Key Compression for Isogeny-Based CryptosystemsabstractSupersingular isogeny-based cryptography is one of the more recent families of post-quantum proposals. An interesting feature is the comparatively low bandwidth occupation in key agreement protocols, which stems from the possibility of key compression. However, compression and decompression introduce a significant overhead to the overall processing cost despite recent progress. In this paper we address the main processing bottlenecks involved in key compression and decompression, and suggest substantial improvements for each of them. Some of our techniques may have an independent interest for other, more conventional areas of elliptic curve cryptography as well. Gustavo H. M. Zanon, Marcos A. Simplício Jr., Geovandro C. C. F. Pereira, Javad Doliskani, Paulo S. L. M. Barreto |
IEEE Trans. Computers | 2 |
| 2018 | Using Externals IdPs on OpenStack: A Security Analysis of OpenID Connect, Facebook Connect, and OpenStack AuthenticationabstractThe installation and configuration of cloud environments has increasingly become automated and therefore simple. For instance, solutions such as RedHat RDO and Mirantis Fuel facilitate the deployment of popular computational clouds like OpenStack. Despite the advances in usability, effort is still required to create and manage multiple users. This is of particular relevance when dealing with sensitive information, a somewhat common case for private clouds. To alleviate this burden, many clouds have adopted federated Single Sign-On (SSO) mechanisms for authenticating their users in a more transparent manner. In this work we analyze the practical security of an OpenStack IaaS cloud when combined with either OpenID Connect (using Google as IdP) or Facebook Connect (using Facebook as IdP). The criteria used in the analysis comprise the ability to provide data encryption, the risks involved in the use of an external IdP, and improper access control. We identify potential issues regarding these solutions and we propose approaches to fix them. Glauber Cassiano Batista, Charles Miers, Guilherme P. Koslovski, Maurício Aronne Pillon, Nelson Mimura Gonzalez, Marcos A. Simplício Jr. |
AINA | 6 |
| 2018 | A Taxonomy Model for Single Sign-on Oriented towards Cloud Computing
Glauber Cassiano Batista, Maurício Aronne Pillon, Guilherme P. Koslovski, Charles Miers, Marcos A. Simplício Jr., Nelson Mimura Gonzalez |
CLOSER | 5 |
| 2018 | Multi-tenant Isolation of What?: Building a Secure Tenant Isolation Architecture for Cloud NetworksabstractMany security challenges arise when mutually untrusted tenants are co-located in the same virtualized network infrastructure. Cloud systems commonly employ different network isolation mechanisms to prevent interferences among tenants' networks, which may rely on different and complementary isolation strategies. In this work, we define three complementary strategies for addressing multi-tenant isolation in cloud networks, observe that no current virtualization architecture implements all the three strategies, and propose a novel architectural design to cover the identified gap. Bruno Medeiros, Marcos A. Simplício Jr., Ewerton R. Andrade |
SoCC | 2 |
| 2018 | Faster Isogeny-Based Compressed Key Agreement
Gustavo H. M. Zanon, Marcos A. Simplício Jr., Geovandro C. C. F. Pereira, Javad Doliskani, Paulo S. L. M. Barreto |
PQCrypto | 2 |
| 2017 | A Framework for Enabling Security Services Collaboration Across Multiple DomainsabstractCollaboration among Security Service Functions (SSF) is expected to become as essential to SECaaS (SECurity as a Service) systems as elasticity is to IaaS (Infrastructure as a Service). The virtualization opens new era in network security as new security appliances can be created on demand in appropriate places in the network. At the same time, the increasing size and diversity of attacks make it necessary to come up with new approaches for more efficient and more resilient security mechanisms. In this paper, we propose a new framework leveraging SDN (Software Defined Networking) and SFC (Service Function Chaining) to enhance the collaboration among different SSFs to mitigate large scale attacks. We describe a framework that allows SSFs from different domains to negotiate and dynamically control the amount of resources allocated for collaboration, in what we call a "best-effort" collaboration mode. This SSF collaboration framework creates a distributed mitigation system for handling large scale attacks in a dynamic and scalable manner. The efficiency and feasibility of this framework is experimentally assessed, showing that our approach incurs low overhead, increases the amount of traffic treated by SSFs and reduces the dropped traffic due to the lack of resources from the security mechanisms. Daniel Migault, Marcos A. Simplício Jr., Bruno M. Barros, Makan Pourzandi, Thiago R. M. Almeida, Ewerton R. Andrade, Tereza Cristina M. B. Carvalho |
