VLDB 2026 Research / reviewers in the wild / expert
Hermann de Meer
dblp:m/HermanndeMeer
· DBLP profile ↗
57ranked-venue papers
9as first author
6since 2021 · last 2026
0000-0002-3466-8135ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 24 · 3 first-author · 4 since 2021Systems, architecture and hardware · 10Security and privacy · 10 · 2 first-authorApplied, interdisciplinary, general and emerging computing · 6 · 1 first-authorArtificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 1Databases, data management, data science and information retrieval · 1Graphics, computer vision, multimedia, augmented reality and games · 1Theory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Design of Weather-Resilient Satellite-Terrestrial ICT Networks for Power Grid CommunicationsabstractHybrid satellite-terrestrial communication networks can enhance the resilience of power grid communications. Recent advancements in low-Earth orbit (LEO) satellite technologies have improved their ability to meet the communication requirements of power grid applications. However, the dynamic nature of LEO networks necessitates frequent routing updates, which can potentially disrupt the transmission of critical power grid monitoring and control data. Additionally, extreme weather events, such as severe rainfall, can impair both terrestrial and satellite communication links, posing risks to the operation of the power grid. This paper presents a two-phase methodology for reducing the need for frequent routing updates by identifying stable low-latency configurations of hybrid satellite-terrestrial communication networks for power grid applications. In the proactive phase, the deterministic dynamics of LEO satellite constellations are considered to generate a sequence of stable network configurations using fine-grained temporal snapshots and graph aggregation. The adaptive phase incorporates a dynamic regional weather model to update link capacities. A minimum-delay multi-commodity flow problem is solved to determine the best traffic distribution under given conditions. Simulation results show that hybrid networks with stable configurations can reduce network reconfiguration frequency by 92%. Compared to terrestrial-only networks, the hybrid network improves end-to-end delay by 65.5% and maintains approximately 80% connectivity even under extreme rainfall conditions. Anna Volkova, Julian Schmidhuber, Hermann de Meer, Jacek Rak |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2025 | Evolutionary Multi-objective Optimization of Unmanned Aerial Base Station Placement for Power Grid Recovery
Mohammad Reza Mohebbi, Anna Volkova, Hermann de Meer |
IJCCI (2) | 3 |
| 2025 | ICT-Based Power-System Service Resilience
Hermann de Meer |
VEHITS | 1 |
| 2025 | QCSAS: A Quasi-Constant and Synchronized Aggregate Signature Scheme for AMI NetworksabstractSmart grids must safeguard their critical infrastructures against both physical and cyber attacks. Therefore, real-time operation and cybersecurity are two fundamental requirements for smart grid systems. AMI (Advanced Metering Infrastructure) is a critical part of the smart grid that specifically deals with the measurement, collection, and analysis of electricity usage data. Digital signatures help prevent data tampering and ensure cybersecurity during AMI communications. However, as the number of smart meters and transactions in an AMI network increases, deploying digital signatures can lead to communication delays. This paper designs a quasi-constant and synchronized aggregate signature scheme (QCSAS), which can protect usage data without hash functions. The QCSAS scheme simplifies the synchronized aggregate signatures, and is proved secure against chosen message attacks in the random oracle model. The QCSAS scheme incorporates the features of synchronized aggregate signatures, such as the constant aggregate signature size, thereby minimizing the data management system’s storage space. Furthermore, the length of usage data does not exceed 12-bit, in compliance with existing governmental standards. The computational cost of multiplying a 12-bit integer is negligible compared to other cryptographic operations. Thus, the verification cost of the QCSAS scheme remains quasi-constant. Yujiao Sun, Zhiyuan Sui, Huaqun Wang, Hermann de Meer |
IEEE Internet Things J. | 4 |
| 2025 | Optimal Redundant Sensor Placement for Protection Blinding in Active Distribution GridsabstractIntegrating renewable energy sources into the power distribution grid challenges protection system operation, leading to protection blinding when circuit breakers fail to trip due to fault current contribution from these sources. Communication-based adaptive protection can address this issue, but communication system components like sensors can fail. This research proposes a genetic algorithm-based approach to optimally place redundant sensors, minimising protection blinding under communication uncertainty within a redundancy budget. The fault tolerance, measured by a new metric called redundancy degree, reflects the number of redundant components deployed. Results demonstrate the algorithm’s effectiveness in optimising redundant sensor locations, reducing system costs, and improving fault tolerance. For the system and scenarios investigated, an average of 60% redundant sensors are relocated, reducing the average protection trip time by 36.65% compared to a baseline approach that does not consider communication uncertainty. This encourages incorporating communication component failure considerations in power system planning. Amit Dilip Patil, Abdorasoul Ghasemi, Hermann de Meer |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2024 | Towards Forming Optimal Communication Network for Effective Power System RestorationabstractRestoration