Andrea Melis 0001

dblp:184/7813 · DBLP profile ↗
← Back
28ranked-venue papers
3as first author
23since 2021 · last 2026
0000-0002-0101-2551ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 1 first-author · 7 since 2021Computer networks · 7 · 2 first-author · 5 since 2021Software engineering, systems software and programming languages · 5 · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
YearPublicationVenuePosition
2026 In-Network Security for Smart Buildings BACnet Communications
abstract
Building Automation and Control Systems increasingly rely on BACnet/IP to interconnect heterogeneous field devices and supervisory applications. Although BACnet Secure Connect provides end-to-end protection via TLS, its adoption in smart-building deployments is hindered by the limited capabilities of legacy devices and the additional communication overhead. In this paper, we propose an in-network security approach for BACnet/IP communications based on two P4-programmable boundary switches that transparently provide confidentiality, integrity, and authentication across exposed network segments without requiring modifications to BACnet endpoints. The solution combines AES-based encryption with support for 128-, 192-, and 256-bit keys and SHA-256 HMAC protection. The proposed approach is validated on a virtualized testbed that we developed on top of the NIST Net-Zero Energy Residential Test Facility (NZERTF) HVAC reference scenario. Experimental results show that the proposed in-network approach achieves a mean RTT between 1393μs and 1541μs, thus reducing latency by 22.8%−30.2%with respect to BACnet/SC (1995 μ s), while remaining above plaintext BACnet/IP (951 μs) by 46.5%−62.0%.
Lorenzo Rinieri, Antonio Iacobelli, Andrea Melis 0001, Roberto Girau, Franco Callegati, Marco Prandini
NetSoft3
2026 P4ICS: P4 in-network security for Industrial Control Systems networks
abstract
Industrial Control Systems (ICS) are increasingly interconnected with enterprise IT and cloud services, yet their communications remain largely unprotected due to the limited adoption of Transport Layer Security (TLS) and other cryptographic standards. Legacy devices often lack the resources to support TLS, and operators face performance constraints and complex certificate management. To address this gap, we present P4ICS, a framework that provides confidentiality, integrity, and replay protection for industrial protocols by shifting security functions from endpoints into P4-programmable switches. P4ICS transparently parses and protects Modbus, DNP3, EtherNet/IP, and MQTT traffic, establishing switch-to-switch encrypted tunnels that secure untrusted network segments while preserving interoperability with legacy equipment. Our evaluation on an ad hoc physical testbed shows that P4ICS introduces only a modest overhead compared to plaintext communication, while consistently outperforming TLS, reducing delays by about 12% for Modbus and DNP3, 43% for EtherNet/IP, and 47% for MQTT. By leveraging in-network computing, P4ICS delivers a practical and deployable security layer for Industry 4.0 communications, narrowing the gap between available secure protocol profiles and their limited use in operational ICS.
Lorenzo Rinieri, Andrea Melis 0001, Roberto Girau, Giovanni Pau 0001, Marco Prandini, Franco Callegati
Comput. Networks2
2026 SAFARI: A Scalable Air-gapped Framework for Automated Ransomware Investigation
Tommaso Compagnucci, Saverio Giallorenzo, Andrea Melis 0001, Simone Melloni, Marco Prandini, Alessandro Vannini
Comput. Secur.3
2026 PLC-Defuser: Detecting hidden Ladder Logic Bombs in PLCs via Control Flow Graph and model checking
abstract
Industrial Control Systems (ICS) are responsible for the operations of critical industrial infrastructures such as water treatment facilities and nuclear plants. To control sensors and actuators, ICSs rely on Programmable Logic Controllers (PLCs), which have become the target of an increasing number of cyberattacks, particularly since the appearance of Stuxnet. In response, numerous anomaly detection methods have been proposed in the literature to identify stealthy attacks targeting ICS sensors and actuators. However, no existing method specifically addresses the detection of Ladder Logic Bombs (LLBs), a class of attacks designed to disrupt the normal operation of PLCs. In this work, we introduce PLC-Defuser, an automated framework specifically tailored to the task of LLB detection. PLC-Defuser first employs static analysis through Control Flow Graphs (CFG) to identify possible LLB triggers within the PLC control logic. It then performs model checking to formally verify whether the identified suspicious triggers activate malicious LLBs. We evaluate PLC-Defuser considering a simplified version of the Secure Water Treatment System (SWaT), for which we built a dataset of PLC programs containing 150 malicious and 150 legitimate samples. Our results demonstrate that PLC-Defuser effectively protects industrial plants without producing false positives and achieves an average execution time of less than 0.5 s.
