Gowri Sankar Ramachandran

dblp:125/2771 · DBLP profile ↗
← Back
41ranked-venue papers
6as first author
29since 2021 · last 2026
0000-0001-5944-1335ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 15 · 2 first-author · 11 since 2021Security and privacy · 10 · 1 first-author · 10 since 2021Software engineering, systems software and programming languages · 7 · 2 first-author · 7 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 4 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Human-computer interaction and ubiquitous computing · 3 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Systems, architecture and hardware · 1
YearPublicationVenuePosition
2026 On the Energy Cost of Post-Quantum Key Establishment in Wireless Low-Power Personal Area Networks
abstract
Post-Quantum Cryptography (PQC) creates payloads that strain the timing and energy budgets of Personal Area Networks. In post-quantum key exchange (PQKE), this causes severe fragmentation, prolonged radio activity, and high transmission overhead on low-power wireless devices. Prior work optimizes cryptographic computation but largely ignores communication cost. This paper separates computation and communication costs using Bluetooth Low Energy as a representative platform and validates them on real hardware. Results show communication often dominates PQKE energy, exceeding cryptographic cost. Efficient quantum-resilient pairing therefore requires coordinated protocol configuration and lower-layer optimization. This work provides developers a practical way to reason about PQC energy trade-offs and informs the evolution of PAN standards toward quantum-safe operation.
Gowri Sankar Ramachandran, Raja Jurdak
SenSys2
2026 A survey of privacy-preserving mechanisms on quality of experience in next-generation networks
Rodrigo Dutra Garcia, Gowri Sankar Ramachandran, Christian Esteve Rothenberg, Bhaskar Krishnamachari, Jo Ueyama
Comput. Networks2
2026 Secure safety inspection in the mining industry: A blockchain-based multi-robot approach
abstract
Abstract Industrial safety inspections, particularly in the mining sector and the industrial Internet of Things (IoT), increasingly rely on multi-robot systems to perform safety inspections and mapping in remote, confined, and hazardous areas inaccessible to humans. However, conventional multi-robot systems often depend on a central robot for data management, leading to vulnerabilities in fault tolerance and data replication during inspections. This centralized approach to inspection data management can result in single points of failure and potential trust disputes among stakeholders, including government agencies, industry representatives, and local communities. To address these challenges, this work proposes a system that combines blockchain technology with a Proof-of-Authority (PoA) consensus mechanism to improve the reliability and performance of multi-robot inspections. By leveraging blockchain’s inherent properties of fault tolerance, data replication, transparency, and immutability, our system mitigates the risks associated with centralized control in multi-robot operations in all safety inspection pipelines. We implemented and evaluated our proposed system using CoppeliaSIM, a widely used robot simulator, to validate its feasibility. The evaluation included multiple scenarios: normal operation, node failure, network latency simulations, and a comparison with a centralized system. The results show that our solution enhances fault tolerance and ensures data integrity in multi-robot systems. While the decentralized system has a higher average transaction latency (approximately 1.9 seconds) compared to the centralized system (1.42 milliseconds), it avoids the vulnerabilities linked to single points of failure. This approach not only enhances the reliability of industrial safety inspections but also provides secure data sharing among diverse stakeholders in the industrial safety ecosystem.
Rodrigo Dutra Garcia, Miguel Bragante Henriques, Saulo Neves Matos, Caetano Mazzoni Ranieri, André Luiz Maciel Cid, Gowri Sankar Ramachandran, Gustavo Pessin, Jo Ueyama
Peer Peer Netw. Appl.6
2026 DySec: A Machine Learning-Based Dynamic Analysis for Detecting Malicious Packages in PyPI Ecosystem
abstract
Malicious Python packages make software supply chains vulnerable by exploiting trust in open-source repositories like Python Package Index (PyPI). Lack of real-time behavioral monitoring makes metadata inspection and static code analysis inadequate against advanced attack strategies such as typosquatting, covert remote access activation, and dynamic payload generation. To address these challenges, we introduce DySec, a machine learning (ML)-based dynamic analysis framework for PyPI that uses eBPF kernel and user-level probes to monitor behaviors during package installation. By capturing 36 real-time features–including system calls, network traffic, resource usage, directory access, and installation patterns–DySec detects threats like typosquatting, covert remote access activation, dynamic payload generation, and multiphase attack malware. We developed a comprehensive dataset of 14,271 Python packages, including 7,127 malicious sample traces, by executing them in a controlled isolated environment. Experimental results demonstrate that DySec achieves 96% detection accuracy with an ML inference latency of <0.5s after dynamic feature extraction, reducing false negatives by 78.65% compared to static analysis and 82.24% compared to metadata analysis. During the evaluation, DySec flagged eleven packages that PyPI classified as benign. A manual analysis, including installation behavior inspection, confirmed six of them as malicious. These findings were reported to PyPI maintainers, resulting in the removal of four packages. DySec bridges the gap between reactive traditional methods and proactive, scalable threat mitigation in open-source ecosystems by uniquely detecting malicious install-time behaviors.