ICDCS | 2 |
| 2017 | Lightweight and escrow-less authenticated key agreement for the internet of things
Marcos A. Simplício Jr., Marcos Vinicius Maciel da Silva, Renan C. A. Alves, Tiago K. C. Shibata |
Comput. Commun. | 1 |
| 2016 | Lyra2: Efficient Password Hashing with High Security against Time-Memory Trade-OffsabstractWe present Lyra2, a password hashing scheme (PHS) based on cryptographic sponges. Lyra2 was designed to be strictly sequential for a given number of cores (i.e., not easily parallelizable beyond that number), providing strong security even against attackers using custom hardware or GPUs. At the same time, it is very simple to implement in software and allows legitimate users to fine tune its memory and processing costs according to the desired level of security against brute force password-guessing. Lyra2 is an improvement of the recently proposed Lyra algorithm, providing an even higher security level against different attack venues and overcoming some limitations of this and other existing schemes. Ewerton R. Andrade, Marcos A. Simplício Jr., Paulo S. L. M. Barreto, Paulo C. F. dos Santos |
IEEE Trans. Computers | 2 |
| 2015 | Classifying Security Threats in Cloud NetworkingabstractA central component of managing risks in cloud computing is to understand the nature of security threats. The relevance of security concerns are evidenced by the efforts from both the academic community and technological organizations such as NIST, ENISA and CSA, to investigate security threats and vulnerabilities related to cloud systems. Provisioning secure virtual networks (SVNs) in a multi-tenant environment is a fundamental aspect to ensure trust in public cloud systems and to encourage their adoption. However, comparing existing SVN-oriented solutions is a difficult task due to the lack of studies summarizing the main concerns of network virtualization and providing a comprehensive list of threats those solutions should cover. To address this issue, this paper presents a threat classification for cloud networking, describing threat categories and attack scenarios that should be taken into account when designing, comparing, or categorizing solutions. The classification is based o n the CSA threat report, building upon studies and surveys from the specialized literature to extend the CSA list of threats and to allow a more detailed analysis of cloud network virtualization issues. Bruno M. Barros, Leonardo H. Iwaya, Marcos A. Simplício Jr., Tereza Cristina M. B. Carvalho, András Méhes, Mats Näslund |
CLOSER | 3 |
| 2015 | OCP: A protocol for secure communication in federated content networksabstractContent Distribution Networks (CDNs) are networks that make intense use of caching and multicast overlay techniques for transmitting video and other stream media, a type of traffic that has been growing tremendously in the last years. To cope with this increasing demand, several telecommunications companies have been associated to create federated CDNs (FCDNs), that involves many different providers and, hence, distinct domains. Although beneficial in terms of increased capillarity and scalability of service delivery, the interaction between FCDN elements from different providers brings many new challenges. Among them, one that has received little attention so far refers to security, an essential service for preventing the misuse of the FCDN resources. Aiming to tackle this issue, this paper presents the Overlay Communication Protocol (OCP), a security mechanism that allows the secure signaling communication in FCDNs. OCP takes into account all elements involved in the content delivery process, addressing Route Forgery attacks and concealing the network structure from potential attackers. Together with the protocol description and security analysis, we also present experimental results on its implementation, showing that it introduces little impact on the overall network performance. Hélcio M. Pimentel, Samuel Kopp, Marcos A. Simplício Jr., Regina Melo Silveira, Graça Bressan |
Comput. Commun. | 3 |
| 2015 | SecourHealth: A Delay-Tolerant Security Framework for Mobile Health Data CollectionabstractSecurity is one of the most imperative requirements for the success of systems that deal with highly sensitive data, such as medical information. However, many existing mobile health solutions focused on collecting patients' data at their homes that do not include security among their main requirements. Aiming to tackle this issue, this paper presents SecourHealth, a lightweight security framework focused on highly sensitive data collection applications. SecourHealth provides many security services for both stored and in-transit data, displaying interesting features such as tolerance to lack of connectivity (a common issue when promoting health in remote locations) and the ability to protect data even if the device is lost/stolen or shared by different data collection agents. Together with the system's description and analysis, we also show how SecourHealth can be integrated into a real data collection solution currently deployed in the city of Sao Paulo, Brazil. Marcos A. Simplício Jr., Leonardo H. Iwaya, Bruno M. Barros, Tereza Cristina M. B. Carvalho, Mats Näslund |
