EDBT 2026 Demo / reviewers in the wild / expert
Ivan Cibrario Bertolotti
dblp:05/5002
· DBLP profile ↗
31ranked-venue papers
6as first author
3since 2021 · last 2023
0000-0002-9607-9993ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 17 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 9 · 1 since 2021Software engineering, systems software and programming languages · 3 · 3 first-authorSecurity and privacy · 2 · 1 first-authorComputer networks · 1 · 1 first-authorTheory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Work in Progress: Schedulability Analysis of CAN and CAN FD AuthenticationabstractEnsuring the data integrity of messages transmitted over the Controller Area Network (CAN) bus and other vehicular networks is achieved through the implementation of cryptographic authentication protocols. However, these protocols raise concerns about a significant increase in response time due to the restrictions on CAN frame size and bandwidth. This paper presents a comprehensive analysis of the impact on response time of CAN and CAN Flexible Data-rate (CAN FD) messages with the implementation of cryptographic message authentication codes (MACs) and the periodic transmission of these codes. Our evaluation is based on a randomized schedulability experiment to provide insights into the overhead incurred by adding authentication to the frame payloads. Omolade Ikumapayi, Habeeb Olufowobi, Jeremy Daily, Ivan Cibrario Bertolotti, Gedare Bloom |
RTAS | 5 |
| 2022 | Open-source firewalls for industrial applications: a laboratory study of Linux IPFire behavior*abstractOpen-source software firewalls are becoming a viable solution to protect industrial networked systems and critical infrastructures. In fact, the adoption of technologies and devices originally conceived for general purpose computer networks and the consumer market has been proven to both reduce costs and enhance performance also in the industrial scenario. The goal of this paper is to start investigating the behavior of Linux IPFire in the light of its possible adoption in industrial applications and to provide a baseline for the development of techniques designed to improve the filtering capabilities in multi-firewall networks. Manuel Cheminod, Ivan Cibrario Bertolotti, Luca Durante, Lucia Seno, Adriano Valenzano |
IECON | 2 |
| 2022 | Improving performance and cyber-attack resilience in multi-firewall industrial networksabstractFirewalls are popular cyber-security countermea-sures that are increasingly used in industrial environments to protect the network infrastructure from attacks and malicious behavior. Unfortunately, they can also become inadvertent bot-tlenecks when the traffic load they have to filter grows larger. Among the different solutions that have been proposed to mitigate this aspect and improve performance of devices, rule migration looks appealing also in industrial multi-firewall systems because, differently from other techniques appeared in the literature, it neither requires interventions on the network topology nor it is based on non-standard packet formats and protocols. This paper is aimed at presenting some preliminary results about performance achievable with the rule migration approach, when it is applied to the popular Iptables open source firewall, in the light of its possible adoption in industrial application scenarios. Lucia Seno, Manuel Cheminod, Ivan Cibrario Bertolotti, Luca Durante, Adriano Valenzano |
WFCS | 3 |
| 2019 | Event Notification in CAN-Based Sensor NetworksabstractPreventive and reactive maintenance require the collection of an ever-increasing amount of information from industrial plants and other complex systems such as those based on robotized cells, a need that can be fulfilled by means of a suitable event notification mechanism. At the same time, timing and delivery reliability requirements in those scenarios are typically less demanding than those in other cases, thus enabling the adoption of best-effort notification approaches. This paper presents, evaluates, and compares some of those approaches, based on either standard Controller Area Network (CAN) messaging or a recently proposed protocol extension called CAN with eXtensible in-frame Reply (CAN XR). In the second case, the combined use of Bloom filters is also envisaged to increase flexibility. Results show that the latter approaches are advantageous in a range of event generation rates and network topologies of practical relevance. Gedare Bloom, Gianluca Cena, Ivan Cibrario Bertolotti, Nicolas Navet, Adriano Valenzano |
IEEE Trans. Ind. Informatics | 3 |