of modern interdependent Information and Communication Technology (ICT) and power networks relies on preplanned and reactive strategies to consider simultaneous communication and power system recovery. This paper addresses the problem of finding and energizing a proper communication network connecting the distributed power grid assets in the restoration process, assuming a probability of infeasibility of recovering each communication node. The proper network has the minimum size, meets the communication requirements of power system recovery, and guarantees robustness against ICT nodes not being recoverable during restoration. The problem is formulated as a multi-objective optimization problem and solved using the genetic algorithm to find the optimal subgraph that ensures enough node-disjoint paths between the communicating power grid assets. Simulation results for the restoration strategy of the communication network associated with a power network are provided and discussed. The results show that networks’ ability to mitigate the adverse consequences of node failures can be significantly improved by incorporating just a few additional nodes and links while keeping the ICT network compact and feasible for restoration. Anna Volkova, Abdorasoul Ghasemi, Hermann de Meer |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2020 | Worst-Case Delay Slicing for Time-Sensitive Applications in Softwarized Industrial NetworksabstractThe pervasiveness of network softwarization has drawn keen interest from industrial domain as network convergence becomes increasingly desirable amongst industrial operators. Coupled with the concept of network slicing, operators will be able to tailor resources to applications regardless of the contrast in application requirements. However, while the concept of slicing is prevalent in industrial network circles, the realization of the concept in practical deployment scenarios is rarely emphasized. This paper provides a step-by-step analysis for the creation of dynamic network slices to guarantee real-time deterministic requirements of periodic industrial applications. The objective of the paper is achieved by the design and integration of worst-case delay models in the virtual network embedding problem with a focus on the behavior of time-sensitive forwarding mechanisms introduced in standard Ethernet bridges. The result shows that the approach is able to guarantee delay requirements irrespective of the arrival order of slices. Ansah Frimpong, Jürgen Rottmeier, Andreas Zirkler, Hermann de Meer |
ETFA | 4 |
| 2020 | A Framework for Virtualizing Time-aware Shaper Using High Performance NFVabstractIn this work, we discover the feasible methods of using Network Function Virtualization (NFV) to reduce the complexity and cost of implementing and deploying the Time- aware Shaper (TAS). TAS is one of the traffic shapers presented in the recent IEEE Time Sensitive Networks (TSN) standard for industrial Ethernet. Virtualizing network functions decouples them from proprietary hardware but imposes performance challenges. We research high performance NFV techniques and use Data Plane Development Kit (DPDK) to implement a virtual TAS with a feasible performance for factory level industrial applications. Furthermore, we design a complete framework that provides preliminary schedule calculation, transmission selection, TAS controller, and time synchronization. Additionally, the framework includes evaluation tools; traffic generation and performance measurement. We evaluate our virtual TAS using delay and frame loss metrics, and a small Service Function Chain (SFC). The evaluation considers different loads of Best Effort Traffic (BET) and external disturbance, and varied Time-critical Traffic (TCT) specifications. Waseem Mandarawi, Hamza Chahed, Hermann de Meer |
ETFA | 3 |
| 2020 | Controller of Controllers Architecture for Management of Heterogeneous Industrial NetworksabstractIncreasing heterogeneity of industrial network systems is a fact and the chances that in the future one communication standard will be able to fulfill the requirements of all possible applications are utopian. With the increasing number of communication systems, their management, configuration, and maintenance become a significant issue. Additionally, due to the increasing amount of network services and traffic, the management of available network resources and the possibility of delivering certain levels of communication quality of service, especially across different network solutions becomes a big challenge. Therefore, in this paper a Controller of Controllers (CoC) concept for management of heterogeneous industrial networks is proposed. The concept is designed to support still widely spread legacy fieldbus systems, different Ethernetbased industrial solutions, and potentially upcoming network technologies. The goal is achieved by leveraging state-of-theart architectural concepts such as software-defined networks, which allows for integration of abstract models in network management. The concept is described and discussed by way of a demonstrator concept for a heterogeneous system of fieldbus and Ethernet-based time-sensitive networks. Ansah Frimpong, Santiago Soler Perez Olaya, Dennis Krummacker, Christoph Fischer, Alexander Winkel, René Guillaume, Lukasz Wisniewski, Marco Ehrlich, Waseem Mandarawi, Henning Trsek, Hermann de Meer, Martin Wollschlaeger, Hans D. Schotten, Jürgen Jasperneite |
WFCS | 11 |