IEEE J. Biomed. Health Informatics | 1 |
| 2014 | SecureTCG: a lightweight cheating-detection protocol for P2P multiplayer online trading card gamesabstractABSTRACT Online gaming is today a very lucrative market, with millions of users all around the globe. At the same time, the increasing popularity and complexity of such games implies the need of deploying cheating‐detection mechanisms for ensuring the continuous interest of honest users in playing. The development of secure and efficient solutions for online games is, however, a challenging issue. This is especially true in P2P environments, in which the lack of a central trusted entity monitoring the game greatly facilitates the activity of malicious players. Aiming to tackle this issue, this paper presents SecureTCG, a protocol for detecting cheating attempts in P2P multiplayer card games where the players use their own decks to play, such as the so‐called trading card games. In summary, SecureTCG allows the multiple players participating in a trading card game match to detect cheating attempts as soon as they are made and without the intervention of third parties, supports multiple players and different game styles, displays tolerance to players’ dropouts during a match, prevents collusion among any number of players, provides (optional) after‐match auditability mechanisms, and has a reduced computational cost. Copyright © 2014 John Wiley & Sons, Ltd. Marcos A. Simplício Jr., Mateus A. S. Santos, Rodrigo R. Leal, Marco A. L. Gomes, Walter Akio Goya |
Secur. Commun. Networks | 1 |
| 2013 | Survey and comparison of message authentication solutions on wireless sensor networks
Marcos A. Simplício Jr., Bruno Trevizan de Oliveira, Cíntia B. Margi, Paulo S. L. M. Barreto, Tereza Cristina M. B. Carvalho, Mats Näslund |
Ad Hoc Networks | 1 |
| 2013 | SMSCrypto: A lightweight cryptographic framework for secure SMS transmission
Geovandro C. C. F. Pereira, Mateus A. S. Santos, Bruno Trevizan de Oliveira, Marcos A. Simplício Jr., Paulo S. L. M. Barreto, Cíntia B. Margi, Wilson Vicente Ruggiero |
J. Syst. Softw. | 4 |
| 2012 | Flow-based Programming as a Solution for Cloud Computing Requirements
Marcel R. Barros, Charles Miers, Marcos A. Simplício Jr., Tereza Cristina M. B. Carvalho, Jan-Erik Mångs, Bob Melander, Victor Souza |
ICORES | 3 |
| 2012 | Revisiting the Security of the ALRED Design and Two of Its Variants: Marvin and LetterSoupabstractThe Alred construction is a lightweight strategy for constructing message authentication algorithms from an underlying iterated block cipher. Even though this construction's original analyses show that it is secure against some attacks, the absence of formal security proofs in a strong security model still brings uncertainty on its robustness. In this paper, aiming to give a better understanding of the security level provided by different authentication algorithms based on this design strategy, we formally analyze two Alred variants—the Marvin message authentication code and the LetterSoup authenticated-encryption scheme,—bounding their security as a function of the attacker's resources and of the underlying cipher's characteristics. Marcos A. Simplício Jr., Paulo S. L. M. Barreto |
IEEE Trans. Inf. Theory | 1 |
| 2011 | A Taxonomy Model for Cloud Computing Services
Nelson Mimura Gonzalez, Charles Miers, Fernando F. Redígolo, Marcos A. Simplício Jr., Tereza Cristina M. B. Carvalho, Mats Näslund, Makan Pourzandi |
CLOSER | 4 |
| 2011 | A Quantitative Analysis of Current Security Concerns and Solutions for Cloud ComputingabstractThe development of cloud computing services is speeding up the rate in which the organizations outsource their computational services or sell their idle computational resources. Even though migrating to the cloud remains a tempting trend from a financial perspective, there are several other aspects that must be taken into account by companies before they decide to do so. One of the most important aspect refers to security: while some cloud computing security issues are inherited from the solutions adopted to create such services, many new security questions that are particular to these solutions also arise, including those related to how the services are organized and which kind of service/data can be placed in the cloud. Aiming to give a better understanding of this complex scenario, in this article we identify and classify the main security concerns and solutions in cloud computing, and propose a taxonomy of security in cloud computing, giving an overview of the current status of security in this emerging technology. Nelson Mimura Gonzalez, Charles Miers, Fernando F. Redígolo, Tereza Cristina M. B. Carvalho, Marcos A. Simplício Jr., Mats Näslund, Makan Pourzandi |