| 2017 | Towards seamless integration of N-version programming in model-based designabstractThe ever-growing complexity of present-day software systems raises new and more stringent requirements on their availability, pushing designers to make use of sophisticated fault tolerance techniques far beyond the areas they were traditionally conceived for, and bringing new challenges to both the modelling and implementation phases. In this paper, we propose a design pattern to model in a domain-specific language one of the prominent fault-tolerant techniques, namely the N-version programming. It can be integrated seamlessly into existing applications to enhance their functional correctness, while still preserving the timing characteristics, in particular the sampling times. Besides, it is also designed in a way to ease the automatic code generation. A counterpart of the same framework is also implemented in a lower-level programming language, for use when direct model execution is impractical, like in severely resource-limited embedded targets. Ivan Cibrario Bertolotti, Nicolas Navet |
ETFA | 2 |
| 2017 | Software patterns for fault injection in CPS engineeringabstractSoftware fault injection is a powerful technique to evaluate the robustness of an application and guide in the choice of fault-tolerant mechanisms. It however requires a lot of time and know-how to be properly implemented, which severely hinders its applicability. We believe software fault injection can be made more “affordable” by automating it and have it integrated within a model-driven engineering design flow. We first propose in this paper a framework supporting these objectives. Then, illustrating on the domain-specific language CPAL, we present injection patterns that can be embedded in the application code and discuss the types of faults each supports, as well as implementation issues. Nicolas Navet, Ivan Cibrario Bertolotti |
ETFA | 2 |
| 2017 | CAN With eXtensible In-Frame Reply: Protocol Definition and Prototype ImplementationabstractController area network (CAN) has been the de facto standard in the automotive industry for the past two decades. Recently, CAN with flexible data-rate (CAN FD) has been standardized, which achieves noticeably higher throughput. Further improvements are still possible for CAN, by exploiting its peculiar physical layer to carry out distributed operations among network nodes, implemented as atomic transactions mapped on quasi-conventional frame exchanges. In this paper, a proposal is made for an extension to the CAN protocol, termed CAN with eXtensible in-frame Reply (CAN XR), which enables upper protocol layers to define new custom services devoted to, e.g., network management, application-specific functions, and high-efficiency data transfer. The key point is that CAN XR retains full backward compatibility with CAN, therefore, there is no need to change the protocol specification once again. Gianluca Cena, Ivan Cibrario Bertolotti, Adriano Valenzano |
IEEE Trans. Ind. Informatics | 2 |
| 2016 | CAN XR: CAN with extensible in-frame ReplyabstractController Area Network (CAN) has been the de facto standard in the automotive industry for the past two decades, and recently CAN with flexible data-rate has been standardized, which achieves higher speed. Further improvements are possible by exploiting the peculiar physical layer of CAN to perform distributed operations among network nodes. In this paper a proposal is made for an extension to the CAN protocol, denoted CAN with eXtensible in-frame Reply (CAN XR), which enables upper protocol layers to define new custom services devoted to, e.g., network management, application-specific functions, and high-efficiency data transfer. Since CAN XR retains full backward compatibility with CAN FD, there is no need to change the protocol specification. Gianluca Cena, Ivan Cibrario Bertolotti, Adriano Valenzano |
INDIN | 2 |
| 2015 | A Mechanism to Prevent Stuff Bits in CAN for Achieving Jitterless CommunicationabstractThe bit stuffing mechanism adopted in controller area networks leads to unwanted jitter on frame reception times, which worsens timing accuracy, even if countermeasures are adopted to avoid contentions on the bus. Several solutions have been proposed so far for dealing with stuff bits in the payload of messages, but they are not effective for the cyclic redundancy check. In this paper, a mechanism is presented that prevents the occurrence of stuff bits in the whole frame completely. It makes the duration of frame transmissions fixed and, hence, it achieves very accurate reception times. An optimized codec has been implemented to demonstrate that this approach is feasible and can be profitably adopted in low-cost networked embedded systems with demanding timing constraints. Gianluca Cena, Ivan Cibrario Bertolotti, Adriano Valenzano |