| 2020 | An Efficient Signcryption Protocol for Hop-by-Hop Data Aggregations in Smart GridsabstractAggregation trees have been proposed for privacy preservation to reduce data collectors' computational cost in smart grids. In aggregation tree models, smart meter usage data should be forwarded by all its ancestors, which delays usage data transmissions. We report the design of an identity-based signcryption protocol without oracles for aggregation trees. The designed protocol significantly reduces smart meter computational costs due to its homomorphic features. (1) Compressed signatures can be verified in batches. The computational cost of verification is independent of the number of usage reports. (2) A smart meter can generate a signature on the aggregated cipher without executing signing algorithms during transmissions. Extensive simulations demonstrate that, based on the proposed protocol, the communication efficiency of our privacy preservation scheme outperforms other aggregation tree-based schemes regarding transmission delay and computational cost. Zhiyuan Sui, Hermann de Meer |
IEEE J. Sel. Areas Commun. | 2 |
| 2020 | BAP: A Batch and Auditable Privacy Preservation Scheme for Demand Response in Smart GridsabstractAdvancing network technologies allow the setup of two-way communication links between energy providers and consumers. These developing technologies aim to enhance grid reliability and energy efficiency in smart grids. To achieve this goal, energy usage reports from consumers are required to be both trustworthy and confidential. In this paper, we construct a new data aggregation scheme in smart grids based on a homomorphic encryption algorithm. In the constructed scheme, obedient consumers who follow the instruction can prove their data consumption's adjustment by using a range proof protocol. Additionally, we propose a new identity-based signature algorithm in order to ensure authentication and integrity of the constructed scheme. By using this signature algorithm, data usage reports are verified in real time. Extensive simulations demonstrate that our scheme outperforms other data aggregation schemes. Zhiyuan Sui, Hermann de Meer |
IEEE Trans. Ind. Informatics | 2 |
| 2019 | DBvLEA: A Demand-Based Approach to Virtual Link Mapping for Multi-Service Industrial ApplicationsabstractNetwork virtualization is proposed in several research work as a means to overcome the ossification of the Internet. Its application relies on embedding algorithms to instantiate virtual networks on substrate infrastructures. Notably, those considered in the scope of traffic-engineering are developed to focus on efficient resource utilization with the aim of increasing the acceptance ratio of the algorithms. In this paper, a demand-based virtual link embedding approach for multi-service mapping in programmable industrial networks is proposed. The approach aims at increasing the overall acceptance ratio of virtual link embedding algorithms by increasing the acceptance of demand critical requests. The goal is achieved by minimizing the deviation between requested demands and the resources satisfying the demand. The approach, when analyzed against state-of-the-art shortest path approaches under the same simulation conditions, shows good results in terms of utilization of the network resources, acceptance of delay-critical traffic demands and overall acceptance ratio. Ansah Frimpong, Hermann de Meer |
CNSM | 2 |
| 2019 | Network Slicing : An Industry PerspectiveabstractThe prevalence of the term “Network Slicing” in today's communication network research community signifies the concept worthy of focus. However, despite its ubiquitous usage, there are varied interpretations of the concept which often leads to disagreement and confusion. The root of this misunderstanding lies in what the term “Slicing” means to the user and the context of its application. Network slicing has been considered as a key concept in 5G which will enable various types of services like enhanced Mobile Broadband (eMBB), Ultra Low Latency Reliable Communication (URLLC) and massive Machine Type Communication (mMTC) for industries. Despite all the standardization efforts, less progress has happened in the field to demystify the concept due to the misinterpretation of the term by various parties. As a result, this paper aims to provide an industrial perspective on the concept of Slicing and its usage in industrial communication networks. It shall as well propose contextualized taxonomy of the areas of usage as a way of reducing the vagueness surrounding the concept. Thus, within this context, an objective rather than subjective comprehension can ensue in intellectual discussions. Ansah Frimpong, Mainak Majumder, Hermann de Meer, Jürgen Jasperneite |
ETFA | 3 |
| 2019 | Application Topology-Aware Virtual Network Mapping and Service Provisioning in Programmable NetworksabstractIn this paper, an application topology-aware virtual network mapping and service provisioning framework dubbed “APTASP” is introduced. The framework is presented as a candidate to deal with the expected increase in the complexity of network management originating from the evolution of IoT and Industrial Internet. Envisaged under the programmable network paradigm, it infers the communication relationships between interacting applications from packet headers. Using this information, it recognizes the communication patterns to build up communication relations. The communication relations are then mapped to template network topologies that enable optimized resource allocation while at the same time ensuring QoS adherence. The service provisioning aspect of the framework introduces as well service function constructs which represent virtualized network function chains required for dynamic and automated service setup. Ansah Frimpong, Santiago Soler Perez Olaya, Hermann de Meer, Martin Wollschlaeger |
ETFA | 3 |
