Antonio Muñoz 0001

dblp:15/4271-1 · also Antonio Muñoz Gallego · DBLP profile ↗
← Back
21ranked-venue papers
13as first author
5since 2021 · last 2025
0000-0002-6751-0625ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 12 · 8 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 first-authorSoftware engineering, systems software and programming languages · 2 · 1 first-authorHuman-computer interaction and ubiquitous computing · 2Artificial intelligence and machine learning · 1Computer networks · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1
YearPublicationVenuePosition
2025 Trusted Platform and Privacy Management in Cyber Physical Systems: The DUCA Framework
Antonio Muñoz 0001, Javier López 0001, Cristina Alcaraz, Fabio Martinelli
DBSec1
2023 A survey on the (in)security of trusted execution environments
abstract
As the number of security and privacy attacks continue to grow around the world, there is an ever increasing need to protect our personal devices. As a matter of fact, more and more manufactures are relying on Trusted Execution Environments (TEEs) to shield their devices. In particular, ARM TrustZone (TZ) is being widely used in numerous embedded devices, especially smartphones, and this technology is the basis for secure solutions both in industry and academia. However, as shown in this paper, TEE is not bullet-proof and it has been successfully attacked numerous times and in very different ways. To raise awareness among potential stakeholders interested in this technology, this paper provides an extensive analysis and categorization of existing vulnerabilities in TEEs and highlights the design flaws that led to them. The presented vulnerabilities, which are not only extracted from existing literature but also from publicly available exploits and databases, are accompanied by some effective countermeasures to reduce the likelihood of new attacks. The paper ends with some appealing challenges and open issues.
Antonio Muñoz 0001, Ruben Rios, Rodrigo Roman, Javier López 0001
Comput. Secur.1
2023 A Test Environment for Wireless Hacking in Domestic IoT Scenarios
abstract
Abstract Security is gaining importance in the daily life of every citizen. The advent of Internet of Things devices in our lives is changing our conception of being connected through a single device to a multiple connection in which the centre of connection is becoming the devices themselves. This conveys the attack vector for a potential attacker is exponentially increased. This paper presents how the concatenation of several attacks on communication protocols (WiFi, Bluetooth LE, GPS, 433 Mhz and NFC) can lead to undesired situations in a domestic environment. A comprehensive analysis of the protocols with the identification of their weaknesses is provided. Some relevant aspects of the whole attacking procedure have been presented to provide some relevant tips and countermeasures.
Antonio Muñoz 0001, Carmen Fernández Gago, Roberto López-Villa
Mob. Networks Appl.1
2022 Secure Mobile Agents on Embedded Boards: a TPM based solution
abstract
Security can be considered one of the essential aspects of any software system today. The current landscape is constantly evolving and new computing models are appearing at the same time as different attacks emerge. All this means that there is an increasing need for new security solutions. Among the different aspects that are opening up, this work focuses on the protection of sensitive data. In particular, an environment based on mobile agents is considered, which contains sensitive information that needs to be protected. To simulate an Internet of Things (IoT) environment, the agencies on which the agents run are deployed on Raspberry Pi devices.
Antonio Muñoz 0001
ARES1
2021 A Threat Model Analysis of a Mobile Agent-based system on Raspberry Pi
abstract
Security is considered one of the critical points in any computer system. Nowadays, a multitude of protocols and computer models are appearing along with new attacks increasing the need to develop solutions. This work focuses on the protection of the agent as well as the information it processes in a distributed environment throughout the network. Mobile agents move between various network-enabled platforms to process the information they manage. To simulate an environment based on the Internet of Things (IoT), a scheme has been presented which details the necessary steps to be carried out by the agent to perform the migration.
Iván García Aguilar, Antonio Muñoz 0001
ARES2
2018 Evolution Oriented Monitoring oriented to Security Properties for Cloud Applications
abstract
Internet is changing from an information space to a dynamic computing space. Data distribution and remotely accessible software services, dynamism, and autonomy are prime attributes. Cloud technology offers a powerful and fast growing approach to the provision of infrastructure (platform and software services) avoiding the high costs of owning, operating, and maintaining the computational infrastructures required for this purpose. Nevertheless, cloud technology still raises concerns regarding security, privacy, governance, and compliance of data and software services offered through it. Concerns are due to the difficulty to verify security properties of the different types of applications and services available through cloud technology, the uncertainty of their owners and users about the security of their services, and the applications based on them, once they are deployed and offered through a cloud. This work presents an innovative and novel evolution-oriented, cloud-specific monitoring model (including an architecture and a language) that aim at helping cloud application developers to design and monitor the behavior and functionality of their applications in a cloud environment.
