EDBT 2026 Demo / reviewers in the wild / expert
André Vasconcelos 0001
dblp:01/5247 · also Andre Ferreira Ferrao Couto e Vasconcelos
· DBLP profile ↗
13ranked-venue papers
1as first author
9since 2021 · last 2025
0000-0003-0038-7199ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 4 since 2021Software engineering, systems software and programming languages · 4 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | XChainWatcher: Identifying Anomalies in Cross-Chain BridgesabstractCross-chain bridges are a blockchain interoperability middleware that supports the transfer of assets and data across blockchains. However, several of these bridges have vulnerabilities that have caused 3.2 billion dollars in losses since May 2021. Some studies have revealed the existence of these vulnerabilities, but there is little quantitative research available, and there are no safeguard mechanisms to protect bridges from such attacks. Furthermore, no studies are available on the practices of cross-chain bridges that can cause financial losses. We propose XChainWatcher (Cross-Chain Watcher), a modular and extensible logic-driven anomaly detector for cross-chain bridges. It operates in three main phases: (1) decoding events and transactions from multiple blockchains, (2) building logic relations from the extracted data, and (3) evaluating these relations against a set of detection rules. Using XChainWatcher, we analyze data from two previously attacked bridges: the Ronin and Nomad bridges. XChainWatcher successfully identified the transactions that led to losses of $611M and $190M (USD) and surpassed the results obtained by a reputable security firm in the latter. We not only uncover successful attacks, but also reveal other anomalies, such as 37 cross-chain transactions (cctx) that should not have accepted, failed attempts to exploit Nomad, over $7.8M worth of tokens locked on one chain but never released on Ethereum, and $200K lost by users due to inadequate interaction with bridges. We provide the first open dataset of 81,000 cctxs across three blockchains, capturing more than $4.2B in token transfers. André Augusto, Rafael Belchior, Jonas Pfannschmidt, André Vasconcelos 0001, Miguel Correia 0001 |
Middleware | 4 |
| 2024 | Multi-Party Cross-Chain Asset TransfersabstractExisting interoperability mechanisms usually en-compass asset exchanges, asset transfers, and general data transfers. However, most of the solutions based on these mechanisms work only for pairs of permissionless blockchains, falling short in use cases that require more complex business relationships. Furthermore, contrary to existing legacy systems, there is little standardization for cross-domain communication, which multiple players in industry and academia are exploring. We present the Multi-Party Secure Asset Transfer Protocol (MP-SATP), a resilient multi-party asset transfer protocol built on top of the Secure Asset Transfer Protocol (SATP), which is being developed by theInternet Engineering Task Force(IETF). Furthermore, we enhance SATP’s crash recovery mechanism to improve the reliability and performance of our solution. Using MP-SATP, we explain how to perform N -to-N resilient asset transfers in permissioned environments by decoupling them into multiple 1-to-1 asset transfers. Our results show that the latency of the protocol is driven by the latency of the slowest 1-to-1 session and that the use of backup gateways avoids the overhead caused by rollbacks. André Augusto, Rafael Belchior, André Vasconcelos 0001, Miguel Correia 0001, Thomas Hardjono |
ICBC | 3 |
| 2024 | Towards a Standard Framework for Blockchain Interoperability: A Position PaperabstractDecentralized ledger technology (DLT) is becoming ubiquitous in today’s society. However, organizations need to connect their existing systems and processes to blockchains (centralized, decentralized) securely and reliably, sometimes also implying that they need to connect blockchains (decentralized, decentralized). This challenge is known as blockchain interoperability. We put the case forward that academia and industry must propose evaluation frameworks for blockchain interoperability solutions that address the three interoperability modes. Those are data transfers, asset transfers, and asset exchanges. In this position paper, we illustrate the remaining challenges of interoperability, focusing on the systematic evaluation of interoperability mechanisms based on the state of the art and our own experience. Our evaluation is a systematic online survey of 17 items targeting blockchain specialists. Our quantitative analysis shows that several interesting metrics can show promising directions for systematically evaluating integration solutions. Rafael Belchior, Sabrina Scuri, Nuno Nunes 0001, Thomas Hardjono, André Vasconcelos 0001 |
ICBC | 5 |
| 2024 | SoK: Security and Privacy of Blockchain InteroperabilityabstractRecent years have witnessed significant advancements in cross-chain technology. However, the field faces two pressing challenges. On the one hand, hacks on cross-chain bridges have led to monetary losses of around 3.1 billion USD, highlighting flaws in security models governing interoperability mechanisms and the ineffectiveness of incident response frameworks. On the other hand, users and bridge operators experience restricted privacy, which broadens the potential attack surface.In this paper, we present the most comprehensive study to date on the security and privacy of blockchain interoperability. We employ a systematic literature review, yielding a corpus of 212 relevant documents, including 58 academic papers and 154 gray literature documents, out of a pool of 531 results. We systematically categorize 57 interoperability solutions based on a novel security and privacy taxonomy. Our dataset, comprising academic