| 2019 | Schedulability Analysis and GCL Computation for Time-Sensitive NetworksabstractIndustrial automation networks are composed of cyber-physical systems where frame delays and jitter influence significantly the quality of communication between control and field devices. Due to these constraints, such systems are often served by dedicated Fieldbus networks which are different from networks for enterprise-level connectivity. However, with the introduction of Time-sensitive Networking standards which are already integrated into IEEE 802.1Q-2018 standards in essential parts, the long expected single converged network for any-type communication in the field, control, and enterprise level is within reach. With it, comes the challenge of synthesizing schedules to obtain parameters for configuring the network bridges for time-triggered communication services.This paper provides a scheduling verification, and Gate Control event computation algorithm focused on asserting the viability of scheduling communication services for multiple independent periodic Talker applications on IEEE 802.1Q- Time Sensitive Networks as well as the computation of Gate Control Lists for the bridges. Ansah Frimpong, Mohamed Amine Abid, Hermann de Meer |
INDIN | 3 |
| 2019 | Prioritize When Patching Everything is Impossible!abstractVulnerable critical networks are attractive targets for remote adversaries with different intentions. Towards enhancing resilience against extreme risks, such networks need to continuously assess their security posture and prioritize possible remediation actions based on security risk. The contribution of this work is to provide an integrated risk-based decision-support methodology for prioritizing risk remediation activities. Our methodology leverages the Time-To-Compromise security metric to quantitatively assess the compromise risk. Furthermore, it employs game-theory principles to model the strategic behaviour of the involved players (e.g., defender and attacker). The novelty of this approach lies in the way it integrates the risk attitude of the decision makers involved in the patch management operations across critical organizations into the prioritization process. Ali Alshawish, Hermann de Meer |
LCN | 2 |
| 2019 | Quasi-purification of mixed game strategies: Sub-optimality of equilibria in security games
Ali Alshawish, Mohamed Amine Abid, Hermann de Meer |
Comput. Secur. | 3 |
| 2018 | Software- Defined Networking as an Enabler for Future Industrial Network ManagementabstractThe overall Industry 4.0 (I4.0) developments combined with the disruptive process of IT-based digitalisation create a vast amount of new opportunities but also challenges for the industrial automation domain. The combination of hybrid (wired & wireless) communication architectures, already widely installed legacy technologies, new approaches, such as Time-Sensitive Networking (TSN) or 5G, and the general heterogeneity of the industrial landscape results in a high configuration complexity. This creates the necessity for future-proof industrial communication network management systems. Therefore, this paper summarises the current state of the art in this area in order to identify the specific requirements towards future industrial network management systems. The most promising candidate is the Software-Defined Networking (SDN) concept. To evaluate SDN as a possible enabler, specified industrial requirements are compared with the current technological and conceptual capabilities of SDN. In addition, drawbacks resulting in future research questions are identified. Marco Ehrlich, Dennis Krummacker, Christoph Fischer, René Guillaume, Santiago Soler Perez Olaya, Ansah Frimpong, Hermann de Meer, Martin Wollschlaeger, Hans D. Schotten, Jürgen Jasperneite |
ETFA | 7 |
| 2016 | Greener Bits: Formal Analysis of Demand Response
Christel Baier, Sascha Klüppelholz, Hermann de Meer, Florian Niedermeier, Sascha Wunderlich |
ATVA | 3 |
| 2016 | QR code based mutual authentication protocol for Internet of ThingsabstractIn the Internet of Things (IoT), security is important and challenging; however, it is often neglected. This paper presents a smart home scenario, together with its requirements for a secure and user friendly mutual authentication protocol. Protocols developed for the internet are often not applicable to the Internet of Things due to hardware limitations and physical inaccessibility of devices. To tackle the challenge of a usable and secure device authentication in the area of the IoT, a QR code based mutual authentication protocol is proposed. The protocol supports two operation modes to handle different hardware configurations with respect to cameras and displays. Both operation modes are secure against attacks within the proposed attacker model. The protocol can also be used to exchange the public keys between two parties, in order to establish a secure channel without a trusted third party. Tobias Marktscheffel, Wolfram Gottschlich, Wolfgang Popp, Philemon Werli, Simon D. Fink, Arne Bilzhause, Hermann de Meer |
WoWMoM | 7 |
| 2016 | Generating Virtual Network Embedding Problems With Guaranteed SolutionsabstractThe efficiency of network virtualization depends on the appropriate assignment of resources. The underlying problem, called virtual network embedding, has been much discussed in the literature, and many algorithms have been proposed, attempting to optimize the resource assignment in various respects. Evaluation of those algorithms requires a large number of randomly generated embedding scenarios. This paper presents a novel scenario generation approach and demonstrates how to produce scenarios with a guaranteed exact solution, thereby, facilitating better evaluation of embedding algorithms. Andreas Fischer 0001, Hermann de Meer |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2015 | RESA: A Robust and Efficient Secure Aggregation Scheme in Smart Grids
Zhiyuan Sui, Michael Niedermeier, Hermann de Meer |
CRITIS | 3 |