Jamal Toutouh, Antonio Muñoz 0001, Sergio Nesmachnow
ARES2
2015 An immersive view approach by secure interactive multimedia proof-of-concept implementation
Pablo Antón, Antonio Maña, Antonio Muñoz 0001, Hristo Koshutanski
Multim. Tools Appl.3
2014 Software and Hardware Certification Techniques in a Combined Certification Model
abstract
Certification has been proved as an essential mechanism for achieving different security properties in new systems. However, it has important advantages; among which we highlighted the increasing in users trust by means of attesting security properties, but it is important to consider that in most of cases the system that is subject of certification is considered to be monolithic, and this feature implies that existing certification schemes do not provide support for dynamic changes of components as required in Cloud Computing running systems. One issue that has special importance of current certification schemes is that these refer to a particular version of the product or system, which derives that changes in the system structure require a process of recertification. This paper presents a solution based on a combination of software certification and hardware-based certification techniques. As a key element in our model we make use of the Trusted Computing functionalities as secure element to provide mechanisms for the hardware certification part. Likewise, our main goal is bringing the gap existing between the software certification and the means for hardware certification, in order to provide a solution for the whole system certification using Trusted Computing technology.
Antonio Muñoz 0001, Antonio Maña
SECRYPT1
2013 Bridging the GAP between Software Certification and Trusted Computing for Securing Cloud Computing
abstract
Despite the fact that software security certification has important advantages; among these we highlighted that it allows to increase users' trust by means of attesting security properties. However, in most of cases the system that is subject of certification is considered to be monolithic. This fact implies that existing certification schemes do not provide support for dynamic changes of components as required in Cloud Computing scenarios. In existing certification schemes certificates refer to a particular version of the product or system, changes in the system structure require a process of recertification. We propose a solution based on the combination of software certification techniques and hardware-based certification, as those provided by the Trusted Computing technology. Likewise, the main target of our approach is bringing the gap existing between the software certification and the means for hardware certification, in order to provide a solution for the whole system certification using Trusted Computing technology.
Antonio Muñoz 0001, Antonio Maña
SERVICES1
2012 A Performance-Oriented Monitoring System for Security Properties in Cloud Computing Applications
abstract
Security is considered one of the crucial issues for the widespread adoption of cloud computing. Despite all research done in preventive security for cloud computing, the high complexity and the interdependence of many software layers and infrastructures mean that in practice there are always chances for something going wrong. For this reason, there is a need to complement preventive security measures with reactive measures. Among these, monitoring is the most relevant approach. In this paper, we introduce a new and robust architecture for dynamic security monitoring and enforcement specially designed for cloud computing scenarios. Our solution is therefore a complete one including a three-layered architecture, a new language for expressing monitoring rules and a strategy based on the generation of a finite-state machine to improve the performance of the monitoring engine.
Antonio Muñoz 0001, Javier González 0001, Antonio Maña
Comput. J.1
2011 Facilitating the Use of TPM Technologies Using the Serenity Framework
Antonio Muñoz 0001, Antonio Maña
ATC1
2011 TPM-based protection for mobile agents
abstract
Abstract Mobile agent is a promising paradigm for emerging ubiquitous computing and ambient intelligent scenarios. We believe that security is the most important issue for the widespread deployment of applications based on mobile agent technology. Indeed, community agrees that without the proper security mechanisms, use of mobile agent‐based applications will be impossible. From our perspective, the security problem in mobile agents is the gathering of two subproblems; the problem of the agent protection and the problem of the host protection. This paper presents a hardware‐based mechanism focused on solving the protection of the agent problem, which is a well known problem named the ‘malicious host’. The solution presented in this paper bases its security in the trust and the security functionalities provided by the trusted platform module (TPM). Thus, migration process of mobile agents is protected when it actually takes place. A complete description of the secure migration can be found in the secure migration protocol section of this paper. Moreover, a validation of this protocol was performed by means of the AVISPA tool suite. Additionally, a first study about the use of an alternative protocol as the direct anonymous attestation protocol was done. Finally, the result of this work is the Secure Migration Library for agents (SecMiLiA), which is completely described in following sections. Copyright © 2010 John Wiley & Sons, Ltd.