IEEE Trans. Ind. Informatics | 2 |
| 2014 | System-level performance of an automation solution based on industry standardsabstractThe flexibility and reconfigurability requirements of factories and manufacturing plants of the future can be partially met by adopting technologies and solutions already available for testing and experimentation. Openness and adherence to international standards are becoming increasingly important in modern distributed production and automation systems, especially when they have to cope with ever-increasing product differentiations and short product lifecycles. However, the increased flexibility and openness should not come to detriment of the system real-time characteristics. This paper deals with a pilot mechatronic architecture for agile transport systems, which has been specifically developed to enable the study of the aforementioned aspects in the framework of the “Factory of the Future” Italian flagship project. In particular, the paper focuses on possible bottlenecks and pitfalls at the operating system and communication levels, and provides preliminary indications on how to address or mitigate them by means of solutions already available on the market. Andrea Ballarino, Alessandro Brusaferri, Marco Cereia, Ivan Cibrario Bertolotti, Luca Durante, Egidio Leo, Leonardo Nicolosi, Lucia Seno, Stefano Spinelli, Federico Tramarin, Adriano Valenzano, Stefano Vitturi |
ETFA | 4 |
| 2014 | Latency evaluation of a firewall for industrial networks based on the Tofino Industrial Security SolutionabstractNowadays, industrial control networks are no longer conceived as isolated systems, being them exposed to the same kind of security threats affecting traditional office and business networks. For this kind of systems, the main security requirement is availability, thus the protection measures used to secure industrial control networks must take into account also performance aspects, such as latency and jitters, usually not critical in traditional networks. For this reason, knowing the delays introduced by devices used to protect the network is of paramount importance, in order to evaluate whether the timing constraints of the communication are still satisfied. This paper presents an experimental evaluation of the communication latency introduced by a firewall for industrial control networks built around the Tofino Industrial Security Solution. Experiments have been carried out in three main working conditions of the firewall, that is when 1) it is plugged in the network with all the protection modules disabled (decommissioned mode); 2) it implements basic security policies only; 3) it adopts complex filtering mechanisms allowing the deep inspection of Modbus TCP packets. Marco Cereia, Ivan Cibrario Bertolotti, Luca Durante, Adriano Valenzano |
ETFA | 2 |
| 2013 | Software-based assessment of the synchronization and error handling behavior of a real CAN controllerabstractAlthough the Controller Area Network (CAN) technology is very mature, the behavior of real CAN controllers under marginal operating conditions is still of practical interest as CAN is being deployed in a variety of application domains. In this paper, we propose a test software architecture able to extensively investigate the reaction of a typical CAN controller when subject to various kinds of error and different timing scenarios. Both the analysis technique and the test software use a black-box approach and do not require any modification of, or access to, the internal structure of the controller itself. They are therefore readily applicable with low effort to different hardware. Possible applications include diagnostic and reliability analysis tools for CAN. Gianluca Cena, Ivan Cibrario Bertolotti, Adriano Valenzano |
ETFA | 2 |
| 2013 | Fixed-Length Payload Encoding for Low-Jitter Controller Area Network CommunicationabstractThe controller area network (CAN) bit stuffing mechanism, albeit essential to ensure proper receiver clock synchronization, introduces a significant, payload-dependent jitter on message response times, which may worsen the timing accuracy of a networked control system. Accordingly, several approaches to overcome this issue have been discussed in literature. This paper presents a novel software payload encoding scheme, which is able to guarantee that no stuff bits will ever be added to the data field by the CAN controller during transmission and, hence, lessens jitters considerably. Particular care has been put in its practical implementation and its subsequent evaluation to show how the simplicity and inherent high performance of the scheme make it suitable even for low-cost, embedded architectures. Gianluca Cena, Ivan Cibrario Bertolotti, Adriano Valenzano |