| 2015 | Data centres' power profile selecting policies for Demand Response: Insights of Green Supply Demand Agreement
Robert Basmadjian, Lukas Müller, Hermann de Meer |
Ad Hoc Networks | 3 |
| 2015 | Distributed and scalable embedding of virtual networks
Michael Till Beck, Andreas Fischer 0001, Juan Felipe Botero, Claudia Linnhoff-Popien, Hermann de Meer |
J. Netw. Comput. Appl. | 5 |
| 2013 | Scope of Security Properties of Sanitizable Signatures RevisitedabstractSanitizable signature schemes allow for altering signed data in a signer-controlled way by a semi-trusted third party. This is contrary to standard digital signature schemes, which do not permit any modifications by any party without invalidating the signature. Due to transparency, a strong privacy notion, outsiders cannot see if the signature for a message was created by the signer or by the semi-trusted party. Accountability allows the signer to prove to outsiders if a message was original or touched by the semi-trusted party. Currently, block-level accountability requires to drop transparency. We allow for accountability for sanitizable signatures with transparency on the block-level. Additionally, we generalize the concept of block-level properties to groups. This offers a even more fine-grained control and leads to more efficient schemes. We prove that group-level definitions imply both the block-level and message-level notions. We derive a provably secure construction, achieving our enhanced notions. A further modification of our construction achieves efficient group-level non-interactive public accountability. This construction only requires a constant amount of signature generations to achieve this property. Finally, we have implemented our constructions and the scheme introduced by Brzuska et al. at PKC '09 and provide a detailed performance analysis of our reference implementations. Hermann de Meer, Henrich Christopher Pöhls, Joachim Posegga, Kai Samelin |
ARES | 1 |
| 2013 | A distributed, parallel, and generic virtual network embedding frameworkabstractOne of the main challenges of network virtualization is the mapping of virtual network demands to physical network resources, commonly known as the virtual network embedding (VNE) problem. This paper introduces DPVNE, a distributed, parallel and generic VNE framework. DPVNE can be used 1) to run various cost-reducing embedding algorithms 2) in a distributed way. Thereby, computational load for embedding multiple virtual networks is spread across the substrate network reducing workload of individual nodes and 3) enabling the embedding of multiple virtual networks in parallel. DPVNE, in contrast to existing distributed algorithms, 4) achieves lower message overhead and, despite of being distributed, 5) keeps embedding costs comparable to those of centralized approaches. Michael Till Beck, Andreas Fischer 0001, Hermann de Meer, Juan Felipe Botero, Xavier Hesselbach |
ICC | 3 |
| 2013 | Integrating data centres into demand-response management: A local case studyabstractPower supply needs to match power demand up to a certain extent at all times in order to provide power with sufficient quality and to maintain the power grid in a stable state. Matching power supply to power demand becomes challenging due to a steadily increasing power demand and due to an increasing production of power based on renewable energy sources. Demand-response management shapes power demand according to the current power availability in the power grid. This paper discusses the feasibility and benefits of integrating data centres into demand-response schemes. Newly designed energy tariffs (so-called green supply-demand agreements) are presented that provide incentives for a possible cooperation between energy provider and data centre. Furthermore, this paper performs a local case study, where financial benefits of integrating data centres into demand-response management are evaluated in a real-world example. Andreas Berl, Sonja Klingert, Michael Till Beck, Hermann de Meer |
IECON | 4 |
| 2013 | An approach to energy-efficient virtual network embeddings
Andreas Fischer 0001, Michael Till Beck, Hermann de Meer |
IM | 3 |
| 2013 | Malleable Signatures for Resource Constrained Platforms
Henrich Christopher Pöhls, Stefan Peters, Kai Samelin, Joachim Posegga, Hermann de Meer |
WISTP | 5 |
| 2013 | A Novel Collaboration Paradigm for Reducing Energy Consumption and Carbon Dioxide Emissions in Data CentresabstractThis work describes a novel approach for the reduction of energy consumption in data centres (DCs) that will yield benefits both in terms of running costs and its environmental impact. The method is based on the introduction of collaborative interactions and flexibility clauses in contracts between all the DC ecosystem entities. The included entities are all the actors along the energy production–consumption chain, from the energy provider to the Information Technology customer. The collaborative approach also integrates the interaction between federated DCs. In this paper, we find a detailed description of the architecture that enables interaction between the DC ecosystem parties, which is designed to be progressively deployed, allowing traditional and ‘greened’ services to coexist, and without modification of the existing DC automation and framework systems. David Rincón Rivera, Anna Agusti-Torra, Juan Felipe Botero, Frederic Raspall, David Remondo, Xavier Hesselbach, Michael Till Beck, Hermann de Meer, Florian Niedermeier, Giovanni Giuliani |
Comput. J. | 8 |
| 2013 | Dynamic key management in wireless sensor networks: A survey
Xiaobing He, Michael Niedermeier, Hermann de Meer |
J. Netw. Comput. Appl. | 3 |
| 2012 | On Structural Signatures for Tree Data Structures
Kai Samelin, Henrich Christopher Pöhls, Arne Bilzhause, Joachim Posegga, Hermann de Meer |