Sk. Tanzir Mehedi, Chadni Islam, Gowri Sankar Ramachandran, Raja Jurdak
IEEE Trans. Inf. Forensics Secur.3
2025 Optimizing Energy Costs in Blockchain Mining: A Multi-Source Approach
Daewoong Cho, Gowri Sankar Ramachandran, Raja Jurdak, Salil S. Kanhere
ICBC2
2025 QUT-DV25: A Dataset for Dynamic Analysis of Next-Gen Software Supply Chain Attacks
abstract
Securing software supply chains is a growing challenge due to the inadequacy of existing datasets in capturing the complexity of next-gen attacks, such as multiphase malware execution, remote access activation, and dynamic payload generation. Existing datasets, which rely on metadata inspection and static code analysis, are inadequate for detecting such attacks. This creates a critical gap because these datasets do not capture what happens during and after a package is installed. To address this gap, we present QUT-DV25, a dynamic analysis dataset specifically designed to support and advance research on detecting and mitigating supply chain attacks within the Python Package Index (PyPI) ecosystem. This dataset captures install and post-install-time traces from 14,271 Python packages, of which 7,127 are malicious. The packages are executed in an isolated sandbox environment using an extended Berkeley Packet Filter (eBPF) kernel and user-level probes. It captures 36 real-time features, that includes system calls, network traffic, resource usages, directory access patterns, dependency logs, and installation behaviors, enabling the study of next-gen attack vectors. ML analysis using the QUT-DV25 dataset identified four malicious PyPI packages previously labeled as benign, each with thousands of downloads. These packages deployed covert remote access and multi-phase payloads, were reported to PyPI maintainers, and subsequently removed. This highlights the practical value of QUT-DV25, as it outperforms reactive, metadata, and static datasets, offering a robust foundation for developing and benchmarking advanced threat detection within the evolving software supply chain ecosystem.
Sk. Tanzir Mehedi, Raja Jurdak, Chadni Islam, Gowri Sankar Ramachandran
NeurIPS4
2024 POSTER: Towards an Identity Authentication Layer in CBDC Networks using Self-Sovereign Identities
abstract
Central Bank Digital Currency (CBDC) is the digital form of a country’s fiat currency, based on Decentralized Ledger Technology (DLT). The increasing interest in CBDCs raises the concern of how to verify user’s identities for achieving regulatory demands, while maintaining user privacy in the CBDC Network. In this paper we explore Self-Sovereign Identities (SSI) as a way for users to have full control over credentials issued by trusted Financial Institutions in a CBDC Governance Framework. These credentials can then be used to generate privacy-preserving proofs by their holders to authenticate them in different service providers in the CBDC Network.
João Pedro Alonso Almeida, Rodrigo Dutra Garcia, Gowri Sankar Ramachandran, Jo Ueyama
ICBC3
2024 Decentralised Redactable Blockchain: A Privacy-Preserving Approach to Addressing Identity Tracing Challenges
abstract
Blockchain is an immutable and distributed ledger managed by all participants, enhancing data transparency and safety. Immutability is a crucial factor in ensuring data transparency and safety. However, there is a significant demand for redaction of the ledger due to security and privacy concerns. In this paper, we propose a redactable blockchain solution based on meta-transactions using zk-SNARK to improve anonymity in a decentralised manner. A one-time cryptographic key generation scheme, designed for a signature generation scheme, produces different keys for each transaction to enhance security and privacy by preventing identity tracing. We also employ zk-SNARK to hide the information of cryptographic keys and signatures. The modification history for each transaction is linked together, and the verification time is significantly short, around 10 msec, even when transactions have multiple modifications. Furthermore, we introduce a redaction fee scheme for transaction owners to maintain concise modification histories encouraging removal instead of modification to minimise the performance overhead associated with this redaction approach.
Jun Wook Heo, Gowri Sankar Ramachandran, Raja Jurdak
ICBC2
2024 Efficient URL and URI Compression
abstract
Web applications use Universal Resource Identifiers (URIs), interchangeably referred to as Uniform Resource Locators (URLs), to locate resources such as files and web pages on the Internet. Messaging services, firewalls, content distribution frameworks, event logs, databases and datasets store countless URIs. Due to the proliferation of the Internet, the number of URIs has increased rapidly, demanding significant storage. Several compression schemes are present in the literature for efficiently storing files on hard disks. However, existing compression schemes are designed for generic content, resulting in sub-optimal storage efficiency for standalone URIs. This paper presents a compression scheme specifically designed for URIs. Our contribution is three-fold: a) an empirical analysis of existing compression schemes for storing URIs, b) a design for a novel URI-focused compression scheme that improves on existing schemes and c) an adaptation of the well-known Huffman coding scheme to URIs using Natural Language Processing (NLP) to create a custom compression dictionary. Evaluation results using five million standalone URI strings show that our novel compression scheme improves storage efficiency by 18%. Furthermore, our customized Huffman coding compression scheme outperforms the standard content-agnostic Huffman technique. Our compression scheme reduces the storage space of a single instance of all URIs in existence – estimated to be more than 130 trillion – by more than 1.2 petabytes (PB) compared to the standard Huffman coding technique. Considering only unique instances of URIs, this bare minimum of 1.2 PB of hard disk savings worth approximately USD$24,000 can be saved, however, in practice, many orders of magnitude more may be possible.