IEEE Trans. Ind. Informatics | 2 |
| 2012 | Modeling Emergency Response Plans with Coloured Petri Nets
Manuel Cheminod, Ivan Cibrario Bertolotti, Luca Durante, Adriano Valenzano |
CRITIS | 2 |
| 2012 | Performance comparison of mechanisms to reduce bit stuffing jitters in controller area networksabstractBit stuffing in CAN is likely to cause jitters on message reception that, in specific cases where timing accuracy is relevant, may worsen the quality of the control algorithm noticeably. Several solutions have appeared in the past years that are aimed to tackle this issue, which are based on a suitable encoding of the payload of the message carried out in s/w by the transmitting node. In this paper, two efficient approaches are considered, namely XOR masking and 8B9B encoding, and their performance evaluated by means of both theoretical analysis and experimental campaigns. In particular, jitter reduction capability and encoding efficiency were taken into account and compared to the case when plain CAN is adopted. Gianluca Cena, Ivan Cibrario Bertolotti, Adriano Valenzano |
ETFA | 2 |
| 2012 | Performance evaluation and improvement of the CPU-CAN controller interface for low-jitter communicationabstractThe effectiveness and quality of several distributed control loops are heavily affected by the ability to reduce jitters. This goal can hardly be achieved without understanding all possible causes that can introduce time fluctuations in the communication path between the processor, running the control algorithms, and the (remote) peripheral devices. This is because any of them, in fact, may worsen the timing accuracy of the system as a whole. After the most well-known sources of jitters are put under control, other aspects become more and more important for the overall behavior of the system. This paper tackles the problem of time fluctuations introduced by the interface between the Central Processing Unit (CPU) and the CAN controller in a typical off-the-shelf, single-chip microcontroller and shows why and how they should be considered and handled carefully. Gianluca Cena, Ivan Cibrario Bertolotti, Adriano Valenzano |
ETFA | 2 |
| 2012 | Evaluation of EtherCAT Distributed Clock PerformanceabstractEtherCAT is a real-time Ethernet protocol conceived explicitly for industrial applications. It is characterized by high communication efficiency, which permits control loops to be closed with short cycle times, and is provided with a suitable mechanism, known as distributed clock (DC), that enables synchronized operations to take place across the controlled system. These features can be profitably adopted, for instance, to support motion control applications. In this paper, the performance of the DC mechanism is evaluated by means of a thorough campaign of experimental measurements carried out on a real network setup. A number of factors have been taken into account that can affect accuracy and precision, and their effects studied in depth. Gianluca Cena, Ivan Cibrario Bertolotti, Stefano Scanzio, Adriano Valenzano, Claudio Zunino |
IEEE Trans. Ind. Informatics | 2 |
| 2011 | Real-time performance of an open-source protocol stack for low-cost, embedded systemsabstractModern embedded devices often require some form of network connectivity, to offer features like remote configuration, diagnostics, and firmware updates. The availability of open-source, lightweight, and portable protocol stacks, makes this goal relatively easy to accomplish, even on very low-cost devices. Interoperability is guaranteed because they implement, at the very least, the TCP/IP and UDP/IP protocols on an Ethernet interface. However, these applications are quite undemanding for what concerns real-time and, for this reason, little is known about the real-time characteristics of the underlying protocol stacks. This paper shows that an open-source protocol stack, when properly coupled with a real-time operating system and an Ethernet interface, can indeed reach an acceptable performance level and thus support an Ethernet-based field bus protocol on the device side. Ivan Cibrario Bertolotti |
ETFA | 1 |