ACNS | 5 |
| 2012 | Redactable Signatures for Independent Removal of Structure and Content
Kai Samelin, Henrich Christopher Pöhls, Arne Bilzhause, Joachim Posegga, Hermann de Meer |
ISPEC | 5 |
| 2012 | Flexible Redactable Signature Schemes for Trees - Extended Security Model and Construction
Henrich Christopher Pöhls, Kai Samelin, Hermann de Meer, Joachim Posegga |
SECRYPT | 3 |
| 2012 | Security and privacy issues for the network of the futureabstractABSTRACT The vision towards the Network of the Future cannot be separated from the fact that today's networks, and networking services are subject to sophisticated and very effective attacks. When these attacks first appeared, spoofing and distributed denial‐of‐service attacks were treated as apocalypse for networking. Now, they are considered moderate damage, whereas more sophisticated and inconspicuous attacks, such as botnets activities, might have greater and far reaching impact. As the Internet is expanding to mobile phones and ‘smart dust’ and as its social coverage is liberalized towards the realization of ubiquitous computing (with communication), the concerns on security and privacy have become deeper and the problems more challenging than ever. Re‐designing the Internet as the Network of the Future is self‐motivating for researchers, and security and privacy cannot be provided again as separate, external, add‐on, solutions. In this paper, we discuss the security and privacy challenges of the Network of the Future and try to delimit the solutions space on the basis of emerging techniques. We also review methods that help the quantification of security and privacy in an effort to provide a more systematic and quantitative treatment of the area in the future. Copyright © 2011 John Wiley & Sons, Ltd. Giannis F. Marias, João Barros, Markus Fiedler, Andreas Fischer 0001, Harald Hauff, Ralph Herkenhöner, Antonio Grillo, Alessandro Lentini, Luísa Lima, Charlott Lorentzen, Wojciech Mazurczyk, Hermann de Meer, Paulo F. Oliveira, George C. Polyzos, Enric Pujol-Gil, Krzysztof Szczypiorski, João P. Vilela, Tiago T. V. Vinhoza |
Secur. Commun. Networks | 12 |
| 2011 | An energy consumption model for virtualized office environments
Andreas Berl, Hermann de Meer |
Future Gener. Comput. Syst. | 2 |
| 2010 | Platforms and Software Systems for an Autonomic InternetabstractThe current Internet does not enable easy introduction and deployment of new network technologies and services. This paper aims to progress the Future Internet (FI) by introduction of a service composition and execution environment that re-use existing components of access and core networks. This paper presents essential service-centric platforms and software systems that have been developed with the aim to create a flexible environment for an Autonomic Internet. Javier Rubio-Loyola, Antonio Astorga, Joan Serrat 0001, Wei Koong Chai, Lefteris Mamatas, Alex Galis, Stuart Clayman, Abderhaman Cheniour, Laurent Lefèvre, Olivier Mornard, Andreas Fischer 0001, Alexandru Paler, Hermann de Meer |
GLOBECOM | 13 |
| 2010 | Towards Automated Processing of the Right of Access in Inter-organizational Web Service CompositionsabstractEnforcing the right of access to personal data usually is a long-running process between a data subject and an organization that processes personal data. As of today, this task is commonly realized using a manual process based on postal communication or personal attendance and ends up conflicting with trade secret protection. In this paper, we present an automated architecture to enable exercising the right of access in the domain of inter-organizational business processes based on Web Services technology. Deriving its requirements from the legal, economical, and technical obligations, we show the architecture's overall approach solving the conflict between trade secret and exercising the right of access. Ralph Herkenhöner, Hermann de Meer, Meiko Jensen, Henrich Christopher Pöhls |
SERVICES | 2 |
| 2010 | Energy-Efficient Cloud ComputingabstractEnergy efficiency is increasingly important for future information and communication technologies (ICT), because the increased usage of ICT, together with increasing energy costs and the need to reduce green house gas emissions call for energy-efficient technologies that decrease the overall energy consumption of computation, storage and communications. Cloud computing has recently received considerable attention, as a promising approach for delivering ICT services by improving the utilization of data centre resources. In principle, cloud computing can be an inherently energy-efficient technology for ICT provided that its potential for significant energy savings that have so far focused on hardware aspects, can be fully explored with respect to system operation and networking aspects. Thus this paper, in the context of cloud computing, reviews the usage of methods and technologies currently used for energy-efficient operation of computer hardware and network infrastructure. After surveying some of the current best practice and relevant literature in this area, this paper identifies some of the remaining key research challenges that arise when such energy-saving techniques are extended for use in cloud computing environments. Andreas Berl, Erol Gelenbe, Marco Di Girolamo, Giovanni Giuliani, Hermann de Meer, Dang Minh Quan, Kostas Pentikousis |
Comput. J. | 5 |
| 2010 | Network virtualization in energy-efficient office environments
Andreas Berl, Nicholas J. P. Race, Johnathan Ishmael, Hermann de Meer |
Comput. Networks | 4 |
| 2009 | Evaluating Streaming Rate Controllers: A Support Tool
Cristian Koliver, Jean-Marie Farines, Barbara Busse, Hermann de Meer |
MMM | 4 |