CloudCom | 5 |
| 2011 | Comparison of Authenticated-Encryption schemes in Wireless Sensor NetworksabstractSecurity is an important concern in any modern network. This also applies to Wireless Sensor Networks (WSNs), especially those used in applications that monitor sensitive information (e.g., health care applications). However, the highly constrained nature of sensors impose a difficult challenge: their reduced availability of memory, processing power and energy hinders the deployment of many modern cryptographic algorithms considered secure. For this reason, the choice of the most memory-, processing- and energy-efficient security solutions is of vital importance in WSNs. To date, several authors have developed extensive analyses comparing different encryption algorithms and key management schemes, while very little attention has been given to message authentication mechanisms. In this paper, we address this issues by identifying Authenticated Encryption with Associated Data (AEAD) schemes suitable for WSNs and by evaluating their features and performance on TelosB sensor nodes. As a result of this analysis, we identify the recommended choices depending on the characteristics of the target network. Marcos A. Simplício Jr., Bruno Trevizan de Oliveira, Paulo S. L. M. Barreto, Cíntia B. Margi, Tereza Cristina M. B. Carvalho, Mats Näslund |
LCN | 1 |
| 2011 | EbitSim: An Enhanced BitTorrent Simulation Using OMNeT++ 4abstractThe BitTorrent protocol is one of the most successful P2P applications, being largely studied by the research community. Nevertheless, studying the dynamics of a large BitTorrent network presents several challenges, such as difficulty in acquiring network traces or building measurement experiments. Evaluation through simulation is usually utilized for studying BitTorrent networks, yet only a few BitTorrent simulation models are available for the research community. In this article, we present an extensible framework for developing BitTorrent simulations, focusing on realism and without losing on scalability. We developed an accurate version of the protocol by analyzing the source code of mainstream BitTorrent clients and by discussing directly with their developers. The simulation model was developed with the OMNeT++ Framework, inheriting its high extensibility, and with the INET Framework, for accuracy of the underlying network model. We also took into account the effects of multitasking in our model, since BitTorrent applications acquires content from several sources simultaneously, and utilized real world traces for modeling the processing times. We present an analysis of our simulator regarding performance aspects and BitTorrent-related results. Pedro Evangelista, Marcelo Amaral, Charles Miers, Walter Akio Goya, Marcos A. Simplício Jr., Tereza Cristina M. B. Carvalho, Victor Souza |
MASCOTS | 5 |
| 2011 | One-time signature scheme from syndrome decoding over generic error-correcting codes
Paulo S. L. M. Barreto, Rafael Misoczki, Marcos A. Simplício Jr. |
J. Syst. Softw. | 3 |
| 2011 | A family of implementation-friendly BN elliptic curves
Geovandro C. C. F. Pereira, Marcos A. Simplício Jr., Michael Naehrig, Paulo S. L. M. Barreto |
J. Syst. Softw. | 2 |
| 2010 | An architecture for P2P locality in managed networks using hierarchical trackersabstractPeer-to-peer (P2P) networks have in the past years become a very attractive method for delivery of media content over the Internet. Many factors have contributed to this success, but the low delivery costs and the inherent scalability of the P2P networks whereby consumers of content are also potential sources are among the most prominent ones. However, the effectiveness and performance of many popular P2P networks (such as BitTorrent based ones) is highly dependent on how well trackers select peers that will provide a content. The peers chosen by a tracker will directly affect the user-perceived performance of the service and the usage of network resources. Moreover, P2P networks have usually no locality awareness, resulting in sub-optimal utilization of network resources. In order to address these issues, we propose a novel hierarchical architecture for P2P locality targeted at managed P2P networks based on the BitTorrent protocol. We then show, through experimentation, that the adoption of the proposed architecture leads to significant network efficiency improvements without compromising end-user experience. Charles Miers, Marcos A. Simplício Jr., Walter Akio Goya, Tereza Cristina M. B. Carvalho, Victor Souza |