Felix Savins, Kevin Saric, Gowri Sankar Ramachandran, Raja Jurdak
ICCCN3
2024 Towards a Portability Scheme for Decentralized Identifiers in Self-Sovereign Identities
abstract
There has been growing attention to the realm of Self-Sovereign Identities (SSI) in the past few years, with significant effort being put into the development of standards and specifications, such as Decentralized Identifiers (DIDs), to be in conformity with essential identity prerequisites such as decentralization, privacy and interoperability. However, the portability of DIDs is still an under-researched topic, even though it is a requirement of great importance in order to guarantee user autonomy amidst the numerous implementations being developed by the industry. In this paper, we explore the concept of portability of DIDs, highlighting how the current standards and protocols don't fully address this major point. We also define key requirements for addressing this feature, and discuss some major concerns on security and privacy that may emerge with the development of DID portability schemes.
João Pedro Alonso Almeida, Gowri Sankar Ramachandran, Paul Ashley, Raja Jurdak, Steven McCown, Jo Ueyama
PST2
2024 Efficient Data Security Using Predictions of File Availability on the Web
abstract
As we approach the physical limits of storage density, digital storage prices are no longer plummeting, despite the lingering belief that they still are. Meanwhile, data production continues to grow, making it harder to securely manage the data we produce. Typical digital storage media is often consumed by a small number of large files that are widely available on the web. If the availability of files on the web could be predicted, the choice between consuming local storage resources or simply redownloading the file in the future could be automated, thus increasing the efficiency of backup and encryption workflows. Through a large-scale analysis of hundreds of billions of crawl URLs spanning 8 years, as well as over 60 million HTTP header request responses from web servers, we explore the requirements and design of a framework for such predictions. It includes a data structure for efficiently representing the lateral/longitudinal availability of files and an extensible mathematical model for fast and adaptable prediction calculations. Additionally, we contribute novel observations about file availability on the web, including the identification of a period of initial volatility in their lifespans. Analysis indicates that a pool of 2,500TB of distributed, popular files is freely and predictably available to users, offering opportunities to reduce the storage and computational costs of both backup and encryption.
Kevin Saric, Gowri Sankar Ramachandran, Raja Jurdak, Surya Nepal
PST2
2024 Malicious Package Detection using Metadata Information
abstract
Protecting software supply chains from malicious packages is paramount in the evolving landscape of software development. Attacks on the software supply chain involve attackers injecting harmful software into commonly used packages or libraries in a software repository. For instance, JavaScript uses Node Package Manager (NPM), and Python uses Python Package Index (PyPi) as their respective package repositories. In the past, NPM has had vulnerabilities such as the event-stream incident, where a malicious package was introduced into a popular NPM package, potentially impacting a wide range of projects. As the integration of third-party packages becomes increasingly ubiquitous in modern software development, accelerating the creation and deployment of applications, the need for a robust detection mechanism has become critical. On the other hand, due to the sheer volume of new packages being released daily, the task of identifying malicious packages presents a significant challenge. To address this issue, in this paper, we introduce a metadata-based malicious package detection model, MeMPtec. This model extracts a set of features from package metadata information. These extracted features are classified as either easy-to-manipulate (ETM) or difficult-to-manipulate (DTM) features based on monotonicity and restricted control properties. By utilising these metadata features, not only do we improve the effectiveness of detecting malicious packages, but also we demonstrate its resistance to adversarial attacks in comparison with existing state-of-the-art. Our experiments indicate a significant reduction in both false positives (up to 97.56%) and false negatives (up to 91.86%).
Sajal Halder, Michael Bewong, Arash Mahboubi, Yinhao Jiang, Md. Rafiqul Islam 0001, Md Zahidul Islam 0001, Ryan H. L. Ip, M. Ejaz Ahmed, Gowri Sankar Ramachandran, Muhammad Ali Babar 0001
WWW9
2024 Hyperlink Hijacking: Exploiting Erroneous URL Links to Phantom Domains
abstract
Web users often follow hyperlinks hastily, expecting them to be correctly programmed. However, it is possible those links contain typos or other mistakes. By discovering active but erroneous hyperlinks, a malicious actor can spoof awebsite or service, impersonating the expected content and phishing private information. In typosquatting, misspellings of common domains are registered to exploit errors when users mistype a web address. Yet, no prior research has been dedicated to situations where the linking errors of web publishers (i.e. developers and content contributors) propagate to users. We hypothesize that these hijackable hyperlinks exist in large quantities with the potential to generate substantial traffic. Analyzing largescale crawls of the web using high-performance computing, we show the web currently contains active links to more than 572 000 dot-com domains that have never been registered, what we term phantom domains. Registering 51 of these, we see 88% of phantom domains exceeding the traffic of a control domain, with up to 10 times more visits. Our analysis shows that these links exist due to 17 common publisher error modes, with the phantom domains they point to free for anyone to purchase and exploit for under $20, representing a low barrier to entry for potential attackers.