| 2009 | idMesh: graph-based disambiguation of linked dataabstractWe tackle the problem of disambiguating entities on the Web. We propose a user-driven scheme where graphs of entities -- represented by globally identifiable declarative artifacts -- self-organize in a dynamic and probabilistic manner. Our solution has the following two desirable properties: i) it lets end-users freely define associations between arbitrary entities and ii) it probabilistically infers entity relationships based on uncertain links using constraint-satisfaction mechanisms. We outline the interface between our scheme and the current data Web, and show how higher-layer applications can take advantage of our approach to enhance search and update of information relating to online entities. We describe a decentralized infrastructure supporting efficient and scalable entity disambiguation and demonstrate the practicability of our approach in a deployment over several hundreds of machines. Philippe Cudré-Mauroux, Parisa Haghani, Michael Jost 0003, Karl Aberer, Hermann de Meer |
WWW | 5 |
| 2009 | Editorial-autonomic and self-organising systems
Simon A. Dobson, John Strassner, Hermann de Meer |
Comput. Networks | 3 |
| 2009 | Finite-source M/M/S retrial queue with search for balking and impatient customers from the orbit
Patrick Wüchner, János Sztrik, Hermann de Meer |
Comput. Networks | 3 |
| 2008 | On the Design Dilemma in Dining Cryptographer Networks
Jens O. Oberender, Hermann de Meer |
TrustBus | 2 |
| 2007 | A Source Routing Solution to Non-Transitive Connectivity Problems in Distributed Hash TablesabstractDistributed hash tables are popular third generation P2P protocols which are well understood in theory. These protocols usually assume that every node in the overlay is able to exchange messages with any other overlay node. However, this assumption is not always true for real-world networks, including the PlanetLab or the entire Internet. In these networks, the non-transitive connectivity phenomenon is experienced, in which some overlay nodes are able to exchange messages with a certain node and others are not. This turned out to be a serious problem, particularly for structured P2P overlays. Non-transitive connectivity issues were mainly ignored by P2P research for a long time, but have been intensively discussed recently. This paper suggests a new measure for the degree of non-transitive connectivity and presents a comprehensive, source routing based solution, to overcome non-transitive connectivity problems in distributed hash tables. Ivan Dedinski, Andreas Berl, Alexander Hofmann, Sebastian Heglmeier, Bernhard Sick, Hermann de Meer |
ISCC | 6 |
| 2007 | A Novelty-Driven Approach to Intrusion Alert Correlation Based on Distributed Hash TablesabstractDistributed intrusion detection and prevention plays an increasingly important role in securing computer networks. In a distributed intrusion detection system, alerts or high-level meta-alerts are exchanged, aggregated, and correlated in a cooperative fashion to overcome the limitations of conventional intrusion detection systems. Substantial progress has been made, but current systems still suffer from various drawbacks: Most of them only distribute the data collection and not the analysis itself or they rely on a hierarchical or even centralized organization and/or communication architecture. Furthermore, the alerts or meta-alerts are usually aggregated at a pre-defined location and there is no reduction of the vast amount of alerts prior to distribution. Consequently, scalability is limited and any central component in the architecture introduces a "single point of failure ". We propose a completely distributed intrusion detection system based on distributed hash tables to efficiently exchange and aggregate alerts and meta-alerts in a cooperative, self-organizing, and load-balanced way. Independent intrusion detection agents publish their alerts based on a new novelty measure for alerts which prohibits the distribution of already known and hence worthless knowledge. The benefits of our approach are evaluated for a well-known probing attack. Alexander Hofmann, Ivan Dedinski, Bernhard Sick, Hermann de Meer |
ISCC | 4 |
| 2005 | Implicit Flow QoS Signaling Using Semantic-Rich Context Tags
Roel Ocampo, Alex Galis, Hermann de Meer, Chris Todd |
IWQoS | 3 |
| 2002 | A performance management architecture for peer-to-peer services based on application-level active networksabstractWe propose an application-level active networking-based architecture using modular "active proxylets" for managing peer-to-peer (p2p) services. The approach combines application-level and network-level performance control. Hermann de Meer, Kurt Tutschku |
NOMS | 1 |
| 2001 | Segmented Adaptation of Traffic Aggregates
Hermann de Meer, Piers O'Hanlon |
IWQoS | 1 |
| 2000 | Programmable agents for flexible QoS management in IP networksabstractNetwork programmability seems to be a promising solution to network management and quality of service (QoS) control. Software mobile-agents technology is boosting the evolution toward application-level control of network functionalities. Code may be deployed in the network dynamically and on demand for the benefit of applications or application classes. Agents support a dynamic distribution of control and management functions across networks, thus increasing flexibility and efficiency. We propose to use mobile-agent technology to overcome some of the problems inherent in current Internet technology. We focus our attention to QoS monitoring, being locally significant in network subdomains, and realize a QoS management strategy in response to variations of user, customer of application requirements, and of the network state. We describe our experience and the results obtained from our testbed, where software agents are instantiated, executed, migrated, and suspended in order to implement flexible QoS management in IP networks. Hermann de Meer, Aurelio La Corte, Antonio Puliafito, Orazio Tomarchio |