| 2011 | Performance of a Real-Time EtherCAT Master Under LinuxabstractThe adoption of open-source operating systems for the execution of real-time applications is gaining popularity, even in the networked control systems domain, due to cost and flexibility reasons. However, as opposed to their commercial counterparts, the actual performance level to be expected from them is still little known and may often depend on the kind of real-time extension being used, its configuration, and the overall software load of the system, including best-effort components. In this paper, an open-source EtherCAT master supported by a popular real-time extension for Linux, the RT Patch, is thoroughly evaluated with long-term measurements, which build confidence on the suitability of the proposed approach for real-world applications. Special attention is devoted to the unexpected, adverse effect that some best-effort components, for instance, graphics applications, may have on the overall real-time characteristics of the system. For reference, the proposed approach is also compared with RTAI, a more traditional and well-known real-time extension for Linux already in use for demanding applications. Marco Cereia, Ivan Cibrario Bertolotti, Stefano Scanzio |
IEEE Trans. Ind. Informatics | 2 |
| 2010 | A software implementation of IEEE 1588 on RTAI/RTnet platformsabstractAt present, an increasing number of distributed control systems are based on platforms made up of conventional PCs running open-source real-time operating systems. Often, the need arises in these systems to have networked devices supporting synchronized operations. In this paper, an inexpensive solution is introduced, described, implemented and evaluated that relies on standard software and protocols such as RTAI, RTnet and IEEE 1588. The main goals of this architecture are reducing design and development costs, ensuring adequate synchronization accuracy, and easing the porting of control applications to different H/W and S/W configurations. Gianluca Cena, Marco Cereia, Ivan Cibrario Bertolotti, Stefano Scanzio, Adriano Valenzano, Claudio Zunino |
ETFA | 3 |
| 2009 | Experimental Evaluation of the Linux RT Patch for Real-time ApplicationsabstractThe possibility of using Linux as underlying operating system for real-time applications has received considerable attention by industry due to several definite advantages, such as the lack of royalties and the availability of rich and programmer-friendly software development frameworks. In addition, the real-time capabilities of the Linux kernel have recently been enhanced considerably through the development of the Linux RT Patch. This paper evaluates the real-time characteristics of the Linux kernel with the RT Patch installed, in order to help the designer understand what sort of real-time performance is to be expected, and decide whether it is adequate or not for a given class of applications. Wolfgang Betz, Marco Cereia, Ivan Cibrario Bertolotti |
ETFA | 3 |
| 2009 | A High-performance CAN-like Arbitration Scheme for EtherCATabstractEtherCAT is a popular Ethernet-based solution conceived for connecting devices at the shop floor in industrial environments. Even though it features very high communication efficiency, that permits thousands of I/O points to be periodically exchanged between controlling devices and decentralized periphery with cycle times well below 1 ms, it is not able to cope in a proper way with event-driven systems, where lots of devices may be producing asynchronous information in a sporadic and unpredictable way. In this paper, some modifications to the basic EtherCAT protocol are proposed which enable CAN-like arbitrations to take place in such networks, so as to achieve a true priority-based access scheme. Gianluca Cena, Ivan Cibrario Bertolotti, Adriano Valenzano, Claudio Zunino |
ETFA | 2 |
| 2009 | Detecting Chains of Vulnerabilities in Industrial NetworksabstractIn modern factories, personal computers are starting to replace traditional programmable logic controllers, due to cost and flexibility reasons, and also because their operating systems now support programming environments even suitable for demanding real-time applications. These characteristics, as well as the ready availability of many software packages covering any kind of needs, have made the introduction of PC-based devices at the factory field level especially attractive. However, this approach has a profound influence on the extent of threats that a factory computing infrastructure shall be prepared to deal with. In fact, industrial personal computers share the same kinds of vulnerabilities with their office automation counterparts. Then, their introduction increases the risk of cyber-attacks. As the complexity of the network grows, the problem rapidly becomes hard to tackle by hand, due to the subtle and unforeseen interactions that may occur among apparently unrelated vulnerabilities, thus bearing the focus on the full automation of the analysis. Going into this direction, this paper presents a software tool that, given an accurate and machine-readable description of vulnerabilities, detects whether or not they are of concern and evaluates consequences in the context of a factory network. Manuel Cheminod, Ivan Cibrario Bertolotti, Luca Durante, Paolo Maggi, Davide Pozza, Riccardo Sisto, Adriano Valenzano |