Kevin Saric, Felix Savins, Gowri Sankar Ramachandran, Raja Jurdak, Surya Nepal
WWW3
2024 nPPoS: Non-interactive practical proof-of-storage for blockchain
abstract
Blockchain full nodes are pivotal for transaction availability, as they store the entire ledger, but verifying their storage integrity faces challenges from malicious remote storage attacks such as Sybil, outsourcing, and generation attacks. However, there is no suitable proof-of-storage solution for blockchain full nodes to ensure a healthy number of replicas of the ledger. Existing proof-of-storage solutions are designed for general-purpose settings where a data owner uses secret information to verify storage, rendering them unsuitable for blockchain where proof-of-storage must be fast, publicly verifiable, and data owner-agnostic. This paper introduces a decentralised and quantum-resistant solution named Non-interactive Practical Proof of Storage (nPPoS) with an asymmetric encoding and decoding scheme, for fast and secure PoStorage, and Zero-Knowledge Scalable Transparent Arguments of Knowledge (zk-STARKs), for public variability in blockchain full nodes. The algorithm with asymmetric times for encoding and decoding creates unique block replicas and corresponding proofs for each storage node to mitigate malicious remote attacks and minimise performance degradation. The intentional resource-intensive encoding deters attacks, while faster decoding minimises performance overhead. Through zk-STARKs, nPPoS achieves public verifiability enabling one-to-many verification for scalability, quantum resistance and decentralisation. It also introduces a two-phase randomisation technique and a time-weighted trustworthiness measurement for scalability and adaptability.
Jun Wook Heo, Gowri Sankar Ramachandran, Raja Jurdak
Blockchain Res. Appl.2
2024 An automated decision-making system employing complex networks and blockchain for the decentralized stock market
Rodrigo Dutra Garcia, Junio Cesar Ferreira, Lucas Zanotti, Gowri Sankar Ramachandran, Júlio Cezar Estrella, Jo Ueyama
Expert Syst. Appl.4
2024 Blockchain in inter-organizational collaboration: A privacy-preserving voting system for collective decision-making
Lívia Maria Bettini de Miranda, Rodrigo Dutra Garcia, Gowri Sankar Ramachandran, Jo Ueyama, Fábio Müller Guerrini
J. Inf. Secur. Appl.3
2023 PPoS : Practical Proof of Storage for Blockchain Full Nodes
abstract
Blockchain is a distributed and immutable ledger managed by all participants. The full nodes which store the entire ledger play an essential role in managing it in a transparent and decentralised manner. However, it is difficult to verify that full nodes store the entire ledger in their dedicated storage due to Sybil, outsourcing, or generation attacks. Existing work on proving storage for cloud computing and remote data storage applications has high latency for decryption, and its impact on decentralisation is unclear, rendering it impractical for use in blockchain. In this paper, we propose a decentralised Practical Proof of Storage (PPoS) solution for blockchain full nodes with asymmetric latencies for encryption and decryption, which introduces a chained encryption and decryption architecture. To generate a unique replica of a block, each full node performs encryption with its own address and a previously encrypted block, storing the unique block in its dedicated storage. In PPoS, encryption is expensive and time consuming, enabling it to detect outsourcing and generation attacks and to deter Sybil attacks. Simultaneously, decryption is about 25 times faster than encryption, resulting in minimal performance overhead. The proof process is also decentralised by randomly selecting provers, verifiers, and encrypted blocks. Our experiments use up to 720 real BitCoin blocks to evaluate the performance and quantify the decentralisation of PPoS. Our results show that PPoS's asymmetric design reduces decryption time 25-fold over existing approaches, while maintaining a high degree of decentralisation, confirming its suitability for blockchain full nodes.
Jun Wook Heo, Gowri Sankar Ramachandran, Raja Jurdak
ICBC2
2023 DeWS: Decentralized and Byzantine Fault-tolerant Web Services
abstract
Many real-world applications employ web service frameworks to provide application programming interface (API) services to businesses and end-consumers, following a client-server architecture. Service providers typically run a web server to deliver services to consumers. Here, service providers and consumers often belong to different organisations in applications such as supply chain management and logistics. In multi-stakeholder safety-critical and mission-critical applications, the centralised web server delivers services by executing computations upon receiving consumers' API requests. Such computations may fail due to crash or byzantine failures. The former happens because of hardware or infrastructure faults, while the latter happens because of a malicious actor. Note that the organisation that runs the web server may act dishonestly by running computations incorrectly for financial benefits, or an external attacker may compromise the web server without the knowledge of the infrastructure owner. As a result of these failures, the centralised web server is susceptible to single-point-of-failure issues. The organisation that runs the web server must be blindly trusted and does not provide transparency and auditability to its clients. We propose DeWS, a Decentralised and Byzantine Fault-tolerant Web Service framework, which overcomes these single-point-of-failure issues while delivering transparency and auditability through a blockchain-based ledger. The proof-of-concept implementation of DeWS using the Tendermint blockchain platform shows that our framework can tolerate byzantine failures at the cost of high latency. DeWS is the first Byzantine Fault-tolerant web service framework. It can support a shift towards more decentralised web services to provide safety assurances for safety-critical and mission-critical applications.
