VLDB 2026 Research / reviewers in the wild / expert
Sihem Guemara El Fatmi
dblp:83/6057 · also Sihem Guemara-ElFatmi
· DBLP profile ↗
31ranked-venue papers
1as first author
6since 2021 · last 2022
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 15 · 2 since 2021Computer networks · 6 · 1 first-authorHuman-computer interaction and ubiquitous computing · 3Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | Ensuring Data Integrity Using Digital Signature in an IoT Environment
Nadia Kammoun, Aida Ben Chehida Douss, Ryma Abassi, Sihem Guemara El Fatmi |
AINA (3) | 4 |
| 2021 | Formal Validation of a Security Mechanism against the RSU Compromise Attack
Ons Chikhaoui, Ryma Abassi, Aida Ben Chehida Douss, Sihem Guemara El Fatmi |
ARES | 4 |
| 2021 | Formal Validation of Credibility and Accuracy Assessment of Safety Messages in VANETsabstractIn Vehicular Ad hoc NETworks (VANETs), vehicles exchange safety messages containing valuable information about traffic environment to increase roads’ safety. The critical nature of these messages entails securing them before considering them. In this context, the credibility and the accuracy assessment of these included safety information arises as a necessity since the consumption of false or imprecise ones by vehicles may cause hazardous consequences. To treat this requirement, we proposed the scheme [1] enabling vehicles to evaluate the credibility and the accuracy of the contents of the safety messages exchanged in VANETs. That scheme is based on three modules: a reputation module, a time and location closeness estimation module, and a majority module. A vehicle can use these modules in a separated or joint way according to the circumstances. Since that scheme is error prone, we conducted in [2], a formal validation, using inference system, to prove the soundness and the completeness of these three modules and their combination. In this paper, we complete that formal validation of [1] by handling the junctions of the three basic modules two by two. To do this, we first completed the inference system in [2] so that the junctions of the three modules two by two become incorporated. A formal verification using this holistic inference system was proposed in a second step to prove the soundness and the completeness of these junctions. This verification's obtained results confirmed the validity of the said junctions for being sound and complete. Ons Chikhaoui, Aida Ben Chehida Douss, Ryma Abassi, Sihem Guemara El Fatmi |
ARES | 4 |
| 2021 | A Lightweight Authentication Scheme for SDN-Based Architecture in IoT
Nadia Kammoun, Ryma Abassi, Sihem Guemara El Fatmi, Mohamed Mosbah 0001 |
AINA (3) | 3 |
| 2021 | Towards the Performance Evaluation of a Trust Based Routing Protocol for VANET
Amira Kchaou, Ryma Abassi, Sihem Guemara El Fatmi |
AINA (1) | 3 |
| 2021 | A Distributed Resource Management for VANET using Smart ContractabstractRecently, the Vehicular Ad-hoc network (VANET) has progressively gained attention from both industry and research with the rapid development of wireless communication technology and intelligent vehicles. The vehicles exchange messages with other entities but cannot share the resources between them. Therefore, security is required in some scenarios including integrity, traceability, confidentiality, notarization of exchanged information as well as access control. In order to provide a secure vehicle communication and access control, we propose an ABAC access control model using smart contract on the blockchain. The use of the blockchain facilitates the sharing of secure messages among vehicles. Moreover, vehicles are able to share the resources with each other exploiting the access control policy on the XACML standard. Then, we evaluate the access response time and the storage overhead of the proposal. Amira Kchaou, Ryma Abassi, Samiha Ayed, Sihem Guemara El Fatmi |
IWCMC | 4 |
| 2020 | Towards the performance evaluation of a clustering and trust based security mechanism for VANETabstractVehicular Ad-hoc Networks (VANETs) establish communication between vehicles in order to share safety information about road accidents or traffic jams, or non-safety information through messages. Besides, VANETs have a dynamic topology since the vehicles have a high mobility and therefore, the exchanged messages could be dropped or modified. However, falsified messages can be transmitted, the network performance can be affected. In a previous work, we have proposed a Clustering Mechanism for VANET (CMV) as well as a Trust management based on CMV (TCMV) to secure clustering mechanism for message exchange in the VANET. The CMV is based on two steps: (1) the clusters formation step where clusters are formed and the Cluster Heads are elected, and (2) the clusters maintenance step where the organization of clusters is kept in the presence of velocity when the topology changes in VANET, mainly at the arrival of a new vehicle or the displacement or the failure of a vehicle. Besides, the TCMV is used the reputation values of vehicles to compute the credibility of exchanged message. In this paper, we evaluate the performance of the CMV and TCMV. Hence, several simulations were realized with different number of vehicles, velocities and transmission range for the number of formed clusters, the cluster stability status, the Packet Data Ratio (PDR), the reputation of honest and dishonest vehicle, and cases of Trust Message. Amira Kchaou, Ryma Abassi, Sihem Guemara El Fatmi |