IEEE Trans. Ind. Informatics | 2 |
| 2008 | Efficient representation of the attacker's knowledge in cryptographic protocols analysisabstractAbstract This paper addresses the problem of representing the intruder’s knowledge in the formal verification of cryptographic protocols, whose main challenges are to represent the intruder’s knowledge efficiently and without artificial limitations on the structure and size of messages. The new knowledge representation strategy proposed in this paper achieves both goals and leads to practical implementation because it is incrementally computable and is easily amenable to work with various term representation languages. In addition, it handles associative and commutative term composition operators, thus going beyond the free term algebra framework. An extensive computational complexity analysis of the proposed representation strategy is included in the paper. Ivan Cibrario Bertolotti, Luca Durante, Riccardo Sisto, Adriano Valenzano |
Formal Aspects Comput. | 1 |
| 2007 | Reasoning about communication latencies in real WLANsabstractLarge diffusion of wireless communications is a trend that will soon involve industrial environments, too, and in particular those applications where granting limited response times is of utmost importance. This paper analyzes the impact of a number of causes, besides the medium access technique, on the performance of real 802.11g networks. In particular, the extent to which beacon frames and traffic on nearby channels can decrease the communication performance is taken into account, as well as the effect of the adapter's and access point's overheads on frame transmission latencies. Gianluca Cena, Ivan Cibrario Bertolotti, Adriano Valenzano, Claudio Zunino |
ETFA | 2 |
| 2007 | Evaluation of Response Times in Industrial WLANsabstractThe adoption of wireless communication technologies in industrial environments for supporting (soft) real-time applications heavily depends on the ability to grant bounded response times for messages, at least from a probabilistic point of view. This aspect is particularly important in factory automation systems, where response times are considered much more significant than other performance indices, such as throughput, that are usually considered in different application areas. The ever-increasing availability on the market of products and solutions based on the IEEE 802.11 standard and the introduction of the 802.11e amendment for enhancing the quality of service (QoS) and prioritizing traffic make this kind of communication technology interesting also for adoption in (loosely coupled) distributed control systems. This paper reports on some experimental measures and the related analysis that have been carried out on real 802.11g/e networks for better understanding the statistical distribution of response times and can be of help in characterizing these solutions when used to support noncritical real-time traffic. Gianluca Cena, Ivan Cibrario Bertolotti, Adriano Valenzano, Claudio Zunino |
IEEE Trans. Ind. Informatics | 2 |
| 2005 | Automatic Detection of Attacks on Cryptographic Protocols: A Case Study
Ivan Cibrario Bertolotti, Luca Durante, Riccardo Sisto, Adriano Valenzano |
DIMVA | 1 |
| 2005 | Modelling CANopen communications according to the socket paradigmabstractAt present, a number of platforms are becoming available for the implementation of intelligent field devices, which are based on low-cost microcontrollers and open-source real-time operating systems. To take full benefit from these platforms and to ease the task of developing and porting the application software, a standard interface has to be provided to cope with communication facilities. In this paper an application programming interface for CANopen is introduced that relies on the well-known socket paradigm. Despite its inherent simplicity, it is very flexible and offers the programmer all the functionalities foreseen by the CANopen specification Gianluca Cena, Ivan Cibrario Bertolotti, Adriano Valenzano |
ETFA | 2 |
| 2004 | Exploiting Symmetries for Testing Equivalence in the Spi Calculus
Ivan Cibrario Bertolotti, Luca Durante, Riccardo Sisto, Adriano Valenzano |
ATVA | 1 |
| 2003 | Introducing Commutative and Associative Operators in Cryptographic Protocol Analysis
Ivan Cibrario Bertolotti, Luca Durante, Riccardo Sisto, Adriano Valenzano |
FORTE | 1 |
| 2003 | A New Knowledge Representation Strategy for Cryptographic Protocol Analysis
Ivan Cibrario Bertolotti, Luca Durante, Riccardo Sisto, Adriano Valenzano |
TACAS | 1 |