Gowri Sankar Ramachandran, Thi Thuy Linh Tran, Raja Jurdak
ICBC1
2023 FUSE: Fault Diagnosis and Suppression with eBPF for Microservices
Gowri Sankar Ramachandran, Lewyn McDonald, Raja Jurdak
ICSOC (1)1
2023 PPS: A Publish-Process-Subscribe Middleware for Predictive Supply Chains
Amir Jabbari, Gowri Sankar Ramachandran, Sidra Malik, Raja Jurdak
MobiQuitous (2)2
2022 A Blockchain-based Data Governance with Privacy and Provenance: a case study for e-Prescription
abstract
Real-world applications in healthcare and supply chain domains produce, exchange, and share data in a multi-stakeholder environment. Data owners want to control their data and privacy in such settings. On the other hand, data consumers demand methods to understand when, how, and who produced the data. These requirements necessitate data governance frameworks that guarantee data provenance, privacy protection, and consent management. We introduce a decentralized data governance framework based on blockchain technology and proxy re-encryption to let data owners control and track their data through privacy-enhancing and consent management mechanisms. Besides, our framework allows the data consumers to understand data lineage through a blockchain-based provenance mechanism. We have used Digital e-prescription as the use case since it has multiple stakeholders and sensitive data while enabling the medical fraternity to manage patients’ prescription data, involving patients as data owners, doctors, and pharmacists as data consumers. Our proof-of-concept implementation and evaluation results based on CosmWasm and pyUmbral PRE show that the proposed decentralized system guarantees transparency, privacy, and trust with minimal overhead.
Rodrigo Dutra Garcia, Gowri Sankar Ramachandran, Raja Jurdak, Jo Ueyama
ICBC2
2022 Poster Abstract: Trade-off Analysis of Inference Accuracy and Resource Usage for Energy-Positive Activity Recognition
abstract
Energy-positive activity recognition classifies human activities, including walking, running, and sitting, while harvesting kinetic energy from such activities. In this setting, the device's lifetime de-pends on the user's activity profile and the resources needed to run inference to classify activities. Thus, the selection of machine learning classification models for energy-positive activity recognition must consider both model's classification accuracy and energy con-sumption compared to the harvested energy from human activities. In this paper, we study the trade-off between accuracy and resource usage of a neural network model when different feature extraction techniques are used. Our results indicate that an on-board sched-uling algorithm can be used to dynamically switch between the optimal feature input tuned for accuracy and energy consumption.
Minh Tuan Tran, Muhammad Moid Sandhu, Sara Khalifa, Gowri Sankar Ramachandran, Raja Jurdak
IPSN4
2022 Exploiting smart contracts in PBFT-based blockchains: A case study in medical prescription system
abstract
Smart contracts allow application developers to automate business processes through a decentralized computation architecture.Contemporary blockchain platforms such as Ethereum and Hyperledger Fabric offer support for smart contracts through consensus mechanisms such as Proof-of-Work (PoW) or other types of transaction validation and ordering services.This article exploits smart contracts in the Byzantine Fault Tolerant (BFT) blockchain platforms.In particular, we explore Tendermint and Hyperledger Besu, BFT blockchain platforms, and apply them to a decentralized e-prescription case study to evaluate their effectiveness.We adopt Hyperledger Besu and Tendermint in this research, given that both are BFT-based blockchains.Also, it is noteworthy that smart contracts in BFT blockchain platforms such as Tendermint are not well established and not widely adopted yet.Our article empirically evaluates the performance of smart contracts in Tendermint and Hyperledger Besu using a decentralized medical prescription case study and compares their results with Ethereum, a PoW blockchain.Our results demonstrate that BFT blockchain platforms are efficient for multistakeholder applications such as e-prescription and supply chains.To the best of our knowledge, this is the first study investigating the implementation of smart contracts in BFT blockchain platforms, such as Tendermint and Hyperledger Besu.
Rodrigo Dutra Garcia, Gowri Sankar Ramachandran, Jo Ueyama
Comput. Networks2
2022 Blockchain-Aided and Privacy-Preserving Data Governance in Multi-Stakeholder Applications
abstract
Real-world applications in healthcare and supply chain domains produce, exchange, and share data in a multi-stakeholder environment. Data owners want to control their data and privacy in such settings. On the other hand, data consumers demand methods to understand when, how, and who produced the data. These requirements necessitate data governance frameworks that guarantee data provenance, privacy protection, consent management, and selective disclosure. We introduce a decentralized data governance framework based on blockchain technology, proxy re-encryption, and Boneh, Boyen, and Shacham (BBS) signatures to let data owners control, selectively share and track their data through privacy-enhancing, consent management, and selective disclosure mechanisms. Besides, our framework allows the data consumers to understand data lineage through a blockchain-based provenance mechanism. We use Digital medical e-prescription as the use case since it handles sensitive data in a multi-stakeholder environment while showing how the medical community can manage patients’ sensitive prescription data, involving patients as data owners, and doctors, and pharmacists as data consumers. Our proof-of-concept implementation and evaluation results based on CosmWasm, Hyperledger Besu, Ethereum, pyUmbral PRE, and BBS signatures show that the proposed decentralized system is platform-agnostic, scalable and guarantees a higher degree of transparency, privacy, and trust with minimal overhead.