ARES | 3 |
| 2019 | Towards a New Clustering Algorithm based on Trust Management and Edge Computing for IoTabstractToday Internet of things (IoT) is omnipresent bringing to us tracking and identification technologies, enhanced communication protocols and distributed intelligence in smart objects. Unfortunately, IoT is not far from security risks since it is an heterogeneous network comprising different nodes status. Malicious nodes impact harmfully on IoT network stability. In addition, IoT objects have limited capacities in processing, storage and batteries. To improve their batteries lifetime, objects workload should be bend down. Taking into consideration these IoT issues, we propose in this paper a clustering mechanism based on trust management and edge computing for IoT. The security intervention is based on excluding malicious nodes from an IoT network as well as by disseminating reliability between worthy nodes in favour of trust management. In order to minimize energy consumption, we established a one hop clustering mechanism based on density of nodes in an IoT network, trust and energy levels of nodes. All clusters are supervised by base stations in the edge of the network. We also integrate edge computing to migrate data processing and storage to base stations. Nadia Kammoun, Ryma Abassi, Sihem Guemara El Fatmi |
IWCMC | 3 |
| 2018 | Towards a Privacy Preserving and Flexible Scheme for Assessing the Credibility and the Accuracy of Safety Messages Exchanged in VANETsabstractIn Vehicular Ad hoc NETworks (VANETs), vehicles exchange safety related messages in order to improve the driving experience. However, it is not realistic to presume the absence of attackers intending to subvert the proper operation of the network. While message authentication enables the receiver to make sure of the received message's integrity and to verify its originator, it does not permit the verification of the message's credibility and accuracy. The main contribution of this paper is then the proposition of a scheme to assess the credibility and the accuracy of safety related messages exchanged in VANETs. Three modules constitute our proposal: a reputation module to evaluate the respective reputations of vehicles, a time and location closeness estimation module to judge the accuracy of a reported event and a majority module to decide the trueness of a received traffic information. These modules can be used in a separated or a combined way enabling a more flexibility in front of different circumstances confronted in VANETs. An in-depth security analysis is performed to demonstrate the efficiency of our proposal. Case studies that illustrate the different modules are also presented. Ons Chikhaoui, Aida Ben Chehida Douss, Ryma Abassi, Sihem Guemara El Fatmi |
ARES | 4 |
| 2018 | Toward a Distributed Trust Management scheme for VANETabstractA Vehicular Ad hoc NETwork (VANET) is a self-organized network, formed by vehicles and some fixed equipment on roads called Roads Side Units (RSUs). Vehicular communications are expected to share different kinds of information between vehicles and infrastructure. Because of these specifications, securing VANET constitutes a difficult and challenging task that has attracted the interest of many researchers. In a previous work, we proposed a Clustering Mechanism for VANET (CMV) and its inherit Trust management scheme (TCMV) to ensure security of communication among vehicles. CMV organizes vehicles into clusters and elected Cluster Heads (CHs), and allows the clusters maintenance while dealing with velocity. On the other side, TCMV computes the credibility of the message by CH using the reputation of vehicles. However, we found that the value of credibility of the message by CH is not enough to verify if an exchanged message is correct or no. In order to provide a secured vehicle communication and to build reliance communication among vehicles, we propose a distributive trust management scheme for VANET to verify the correctness of the message based on the controlling of the vehicle'behavior by a miner and the credibility of message by a CH. Amira Kchaou, Ryma Abassi, Sihem Guemara El Fatmi |