IEEE J. Sel. Areas Commun. | 1 |
| 1998 | Towards Formal Semantics for QoS SupportabstractThe introduction of the concept of QoS has led to an extension of the traditional concepts of service and service specification. However, the design of QoS support is usually done without a systematic approach, leading to concepts of QoS support ranging from basic QoS monitoring capabilities to hard real-time guarantees. In more advanced QoS support, intermediate layers should be designed in a way that enables the masking or controlled handling of sporadic QoS violations. To implement this degradation path support across multiple layers, a negotiation of preferred and supportable failure semantics is a requirement. To realize these advanced QoS support features, not only new QoS control mechanisms within the layers have to be developed but the semantics of QoS negotiation protocols between layers must be better understood and subsequently extended. A framework formally based on set theory and relations is presented that allows the specification of QoS hierarchies including a well-defined failure type model. The framework supports the development of QoS negotiation protocols and can be used as a formal base for a structured system analysis. Jan-Peter Richter, Hermann de Meer |
INFOCOM | 2 |
| 1998 | QoS-adaptation by software agents in the presence of defective reservation mechanisms in the InternetabstractOriginally, the Internet delivered best-effort service quality with respect to end-to-end delay. Recently, extensions such as RSVP have been proposed to provide guaranteed real-time services as well. Unfortunately, network resources, such as routers, do not yet fully, support RSVP reservation protocols so that guarantees cannot truly be given. We suggest to follow the paradigm of open programmable networks for a more complete QoS provisioning. Reservation gaps or tunnels are dynamically closed by means of a software agent approach that is flexibly deployed for an application oriented QoS support. Agents are dynamically located to such tunnels in order to monitor the tunnels, to provide feedback information in case of QoS violations, and to decide on possible compensating measures to be taken. Hermann de Meer, Antonio Puliafito, Jan-Peter Richter, Orazio Tomarchio |
ISCC | 1 |
| 1998 | QoS Management: A Model-Based ApproachabstractQuality of service (QoS) management is an important issue in today's high-speed distributed systems supporting multimedia applications. Most existing QoS management schemes usually just cope with technical issues of resource reservations and QoS guarantees, often completely neglecting revenue issues which are especially important for service providers in order to maximize their profit. The revenue to be expected does not only depend on the stream itself but also very much on stochastic events such as network failures or QoS violations. A QoS management system taking revenue issues and the possibly stochastic behavior of the environment into account thus seems to be superior to the existing ones. We show how controller programs for such enhanced QoS management systems can be developed based on a new kind of Petri nets, so-called controlled stochastic Petri nets. We show how to numerically analyze such models using a tool environment in order to obtain strategies for the QoS management system. Stefan Fischer 0001, Hermann de Meer |
MASCOTS | 2 |
| 1998 | Management of Quality of Service with Software AgentsabstractAs distributed multimedia applications become more widely diffused, systems for quality of service QoS management are increasingly essential. In this paper we present an architecture for distributed QoS management based on software agents. We discuss the advantages of using agent technology in a problem inherently distributed and complex such as QoS management. Besides introducing several negotiation and coordination techniques among agents as fundamental properties for QoS management, it is argued in favor of decision making based on analytical and simulative modeling techniques. Furthermore, design and implementation issues are discussed in detail and our Java-based platform for agent-based QoS management is introduced. Hermann de Meer, Antonio Puliafito, Orazio Tomarchio |
Cybern. Syst. | 1 |
| 1997 | Controlled Stochastic Petri NetsabstractA new framework for the extension of stochastic Petri nets (SPNs) is introduced. SPNs are extended by elements providing means for a dynamic optimization of performability measures. A new type of transition is defined, offering a feature for specification of controlled switching, called reconfiguration, from one marking of a SPN to another marking. Optional reconfiguration transitions are evaluated in order to optimize a specified reward or cost function. The result of an analysis is provided in the output of a numerical computation, in the form of a graphical presentation of an optimal, marking dependent control strategy and the resulting performability measure when applying the optimal strategy. The extended SPNs are called COSTPNs (Controlled Stochastic Petri Nets). COSTPNs are mapped on EMRMs (Extended Markov Reward Models) for a numerical analysis. Computational analysis is possible with algorithms adopted from Markov decision theory, including transient and stationary optimization. The scope of the paper is to introduce the new control structure for SPNs and to present an algorithm for the mapping of COSTPNs on EMRMs. Hermann de Meer, Oliver-Rainer Düsterhöft |
SRDS | 1 |
| 1994 | Guarded Repair of Dependable Systems
Hermann de Meer, Kishor S. Trivedi, Mario Dal Cin |
Theor. Comput. Sci. | 1 |