Rodrigo Dutra Garcia, Gowri Sankar Ramachandran, Raja Jurdak, Jo Ueyama
IEEE Trans. Netw. Serv. Manag.2
2022 Blockchain Storage Optimisation With Multi-Level Distributed Caching
abstract
Distribution, security, and immutability have led to the great success of blockchain in many applications, while contributing to major increases in ledger size. The storage challenge is one of the major barriers to the adoption of blockchain in the Internet of Things (IoT), which consists of many resource constrained devices. In this paper, we propose Multi-Level Distributed Caching (MLDC) for blockchain storage optimisation which reduces data replication based on data access patterns in a decentralised manner. For storage optimisation of data-centric blockchains, MLDC introduces a hierarchical storage class (SC), in which every node is assigned to an SC with its own Access Frequency (AF) threshold based on node availability. To reduce the number of replications shared among participant nodes, each node in a SC continues to remove unaccessed data from local storage based on a threshold time determined by the AF threshold of the SC, while maintaining all block hashes for consistency. Eventually, all nodes in MLDC store the most frequently accessed data in their local storage, so MLDC effectively reduces the storage and query costs while minimising network overhead. We also analyse the security of MLDC and quantitatively evaluate its performance for both the uniform access and exponentially decaying access patterns. The evaluation was carried out on a representative blockchain simulator with 15 storage nodes. Our results from 11 hours of experiments producing 6667 blocks and 39997 transactions show good performance for MLDC. The results of the experimentation for the exponentially decaying assess pattern show that MLDC can reduce the total storage cost by 83% compared to conventional blockchain systems, while maintaining blockchain consistency and data availability with a slight increase in network overhead and query cost.
Jun Wook Heo, Gowri Sankar Ramachandran, Ali Dorri, Raja Jurdak
IEEE Trans. Netw. Serv. Manag.2
2022 AsTAR: Sustainable Energy Harvesting for the Internet of Things through Adaptive Task Scheduling
abstract
Battery-free Internet-of-Things devices equipped with energy harvesting hold the promise of extended operational lifetime, reduced maintenance costs, and lower environmental impact. Despite this clear potential, it remains complex to develop applications that deliver sustainable operation in the face of variable energy availability and dynamic energy demands. This article aims to reduce this complexity by introducing AsTAR, an energy-aware task scheduler that automatically adapts task execution rates to match available environmental energy. AsTAR enables the developer to prioritize tasks based upon their importance, energy consumption, or a weighted combination thereof. In contrast to prior approaches, AsTAR is autonomous and self-adaptive, requiring no a priori modeling of the environment or hardware platforms. We evaluate AsTAR based on its capability to efficiently deliver sustainable operation for multiple tasks on heterogeneous platforms under dynamic environmental conditions. Our evaluation shows that (1) comparing to conventional approaches, AsTAR guarantees Sustainability by maintaining a user-defined optimum level of charge, and (2) AsTAR reacts quickly to environmental and platform changes, and achieves Efficiency by allocating all the surplus resources following the developer-specified task priorities. (3) Last, the benefits of AsTAR are achieved with minimal performance overhead in terms of memory, computation, and energy.
Fan Yang 0051, Ashok Samraj Thangarajan, Gowri Sankar Ramachandran, Wouter Joosen, Danny Hughes 0001
ACM Trans. Sens. Networks3
2021 Towards a decentralized e-prescription system using smart contracts
abstract
Electronic prescription (e-Prescription) is a digital way to manage medical prescriptions and reduce inconsistencies in the communication between doctors, patients, and pharmacies. Smart contracts allow the automation of tasks and business rules in a decentralized architecture (i.e., without the need for an intermediary or central authority). Platforms such as Ethereum and Hyperledger Fabric support smart contracts development through a consensus mechanism such as Proof-of-Work or another criterion among the network's participating nodes. This paper explores Tendermint, a Byzantine Fault Tolerant (BFT) based consensus mechanism that has not yet been widely adopted for smart contracts platforms. We apply our devised model to the healthcare application domain, more precisely in the field of e-prescription, and our results demonstrate that smart contracts can be implemented on a BFT-based platform. To the best of our knowledge, this is the first study investigating the implementation of smart contracts in a BFT-based platform such as Tendermint. We exploit this domain as there can exist some conflicting interests of profit-taking. For example, pharmacists can increase the medication dosage above the one prescribed by doctors for profit-taking. Such a scenario can occur particularly in countries where healthcare is free of charge and offered as a public service (e.g., Brazil). We show that smart contracts in BFT-based blockchain can help in solving problems in these application scenarios. Finally, our two key contributions in this paper are two-fold: (i) exploit smart-contracts in BFT-based platforms where they (smart contracts) are not very established yet in the blockchain domain; (ii) provide a smart-contract-based e-prescription solution to reduce the costs (no need for a central authority) and scams particularly in countries where the medical service is free and public.
Rodrigo Dutra Garcia, Gabriel Augusto Zutião, Gowri Sankar Ramachandran, Jo Ueyama
CBMS3
2021 Blockchain-enabled Personalized Incentives for Sustainable Behavior in Smart Cities
abstract
Smart cities must adopt innovative technologies and strategies to boost existing sustainability solutions in order to fight climate change and reduce greenhouse gas emissions. We provide an overview of the existing work on the application of blockchain technologies in conjunction with other digital technologies such as IoT for incentivizing individuals and organizations to engage in more sustainable behaviors. We focus on three main areas in which these digital technologies can encourage actions aimed at reducing environmental impact: low-carbon transportation, energy efficiency, and waste diversion. Some notable examples are The Plastic Bank, ECO-Coin and SolarCoin. By analyzing case studies in which monetary and nonmonetary incentives have successfully demonstrated behavior change, we seek to understand the key elements for implementing blockchain-based solutions. We also identify key directions for future research in this area.