ARES | 3 |
| 2017 | Hierarchical Identity Based Cryptography for Security and Trust in Named Data NetworkingabstractNamed Data Networking (NDN) represents an emergent Information-Centric Networking architecture. It treats data as the central element and it leverages in-network caching. With the latter feature, traditional security mechanisms, tied to data location, can no longer be used. That's why a data-centric security model is adopted. This model relies mainly on the addition of a signature to each of the recovered data. However, the signature verification requires the appropriate public key. To trust this key, NDN provides an interesting platform, supporting multiple models. In this paper, we analyze the security and the trust in NDN. We determine the limits of the already proposed solutions. We propose then a security extension that relies on Hierarchical Identity-Based Cryptography (HIBC). This extension better meets the security requirements and it builds trust in the keys used in signature verification. To validate our proposal, it is integrated into the current prototype of NDN and its performance evaluation is provided. This evaluation proves that by adopting our extension, performance is comparable, even better in some cases than plain NDN. Balkis Hamdane, Rihab Boussada, Mohamed Elhoucine Elhdhili, Sihem Guemara El Fatmi |
WETICE | 4 |
| 2017 | Towards a Secure Access to Content in Named Data NetworkingabstractNamed Data Networking (NDN) is one of the most promising candidates for the next-generation Internet architecture. It adopts the Information Centric Networking (ICN) approach which considers the named data as the central element. For a more effective content delivery in this approach, content can be recovered from any node implementing caching capabilities. However, with this caching property, access control can no longer be ensured by traditional mechanisms. It must be built into the content itself regardless its location. In this paper, we propose an access control solution based on content encryption and valid both in closed and open environments. In this solution, sensitive content are encrypted and only authorized entities can retrieve the necessary keys for encryption and decryption. We demonstrate the effectiveness of the proposed solution by implementing it in the prototype of NDN, named CCNx, and by evaluating its performances. This evaluation proves that our solution introduces an acceptable overhead, lower than that of the access control solution currently adopted in CCNx. Balkis Hamdane, Rihab Boussada, Mohamed Elhoucine Elhdhili, Sihem Guemara El Fatmi |
WETICE | 4 |
| 2015 | Trust Negotiation Based Approach to Enforce MANET Routing SecurityabstractMANETs (Mobile Ad hoc Networks) are described assets of mobile nodes connected with wireless links. To be efficient, routing protocols in MANETs should, in fact, manage mobility, handle nodes energy dissipation and ensure security. We argue in this paper that trust negotiation is appropriate in such context to enhance the network performances. Trust concept is of concern to communication and network protocol designers. Thus, building trust relationships among participating nodes is critical to enabling collaborative optimization of system metrics. The main contribution of this paper is an extension of our previous proposition DTMCA (Delegation Trust Mobility-based Clustering Approach) which defines a new clustering approach, a trust management process and a delegation process. This environment allows the localization and the isolation of malicious nodes in MANETs. The extension proposed in this paper extends the trust management process by adding a trust negotiation module used in order to minimize the risk that malicious nodes join the MANETs. Aida Ben Chehida Douss, Samiha Ayed, Ryma Abassi, Nora Cuppens, Sihem Guemara El Fatmi |
ARES | 5 |
| 2015 | A Model for Specification and Validation of a Trust Management Based Security Scheme in a MANET EnvironmentabstractRecently, we proposed a reputation based trust management scheme built upon a Mobility-based Clustering Approach (MCA) organizing Mobile Ad hoc Network MANET and detecting and isolating malicious behaviors. The whole scheme was called TMCA (Trust based MCA) and was extended in a second time with a delegation process resulting a proposition baptized DTMCA (Delegation TMCA based process). However, deploying such scheme is error prone and it appears necessary to validate it before its real implementation. In fact, scheme specification and validation constitute two fundamental challenges in the development of secure communication systems ensuring that the scheme is correctly enforced and complete. Hence, the main contribution of this paper concerns a validation framework for DTMCA scheme. The first step towards validation