CNSM | 2 |
| 2010 | Impact of Operating Systems on Wireless Sensor Networks (Security) Applications and TestbedsabstractWireless Sensor Networks (WSNs) are a valuable technology to support countless applications in different areas. Given the WSN nodes resource constrained characteristics, designing energy-aware applications, communication protocols and security mechanisms are critical. The operating system (OS) running on the WSN node also interferes with the node overall behavior, and its energy consumption. In this paper, we develop a comparison between two different operating systems (Contiki and TinyOS) running on the same hardware platform (Crossbow TelosB). Using a set of tasks, which includes sensing, communication and security mechanisms, we evaluate their behavior in terms of energy consumption and execution time. Cíntia B. Margi, Bruno Trevizan de Oliveira, Gustavo T. de Sousa, Marcos A. Simplício Jr., Paulo S. L. M. Barreto, Tereza Cristina M. B. Carvalho, Mats Näslund, Richard Gold |
ICCCN | 4 |
| 2010 | Revisiting the Security of the Alred Design
Marcos A. Simplício Jr., Paulo S. L. M. Barreto, Tereza Cristina M. B. Carvalho |
ISC | 1 |
| 2010 | Implementation of data survival in unattended Wireless Sensor Networks using cryptographyabstractSecurity in Wireless Sensor Networks (WSNs) is highly dependent on the behavior of the base station. This happens because, if the network is left unattended, sensor nodes cannot offload data to the (secure) base station in real time and, thus, until the base station becomes available, adversaries can compromise some sensor nodes and selectively destroy data. In order to prevent such attacks, providing the so-called “data survival”, some strategies can be employed. In this paper, we discuss and analyze different data survival strategies using cryptography. To the best of our knowledge, we provide the first implementation of such techniques, using a real sensor platform for their evaluation. As a result, we show that the main costs for the data survival process are not as high as it could be expected, and that strategies based on private keys can be used even if one considers the highly resource constrained nature of sensors. Mateus A. S. Santos, Cíntia B. Margi, Marcos A. Simplício Jr., Geovandro C. C. F. Pereira, Bruno Trevizan de Oliveira |
LCN | 3 |
| 2010 | A survey on key management mechanisms for distributed Wireless Sensor Networks
Marcos A. Simplício Jr., Paulo S. L. M. Barreto, Cíntia B. Margi, Tereza Cristina M. B. Carvalho |
Comput. Networks | 1 |
| 2009 | PHDabstractAs TV consumers expect a growing quantity and quality of services provided to them, and providers fear uncontrolled distribution of the digital content, one of the more promising theoretical proposals to balance these two needs are the so-called "Authorized Domains" (AD). We present in this paper a novel architecture that builds on the AD concept, but extends it to allow for a more generic, open, and flexible solution. The contributions of our work are twofold: First, we analyze and motivate which features a generic and flexible IPTV architecture should exhibit in order to enable various business models, while maintaining in all instances the above-mentioned core features. Second, we present our architecture – “Personal Home Domains” (PHD) –, which adds some key features to the original AD: it allows offline content in addition to streaming; it harmonizes the distribution inside the domain with (new) the delivery from service provider to the domain; it allows for the distribution of free or age-protected content; it emphasizes the mobility of users more than the original concept; and it allows for non-compliant devices inside the domain devices as well. Marcos A. Simplício Jr., Vlad C. Coroama, Yeda Regina Venturini, Tereza Cristina M. B. Carvalho, Mats Näslund, Makan Pourzandi |
AINA | 1 |
| 2009 | The MARVIN message authentication code and the LETTERSOUP authenticated encryption schemeabstractAbstract We present MARVIN, a new parallelizable message authentication code (MAC) based on the ALRED family. The new algorithm is designed with resource‐constrained platforms inmind and explores the structure of an underlying block cipher toprovide security at a small cost in terms of memory needs. Also,we show how MARVIN can be used as an authentication‐onlyfunction or else in an authenticated encryption with associateddata (AEAD) scheme. We define a new AEAD proposal called LETTERSOUP, which is based on the mode ofoperation. Finally, we LFSRC analyze the security and performance of theresulting schemes. Copyright © 2008 John Wiley & Sons, Ltd. Marcos A. Simplício Jr., Pedro d'Aquino F. F. S. Barbuda, Paulo S. L. M. Barreto, Tereza Cristina M. B. Carvalho, Cíntia B. Margi |
Secur. Commun. Networks | 1 |