Ayten Kahya, Anusha Avyukt, Gowri Sankar Ramachandran, Bhaskar Krishnamachari
ICCCN3
2021 CONTAIN: Privacy-oriented Contact Tracing Protocols for Epidemics
Arvin Hekmati, Gowri Sankar Ramachandran, Bhaskar Krishnamachari
IM2
2020 Enhancing the Reliability of IoT Data Marketplaces through Security Validation of IoT Devices
abstract
IoT data marketplaces are being developed to help cities and communities create large scale IoT applications. Such data marketplaces let the IoT device owners sell their data to the application developers. Following this application development model, the application developers need not deploy their own IoT devices when developing IoT applications; instead, they can buy data from a data marketplace. In a marketplace-based IoT application, the application developers are making critical business and operation decisions using the data produced by seller's IoT devices. Under these circumstances, it is crucial to verify and validate the security of IoT devices.In this paper, we assess the security of IoT data marketplaces. In particular, we discuss what kind of vulnerabilities exist in IoT data marketplaces using the well-known STRIDE model, and present a security assessment and certification framework for IoT data marketplaces to help the device owners to examine the security vulnerabilities of their devices. Most importantly, our solution certifies the IoT devices when they connect to the data marketplace, which helps the application developers to make an informed decision when buying and consuming data from a data marketplace. To demonstrate the effectiveness of the proposed approach, we have developed a proof-of-concept using I3 (Intelligent IoT Integrator), which is an open-source IoT data marketplace developed at the University of Southern California, and IoTcube, which is a vulnerability detection toolkit developed by researchers at Korea University. Through this work, we show that it is possible to increase the reliability of a IoT data marketplace while not damaging the convenience of the users.
Yoonjong Na, Yejin Joo, Heejo Lee, Xiangchen Zhao, Kurian Karyakulam Sajan, Gowri Sankar Ramachandran, Bhaskar Krishnamachari
DCOSS6
2020 Context information sharing for the Internet of Things: A survey
Everton de Matos, Ramão Tiago Tiburski, Carlos Moratelli, Sergio Johann Filho, Leonardo A. Amaral, Gowri Sankar Ramachandran, Bhaskar Krishnamachari, Fabiano Hessel
Comput. Networks6
2019 AsTAR: Sustainable Battery Free Energy Harvesting for Heterogeneous Platforms and Dynamic Environments
Fan Yang 0051, Ashok Samraj Thangarajan, Wouter Joosen, Christophe Huygens, Danny Hughes 0001, Gowri Sankar Ramachandran, Bhaskar Krishnamachari
EWSN6
2019 An Immersive Visualization of Micro-climatic Data using USC AiR
abstract
The air pollution level is increasing globally at an alarming rate. In the last two decades, many cities have adopted policies to control the emission of pollutants to the atmosphere as well as to promote sustainable urban developments. However, many of these initiatives have concluded that a long term success would require investing in the environmental literacy of the general population. In this demonstration paper, we present USC AiR, a mobile application that translates the air quality sensor feeds from the CCITI smart campus testbed into augmented reality visualizations for the USC community. USC AiR also allows users to report alarming air quality conditions and recommend environmental interventions such as planting trees. We believe that the integration of augmented reality for air quality monitoring enables the citizens to become more engaged with the air quality data while encouraging them to contribute to the reduction of anthropogenic air pollutants.
Gowri Sankar Ramachandran, Biayna Bogosian, Kunal Vasudeva, Sushanth Ikshwaku Sriramaraju, Shubhesh Amidwar, Lavanya Malladi, Rohan Doddaiah Shylaja, Nishant Revur Bharath Kumar, Bhaskar Krishnamachari
MobiSys1
2019 Micropayments for Trusted Vehicular Services using MOTIVE
abstract
The connected and autonomous vehicles are expected to rely heavily on connectivity to exchange data and computation services with other vehicles and remote infrastructure including roadside units and other edge infrastructure to increase their immediate view, which leads to greater safety, coordination and more comfortable experience for their human occupants. In order for vehicles to obtain data, compute and other services from other vehicles or road-side infrastructure, it is important to be able to make micropayments for those services and for the services to run seamlessly despite the challenges posed by mobility and ephemeral interactions with a dynamic set of neighboring devices. We present MOTIVE, a trusted and decentralized framework that allows vehicles to make peer-to-peer micropayments for data, compute and other services obtained from other vehicles or road-side infrastructure within radio range. The framework utilizes distributed ledger technologies including smart contracts to enable autonomous operation and trusted interactions between vehicles and nearby entities.
Gowri Sankar Ramachandran, Pavas Navaney, Licheng Zheng, Martin Martinez, Bhaskar Krishnamachari
MobiSys1
2018 Self-managing Internet of Things
Danny Weyns, Gowri Sankar Ramachandran, Ritesh Kumar Singh
SOFSEM2
2017 CerberOS: A Resource-Secure OS for Sharing IoT Devices
Sven Akkermans, Wilfried Daniels, Gowri Sankar Ramachandran, Bruno Crispo, Danny Hughes 0001
EWSN3
2017 Selective Jamming of LoRaWAN using Commodity Hardware
abstract
Long range, low power networks are rapidly gaining acceptance in the Internet of Things (IoT) due to their ability to economically support long-range sensing and control applications while providing multi-year battery life. LoRa is a key example of this new class of network and is being deployed at large scale in several countries worldwide. As these networks move out of the lab and into the real world, they expose a large cyber-physical attack surface. Securing these networks is therefore both critical and urgent. This paper highlights security issues in LoRa and LoRaWAN that arise due to the choice of a robust but slow modulation type in the protocol. We exploit these issues to develop a suite of practical attacks based around selective jamming. These attacks are conducted and evaluated using commodity hardware. The paper concludes by suggesting a range of countermeasures that can be used to mitigate the attacks.