process is its formal specification. This is our first concern in this paper: a formal specification language called SCMSL (Secured Clustered MANET Specification Language) defined through a syntax based on authorization and obligation rules and a clear semantics. The second part of this paper proves the two major characteristics that must be guaranteed in such case: consistency and completeness. Consistency is proved by showing that there is no conflict in our scheme whereas completeness is proved by assessing that all potential situations are handled. The proof of consistency and completeness is made using automated systems through the definition of adequate algorithms. Aida Ben Chehida Douss, Ryma Abassi, Sihem Guemara El Fatmi |
ARES | 3 |
| 2015 | A Formal Environment for MANET Organization and Security
Aida Ben Chehida Douss, Ryma Abassi, Nihel Ben Youssef, Sihem Guemara El Fatmi |
CANS | 4 |
| 2015 | Toward Securing MANET Against the Energy Depletion Attack
Aida Ben Chehida Douss, Ryma Abassi, Sihem Guemara El Fatmi |
CRiSIS | 3 |
| 2015 | A credential and encryption based access control solution for named data networkingabstractNamed Data Networking (NDN) represents a promising candidate for the future Internet architecture adopting the Information Centric Networking (ICN) approach. For a more effective content delivery, it leverages in-network caching. However, security can no longer be tied a particular location. It becomes a property of the content and its name, regardless where it is situated. To ensure access control that represents an important security feature, NDN proposes the use of an encryption-based model; sensitive data can be encrypted then decrypted only by legitimate entities. Many solutions adopting this model have been proposed but they require prior knowledge of all authorized entities. In this paper, we propose an encryption-based access control solution that does not have such requirements and which is valid in an open environment. This solution assigns access rights based on certified encrypted credentials provided by the different entities. To confirm the security of this proposal, a formal security analysis is provided. Balkis Hamdane, Sihem Guemara El Fatmi |
IM | 2 |
| 2014 | A Trust Management Based Security Mechanism against Collusion Attacks in a MANET EnvironmentabstractMANETs (Mobile Ad hoc Networks) are self organized networks with mobile and collaborating nodes without any pre-established infrastructure. Because of these characteristics, securing MANETs constitute a hard and challenging task. Consequently, new mechanisms may be of interest to secure such networks. To this end, we have found that trust management can be a support for MANET security. In fact, the reputation concept and the establishment of trustful relation between collaborating nodes can be meaningful to express security aspects in such environment. From there, we proposed in previous works a Mobility-based Clustering Algorithm (MCA) and a Trust management scheme for MCA (TMCA) to secure routing behaviors. MCA organizes nodes into clusters managed by a cluster-head (CH) and TMCA detects malicious routing behavior based on CHs direct observations and exchanged alerts. A delegation based process was also defined on TMCA and was called DTMCA. Although DTMCA meets security objectives, it may unfortunately be faced with various threats from malicious nodes: Several nodes can in fact collude in order to increase or decrease other reputation values to damage the QoS and even the MANET functioning. Our objective in this paper is then to secure DTMCA against collusion attacks. The mechanism proposed here is based on colluding nodes detection through cluster members behavior monitoring and by comparing this behavior with the received reputation value in the alert message. Detected colluder nodes are then discarded from further communication. Aida Ben Chehida Douss, Ryma Abassi, Sihem Guemara El Fatmi |
ARES | 3 |
| 2014 | A novel name-based security mechanism for information-centric networkingabstractThe Information-Centric Networking (ICN) approach represents a prominent future Internet research activity. It aims to ensure a large-scale content distribution while supporting mobility and security natively. In this approach, named content represents the central element and it is independent from its delivering host. Security can no longer be tied to a particular location. It is built-in the content and it strongly depends on names. There are mainly two naming approaches: (1) hierarchical and human readable, (2) flat and self-certifying. Each one provides certain security services. The other services are ensured using additional mechanisms. In this paper, we propose the adaptation of the naming system in order to provide a robust security model built-in the name. The proposed solution combines the benefits of the two existing naming system and it is built on top of Identity-Based Cryptography (IBC). A formal security analysis is provided to confirm the safety of the new proposal. Balkis Hamdane, Sihem Guemara El Fatmi, Ahmed Serhrouchni |