research, disclosures from bug bounty programs, and audit reports, exposes 45 cross-chain vulnerabilities, 4 privacy leaks, and 92 mitigation strategies. Leveraging this data, we analyze 18 notable bridge hacks accounting for over 2.9 billion USD in losses, mapping them to the identified vulnerabilities.Our findings reveal that a substantial portion (65.8%) of stolen funds originates from projects secured by intermediary permissioned networks with unsecured cryptographic key operations. Privacy-wise, we demonstrate that achieving unlinkability in cross-chain transactions is contingent on the underlying ledgers providing some form of confidentiality. Our study offers 17 critical insights into the security and privacy of cross-chain systems. We pinpoint promising future research directions, underscoring the urgency of enhancing security and privacy efforts in cross-chain technology. The identified improvements have the potential to mitigate the financial risks associated with bridge hacks, fostering user trust in the blockchain ecosystem and, consequently, wider adoption. André Augusto, Rafael Belchior, Miguel Correia 0001, André Vasconcelos 0001, Luyao Zhang 0001, Thomas Hardjono |
SP | 4 |
| 2024 | BUNGEE: Dependable Blockchain Views for InteroperabilityabstractWith the evolution of distributed ledger technology (DLT), several blockchains that provide enhanced privacy guarantees and features, including Corda, Hyperledger Fabric, and Canton, are being increasingly adopted. These distributed ledgers only provide partial consistency, meaning that participants can observe the same ledger differently, i.e., observe some transactions but not others, providing higher levels of privacy to the end-user. Choosing privacy instead of transparency leads to delicate trade-offs that are difficult to manage during runtime, hampering the development of applications that depend on reasoning about shared state, e.g., asset transfers across blockchains. We propose using the concept of blockchain view (view) – an abstraction of the state a participant can access at a certain point to address this problem. Views allow us to systematically reason about either state partitions within the same DLT or an integrated view spanning across several DLTs. We introduce BUNGEE (Blockchain UNifier view GEnErator), the first DLT view generator, to allow capturing snapshots, constructing views from these snapshots, and merging views according to a set of rules specified by the view stakeholders. Creating views and operating views allows new applications built on top of dependable blockchain interoperability, such as stakeholder-centric snapshots for audits, cross-chain analysis, blockchain migration, and combined on-chain-off-chain analytics. Rafael Belchior, Limaris Torres, Jonas Pfannschmidt, André Vasconcelos 0001, Miguel Correia 0001 |
Distributed Ledger Technol. Res. Pract. | 4 |
| 2024 | Hephaestus: Modeling, Analysis, and Performance Evaluation of Cross-Chain TransactionsabstractEcosystems of multiple blockchains are now a reality. Multichain applications and protocols are perceived as necessary to enable scalability, privacy, and composability. Despite being a promising emerging area, we have been witnessing devastating attacks on cross-chain bridges that have caused billions of dollars in losses, and no apparent solution seems to emerge from the ongoing chaos. In this article, we present our contribution to minimizing bridge attacks, by monitoring across-chain model. In particular, we aggregatecross-chain eventsintocross-chain transactions, and verify if they follow a set ofcross-chain rules, which then generate a model. We proposeHephaestus, the first cross-chain model generator that captures the operational complexity of cross-chain applications.Hephaestuscan generate cross-chain models from local transactions in different ledgers, realizing arbitrary cross-chain use cases and allowing operators to monitor their applications. Monitoring helps identify outliers and malicious behavior, which can enable programmatically stopping attacks (“a circuit breaker”), including bridge hacks. We conduct a detailed evaluation of our system, where we implement a cross-chain bridge use case. Our experimental results show thatHephaestuscan process 600 cross-chain transactions in less than 5.5 s in an environment with two blockchains using sublinear storage, paving the way for more resilient bridge designs. Rafael Belchior, Peter Somogyvari, Jonas Pfannschmidt, André Vasconcelos 0001, Miguel Correia 0001 |
IEEE Trans. Reliab. | 4 |
| 2023 | CBDC Bridging between Hyperledger Fabric and Permissioned EVM-based BlockchainsabstractThe last few years have seen a steep increase in blockchain interoperability research. Most solutions connect public blockchains, where the main cross-chain use case is token transfer. By-design platform transparency, tamper resistance, and auditability make blockchains a candidate infrastructure for Central Bank Digital Currencies (CBDCs), but bridging CBDCs is an important missing piece in that scenario. In this paper, we leverage an asset transfer protocol, SATP, to define an extendable and dependable blockchain interoperability middleware that can bridge CBDC between Hyperledger Fabric and EVM-based permissioned blockchains. The key interoperation enabler in the solution is a shared asset definition enforced by both sides of the bridge, accompanied by a mapping between Fabric identities and Ethereum addresses for identity management. We implemented our design using Hyperledger Cacti. A preliminary evaluation shows that latency is more influenced by the ledgers than the bridging components. André Augusto, Rafael Belchior, Imre Kocsis, László Gönczy, André Vasconcelos 0001, Miguel Correia 0001 |
ICBC | 5 |