Emekcan Aras, Nicolas J. Small, Gowri Sankar Ramachandran, Stéphane Delbruel, Wouter Joosen, Danny Hughes 0001
MobiQuitous3
2015 Dawn: Dependable Networking Framework for Multimedia-enabled Internet-of-Things
abstract
Developing reliable application for the Internet-of-Things (IoT) is challenging due to heterogenous sensors and the resource-constraints of IoT platforms. Multimedia sensors such as cameras and microphones require significant memory and bandwidth. Typically, multimedia content results in bursty traffic. It is shown in the literature that the bursty traffic degrades the performance of the network. Hence, the regulation of bursty transmission is important for achieving high reliability. In this paper, we propose Dawn, a dependable networking framework for time-synchronised IoT platforms, which uses application meta-data to derive bandwidth requirements and uses this information to optimally allocate bandwidth for the network. Dawn regulates the transmission of bursty traffic generated by multimedia sensors, while performing admission control for dynamically added sensors. Dawn guarantees end-to-end reliability for heterogenous IoT applications with minimal energy consumption. Our preliminary evaluation results show that dawn is dependable and provides 100% reliability for dynamic multimedia-enabled IoT applications while increasing the network lifetime by up to 4 years.
Gowri Sankar Ramachandran, Nelson Matthys, Sam Michiels, Wouter Joosen, Danny Hughes 0001
MoMM1
2013 Analysis of Sensor Network Operating System Performance Throughout the Software Life Cycle
abstract
Wireless Sensor Networks (WSN) are evolving beyond research prototypes towards real world deployments in various application domains. While prior research has resulted in a range of operating systems and associated programming languages, a comprehensive empirical analysis of WSN operating systems is missing from the literature. We address this problem through an empirical study of all actively maintained WSN operating systems for the popular Tmote Sky / TelosB platform: TinyOS, Contiki and Lorien. Our analysis considers overhead at each stage of the software life cycle. During the development phase, we measure developer effort in terms of lines of application code. During the execution phase we measure energy consumption, flash footprint and RAM usage. During the reconfiguration phase we measure artefact size and developer effort in terms of number of configuration commands. Our results indicate distinct trade-offs in terms of development effort, application performance and reconfiguration performance. We find that TinyOS performs best for static applications with tight RAM constraints, while Contiki offers the lowest development effort and Lorien performs best in dynamic applications which require reconfiguration.
Gowri Sankar Ramachandran, Sam Michiels, Wouter Joosen, Danny Hughes 0001, Barry Porter
NCA1
2013 Energy aware software evolution for Wireless Sensor Networks
abstract
Wireless Sensor Networks (WSNs) are subject to high levels of dynamism arising from changing environmental conditions and application requirements. Reconfiguration allows software functionality to be optimized for current environmental conditions and supports software evolution to meet variable application requirements. Contemporary software modularization approaches for WSNs allow for software evolution at various granularities; from monolithic re-flashing of OS and application functionality, through replacement of complete applications, to the reconfiguration of individual software components. As the nodes that compose a WSN must typically operate for long periods on a single battery charge, estimating the energy cost of software evolution is critical. This paper contributes a generic model for calculating the energy cost of the reconfiguration in WSN. We have embedded this model in the LooCI middleware, resulting in the first energy aware reconfigurable component model for sensor networks. We evaluate our approach using two real-world WSN applications and find that (i.) our model accurately predicts the energy cost of reconfiguration and (ii.) component-based reconfiguration has a high initial cost, but provides energy savings during software evolution.
Danny Hughes 0001, Eduardo Canete, Wilfried Daniels, Gowri Sankar Ramachandran, James Meneghello, Nelson Matthys, Jef Maerien, Sam Michiels, Christophe Huygens, Wouter Joosen, Maarten Wijnants 0001, Wim Lamotte, Erik Hulsmans, Bart Lannoo, Ingrid Moerman
WOWMOM4
2012 Towards RTOS support for mixed time-triggered and event-triggered task sets
abstract
Many embedded systems have complex timing constraints and, at the same time, have flexibility requirements which prohibit offline planning of the entire system. To support a mixture of time-triggered and event-triggered tasks, some industrial systems deploy a real-time operating system (RTOS) with a table-driven dispatcher complemented with a preemptive scheduler to allocate free time slots to event-driven tasks. Rather than allocating dedicated time-slots to time-triggered tasks, we propose to dynamically re-allocate time-slots of time-triggered tasks within a pre-computed time range to maximize the available processing capacity for event-triggered tasks. Although the concept - called slotshifting - is not new, we are unaware of a commercial RTOS with such support. After identifying the mechanisms for an RTOS implementation of slotshifting, we discuss the run-time overheads for admitting aperiodic requests into the system1.
Martijn M. H. P. van den Heuvel, Reinder J. Bril, Johan J. Lukkien, Damir Isovic, Gowri Sankar Ramachandran
ETFA5