WCNC | 2 |
| 2013 | A Reputation-Based Clustering Mechanism for MANET Routing SecurityabstractA Mobile Ad hoc NETwork (MANET) is a collection of mobile nodes having no fixed topology and cooperating with each other. Due to these particularities, classical routing protocols cannot be used and some specific ones have been proposed. Because routing process is fundamental in a MANET deployment, it constitutes a privileged target of attackers. In this paper we propose a novel reputation-based clustering mechanism to locate malicious nodes and isolate them. In order to reduce network overhead and to handle network topology dynamicity, the proposed mechanism is based on a specific clustering environment. The clustering maintenance complexity is for its part reduced by the use of a reputation based delegation process allowing the cluster-head to delegate its privileges to a chosen cluster member in case of displacement or lack of energy. Moreover, node's reputation handling allows the detection and isolation of malicious nodes. Five modules constitute this mechanism: a monitoring module to detect malicious nodes, a reputation module to update reputation values, an isolation module to discard malicious nodes, an identity recognition module to assess alerts sources and a delegation module to allow clusterhead privileges delegation. Aida Ben Chehida Douss, Ryma Abassi, Sihem Guemara El Fatmi |
ARES | 3 |
| 2013 | Data-based access control in named data networkingabstractNamed Data Networking (NDN) presents one of the first and most emergent Information Centric Networking (ICN) project. It offers an excellent substrate to solve today's Internet problems. To ensure security challenge, it adopts a data-centric model. The access control represents a fundamental securit Balkis Hamdane, Mounira Msahli, Ahmed Serhrouchni, Sihem Guemara El Fatmi |
CollaborateCom | 4 |
| 2012 | Trust-based delegation for Ad Hoc QoS enhancingabstractThe importance of resources and services availability in Ad Hoc networks has already been proved several times in the past. It concerns, essentially, node availability as well as routing and forwarding actions accessibility. Unfortunately, nodes' lifetimes may be reduced or even depleted which leads to route failure, packets loss, QoS deterioration, etc. This is mainly due to a battery problem that can be caused by a legitimate consumption or by an attacker. To mitigate this problem and in order to allow nodes perpetuity and to face up any unavailability or flinching, a sharing of nodes' permissions can be used. Delegation is a common practice that is used to simplify and to manage this kind of sharing. Our proposition is then, to use a delegation process in order to enhance the QoS of Ad hoc networks by allowing the perpetuity of routes without stopping the packets transfer nor the re-calculation of a novel route. In view of the importance of the issue, we propose to base delegation on trust relations. Trust is a security concept generally used to provide collaborating network entities with a mean to counter their uncertainty. The main contribution in this paper is then, the proposition of a trust based delegation model for Ad Hoc networks in order to enhance QoS and specially routes availability. Ryma Abassi, Sihem Guemara El Fatmi |
CRiSIS | 2 |
| 2008 | A Model for Specification and Validation of Security Policies in Communication Networks: The Firewall CaseabstractA security policy constitutes one of the major actors in the protection of communication networks. For this, and in order to manage the access grants in accordance with the security constraints, a security policy has to be validated before its deployment. Unfortunately, in the literature, there is no well established validation mechanisms ensuring the well founded of such security policies. This paper proposes a validation framework for security policies where: (1) executable specifications are used to build an 'Executable Security Policy', (2) a validation model is proposed to support the validation activity, and (3) a validation of the executable security policy is performed. The main contributions provided by this paper concerns the adaptation of some concepts and mechanisms traditionally used in software engineering for validation aims, such as specification, executable specification or reachability graph. All the definitions made in this paper have been proposed in accordance with the firewall case. Ryma Abassi, Sihem Guemara El Fatmi |
ARES | 2 |