| 2023 | Do You Need a Distributed Ledger Technology Interoperability Solution?abstractEntrepreneurs, enterprises, and governments are using distributed ledger technology (DLT) as a component of complex information systems, and therefore interoperability capabilities are required. Interoperating DLTs enable network effects and synergies, and similarly to the rise of the Internet, it unlocks the full potential of the technology. However, due to the novelty of the area, interoperability mechanisms (IMs) are still not well understood, as interoperability is studied in silos. Consequently, choosing the proper IM for a use case is challenging. Our article has three contributions: first, we systematically study the research area of DLT interoperability by dissecting and analyzing previous work. We study the logical separation of interoperability layers, how a DLT can connect to others (connection mode), the object of interoperation (interoperation mode), and propose a new categorization for IMs. Second, we propose the first interoperability assessment for DLTs that systematically evaluates the interoperability degree of an IM. This framework allows comparing the potentiality, compatibility, and performance among solutions. Finally, we propose two decision models to assist in choosing an IM, considering different requirements. The first decision model assists in choosing the infrastructure of an IM, while the second decision model assists in choosing its functionality. Rafael Belchior, Luke Riley, Thomas Hardjono, André Vasconcelos 0001, Miguel Correia 0001 |
Distributed Ledger Technol. Res. Pract. | 4 |
| 2022 | Hermes: Fault-tolerant middleware for blockchain interoperability
Rafael Belchior, André Vasconcelos 0001, Miguel Correia 0001, Thomas Hardjono |
Future Gener. Comput. Syst. | 2 |
| 2020 | SSIBAC: Self-Sovereign Identity Based Access ControlabstractIneffective data management practices pose serious issues to individuals and companies, e.g., risk of identity theft and online exposure. Self-sovereign identity (SSI) is a new identity management approach that ensures users have full control of their personal data. In this work, we alleviate data breach and user privacy problems by showing how SSI can fit within the context of established enterprise identity and access management technologies. In light of recent endeavors, we explore the use of decentralized identifiers, verifiable credentials, and blockchains that support SSI. We propose Self-Sovereign Identity Based Access Control (SSIBAC), an access control model for cross-organization identity management. SSIBAC leverages conventional access control models and blockchain technology to provide decentralized authentication, followed by centralized authorization. The access control process does not require storing user sensitive data. A prototype was implemented and evaluated, processing 55,000 access control requests per second with a latency of 3 seconds. Rafael Belchior, Benedikt Putz, Günther Pernul, Miguel Correia 0001, André Vasconcelos 0001, Sérgio Guerreiro 0001 |
TrustCom | 5 |
| 2011 | Dynamic Business Transactions Control - An Ontological Example: Organizational Access Control with DEMO
Sérgio Guerreiro 0001, André Vasconcelos 0001, José M. Tribolet |
KEOD | 2 |
| 2010 | IT Architecture Automatic Verification: A Network Evidence-based ApproachabstractEnsuring constant synchronicity between the IT Architecture (ITA) and the actual Information Systems (IS) without the help of automatic tools is an intractable task, especially when taking into account modern IS' rapid evolution and growing complexity and distributed nature. We propose an automatic AS-IS ITA verification methodology and framework based on deep passive network traffic analysis and logical inference rules with the goal of inferring relevant facts about the actual ITA. The resulting knowledge is described according to a conceptual model designed for this purpose. We also propose an organization-independent mapping relationship between that ITA network evidence model and an ISA modeling framework (CEO Framework), at the technology (ITA) level, realized through a set of logical deduction rules. These rules formally define the conditions that must hold between the inferred evidence and a high-level ITA model (both represented in this inference system) in order to declare that model factual and in line with reality. It is the automatic execution of these rules that realizes the verification process that reports, as a result, all the significant detected discrepancies. The proposed concepts and methodology are implemented in a prototype applied to a case study in the leading Portuguese Telecom operator. The proposed solution was shown to be capable of successfully verifying the case study's ITA model as well as discovering new, undocumented, information through logical inference. António Alegria, André Vasconcelos 0001 |
RCIS | 2 |
| 2001 | A Framework for Modeling Strategy, Business Processes and Information SystemsabstractIn order to continuously improve its knowledge and to identify problems and possible solutions, an organization requires understanding of the way business is aligned with the organizational strategy and how information systems are supporting the business. The paper presents a framework for describing and associating organizational concepts at multiple levels of detail using three separate areas of concerns: goals and strategy, business processes, and information systems. The framework is presented as an extension to the Unified Modeling Language (UML) using a standard UML Profile. The framework concepts are illustrated by modeling the purchase and sales business operations of a retail store from the strategic, process and information systems viewpoints. André Vasconcelos 0001, Artur Caetano, João Neves 0005, Pedro Sinogas, Ricardo Mendes, José M. Tribolet |
EDOC | 1 |