Antonio Muñoz 0001, Antonio Maña
Secur. Commun. Networks1
2009 SecMiLiA: An Approach in the Agent Protection
abstract
Agent-based computing represents a promising paradigm for distributed computing. Unfortunately the lack of security is hindering the application of this paradigm in real world applications. The protection of malicious hosts is considered the most difficult security problem to solve in mobile agent systems. In this paper we provide a mechanism that aims to solve the problem of the malicious hosts. The core of our work is a new agent migration protocol based on the use of tamper resistant cryptographic hardware. Concretely, we base our work on the use of the Trusted Computing technology. Our protocol has been validated using the Automated Validation of Internet Security Protocols and Applications (AVISPA) model checking tool. As a result we have a library built on JADE that implements the secure migration for agents named Secure Migration Library for Agents (SecMiLiA). This library provides a friendly use of the Trusted Computing technology for agent based system developers.
Antonio Muñoz 0001, Antonio Maña, Daniel Serrano
ARES1
2009 AVISPA in the Validation of Ambient Intelligence Scenarios
abstract
Ambient Intelligence (AmI) refers to an environment that is sensitive, responsive, interconnected, contextualized, transparent, intelligent, and acting on behalf of humans. AmI environments impose some constraints in the connectivity framework, power computing as well as energy budget. This makes of AmI a significantly different case within distributed systems. The combination of heterogeneity, dynamism, sheer number of devices, along with the growing demands placed on software security and dependability, make application development vastly more complex. Also, the provision of security and dependability for applications becomes increasingly difficult to achieve with the existing security engineering mechanisms and tools. Furthermore the validation of these mechanisms is even a hard task. In this paper we present an approach to model dynamic changes in ambient intelligence scenarios using the Avispa (Automated Validation of Internet Security Protocols and Applications) model-checking tool suite. The main goal ofour approach consists on providing a starting point in the use of Formal Description Techniques (FDM) for AmI scenarios. The paper studies and assesses the suitability of the Avispa tool for security validation in Ambient Intelligent environments and proposes mechanisms to capture the dynamic context changes in these environments.
Antonio Muñoz 0001, Antonio Maña, Daniel Serrano
ARES1
2009 Agent Protection Based on the Use of Cryptographic Hardware
abstract
Mobile agents are processes that can migrate autonomously from new hosts. Despite of the huge number of fields of application of this technology, a lack in the security exists. The main approach of this work is based on the provision of a secure execution environment for mobile agents. Our approach is based on the idea of the trusted migration. This trusted migration is reached by means of the use of cryptographic hardware. Concretely, trusted computing module (TPM). Thus, we have designed and developed a specific protocol, which is the basis to build the solution. In order to build our solution on a robust basis, we have validated this protocol by means of a model checking tool called AVISPA. Finally, we built a library to provide access to TPM (trusted platform module) functionalities. The idea behind of this is based on the easy in using cryptographic hardware in the agent based systems development, disposing to agent developers of the security related tasks of their systems. The most relevant aspects of this library are described along this paper both at development stage of it and while we use it to develop a system based agent.
Antonio Muñoz 0001, Antonio Maña, Rajesh Harjani, Marioli Montenegro
COMPSAC (2)1
2009 The Role of Trusted Computing in the Secure Migration Library for Agents
abstract
Software agents are a promising computing paradigm. Scientific community has devoted important efforts to this field [1]. Indeed, several important applications exist based on this technology. Despite of their benefits, the lack of the appropriate security mechanisms for agent based systems represents a barrier for the widespread use of this technology. Additionally, the application of the current security techniques is not trivial for agent based system developers, which are usually not security experts. This paper presents a hardware based protection infrastructure that takes advantage of the recent advances in trusted hardware in order to solve the problem known as the malicious host in mobile agent systems. This infrastructure is composed of extensions to the JADE framework and the Trusted Computing technology. Additionally, the protocol used in this implementation has been validated using the Automated Validation of Internet Security Protocols and Applications (AVISPA) as we described in the paper.
Antonio Muñoz 0001, Antonio Maña, Daniel Serrano
RCIS1
2009 Security Patterns, Towards a Further Level
Beatriz Gallego-Nicasio, Antonio Muñoz 0001, Antonio Maña, Daniel Serrano
SECRYPT2
2007 Trusted Code Execution in JavaCard
Antonio Maña, Antonio Muñoz 0001
TrustBus2
2007 Towards Secure Agent Computing for Ubiquitous Computing and Ambient Intelligence
Antonio Maña, Antonio Muñoz 0001, Daniel Serrano
UIC2
2006 Towards Secure Ambient Intelligence Scenarios
Antonio Maña, Francisco Sánchez-Cid, Daniel Serrano, Antonio Muñoz 0001
SEKE4
2006 A Secure and Auto-configurable Environment for Mobile Agents in Ubiquitous Computing Scenarios
Javier López 0001, Antonio Maña, Antonio Muñoz 0001
UIC3