| 2008 | An Automated Validation Method for Security Policies: The Firewall CaseabstractResearch in computer security issues has recently addressed the development of security policy specification languages. It has however omitted the need of formal validation. In this paper we try to remedy to this drawback by the proposition of an automated tool for security policies. Because we have found several similarities between security policies and software engineering, our approach is strongly inspired from the reasoning followed in the software engineering. First, it brings out a model inspired by Promela to enable the validation task. Secondly, it proposes a 3-step validation process that deals with consistency, completeness and preservation of safety and liveness properties. Ryma Abassi, Sihem Guemara El Fatmi |
IAS | 2 |
| 2008 | Towards an automated firewall security policies validation processabstractA security policy constitutes one of the major actors in the protection of communication networks. However, it can be one of their weaknesses if it is inadequate according to the network security requirements. For this, a security policy has to be validated before its deployment. Unfortunately, in the literature, there is no well established validation mechanisms ensuring the well founded of such security policies. This paper proposes a validation framework for security policies based on the concept of executable specifications and applied to the firewall case. The main contributions provided by this paper concerns the adaptation of some concepts and mechanisms traditionally used in software engineering for validation aims, such as specification, executable specification or reachability graph. Ryma Abassi, Sihem Guemara El Fatmi |
CRiSIS | 2 |
| 2007 | A QoS-Oriented Protocol for Burst Admission Control in OBS NetworksabstractAmong the promising solutions for next generation Internet backbones, one can consider the optical burst switching (OBS) technology. One of the main aspects in the design of optical burst-switched networks is the development of a burst admission control protocol suitable for QoS provisioning. In this paper, we develop a method to address the call admission control (CAC) in OBS networks that is QoS-oriented. For this, an analytic model is developed for formulating the burst admission control problem. A QoS-constraints based burst admission control protocol is developed. Finally, simulation experiments are performed to validate the proposed schemes. Amor Lazzez, Noureddine Boudriga, Mohammad S. Obaidat, Sihem Guemara El Fatmi |
AICCSA | 4 |
| 2007 | A Dynamic QoS-Based Scheme for Admission Control in OBS NetworksabstractOptical burst switching (OBS) technology is a promising solution for the next generation Internet backbone. However, call admission control (CAC) and QoS support constitute critical issues for this technology. In this paper, we propose a novel QoS-Oriented scheme for burst admission control in OBS networks. An analytic model is developed to estimate the provided QoS for a given traffic type. We also develop a performance evaluation study to validate the proposed scheme and evaluate its impacts on the efficiency of network resource utilization. Amor Lazzez, Sihem Guemara El Fatmi, Noureddine Boudriga, Mohammad S. Obaidat |
ICC | 2 |
| 2007 | A novel node architecture for optical networks: Modeling, analysis and performance evaluation
Amor Lazzez, Yassine Ramadhane Khlifi, Sihem Guemara El Fatmi, Noureddine Boudriga, Mohammad S. Obaidat |
Comput. Commun. | 3 |
| 2006 | QoS Oriented Contention Resolution Techniques for Optical Burst Switching NetworksabstractOne of the major challenges in optical burst switching networks is the quality of service provision. Some proposals have been made and several limitations have been observed. In this paper, we propose two efficient techniques that enhance the quality of service provided in such networks. The first one deals with optical burst loss during contention resolution process. The second one provides a differentiated service technique using prioritized contention resolution policies in the network core. The two proposed techniques are investigated through extensive simulations. The simulation results show that these techniques lead an effective reduction of the burst average loss rate compared to existing techniques. They also show that a significant differentiation with regard to burst loss can be achieved when burst priorities are considered. Moëz Cherif, Sihem Guemara El Fatmi |
BROADNETS | 2 |
| 2004 | Relational-based calculus for trust management in networked services
Sihem Guemara El Fatmi, Noureddine Boudriga, Mohammad S. Obaidat |
Comput. Commun. | 1 |
| 1997 | Multiple connections in data communication and advanced applications
Noureddine Boudriga, Mohammad S. Obaidat, Sihem Guemara El Fatmi |
Comput. Commun. | 3 |