Lorenzo Rinieri, Antonio Iacobelli, Andrea Melis 0001, Marco Prandini, Franco Callegati
Comput. Secur.3
2026 Choreography-defined networks: Concepts and a case study on AI-based attack detection
abstract
Modern network infrastructures increasingly rely on Software-Defined Networking (SDN) and Network Function Virtualisation (NFV) to achieve flexibility, scalability, and efficiency. While these paradigms facilitate the deployment of Cloud-native Network Functions (CNF), they lack tools for high-level programming and guarantees on correct multi-component compositions. We introduce Choreography-Defined Networking (CDN), a methodology that applies choreographic programming to the specification and implementation of SDN compositions. In CDN, developers write a single global choreography that describes interactions among CNFs and a compiler generates endpoint code that coordinate them as specified in the choreography. CDN delivers correctness-by-construction guarantees – including deadlock freedom and communication-type safety – while eliminating the need for a centralised orchestrator, replaced by direct, parallel communication among CNFs. To evaluate our methodology, we use CDN to design and implement a case study on a distributed, AI-enhanced SDN composition for volumetric attack detection and mitigation, in which four CNFs collaboratively analyse traffic using volumetric anomaly inspection, machine-learning classification, and signature matching. We compare this CDN implementation against two SDN baselines: a classical controller-driven chain and a hybrid solution that repurposes network traffic as a management channel. Experiments across four representative attack scenarios show that the CDN approach reduces mean decision latency by approximately 15% over both baselines, while generating up to 80% less management traffic. These results confirm that CDN allows to raise the abstraction level at which one writes distributed SDN compositions without compromising – actually improving – runtime performance in real-world network deployments.
Saverio Giallorenzo, Jacopo Mauro, Andrea Melis 0001, Fabrizio Montesi, Marco Peressotti, Marco Prandini
Inf. Softw. Technol.3
2025 SAFARI: A Scalable Air-Gapped Framework for Automated Ransomware Investigation
abstract
Ransomware poses a significant threat to individuals and organisations, creating a need for tools to investigate its behaviour and the effectiveness of mitigations. To address this need, we present SAFARI, an open-source framework designed for safe and efficient ransomware analysis. SAFARI’s design emphasises scalability, air-gapped security, and automation, democratising access to safe ransomware investigation tools and fostering collaborative efforts. SAFARI leverages virtualisation, Infrastructure-as-Code, and OS-agnostic task automation to create isolated environments for controlled ransomware execution and analysis. The framework enables researchers to profile ransomware behaviour and evaluate mitigation strategies through automated, reproducible experiments. We demonstrate SAFARI’s capabilities by building a proof-of-concept implementation and using it to conduct two case studies: the first analyses seven ransomware strains – including WannaCry and LockBit – to identify their encryption patterns and file-targeting strategies; the second evaluates Ranflood, a countermeasure tool, against five dangerous strains. Our results provide insights into ransomware behaviour and the effectiveness of countermeasures, showcasing SAFARI’s potential to advance ransomware research and defence development.
Tommaso Compagnucci, Franco Callegati, Saverio Giallorenzo, Andrea Melis 0001, Simone Melloni, Alessandro Vannini
SEC (1)4
2025 Supporting Resilient, Ethical, and Verifiable Anonymous Identities Through Blockchains
abstract
In recent years, anonymity on the internet has come under intense scrutiny for enabling criminal behaviors like cyberbullying, disinformation, child exploitation, and illicit financial activities. Nevertheless, strong advocates highlight its importance as a protective space for legitimate and ethical actions that individuals may prefer to keep separate from their real-world identities. This paper presents a protocol for authenticated anonymity, enabling anonymous usage that remains unlinkable to real identities unless criminal activity is detected. Blockchain offers a robust and secure framework to manage these needs. While existing solutions — e.g., self-sovereign identities — grant users full control over their disclosure, they lack proper accountability. To address this limitation, the proposed protocol employs a blockchain-driven mechanism that supports anonymous yet verifiable identities. De-anonymization is achieved exclusively through multi-party consensus on the blockchain, t riggered by explicit and non-repudiable requests. We provide the formal mathematical model of the protocol and offer some evaluations of its robustness and fault tolerance, even under large-scale identity management scenarios.
Alberto De Marchi, Lorenzo Gigli, Andrea Melis 0001, Luca Sciullo, Fabio Vitali
SECRYPT3
2025 Time-Sensitive Networking Digital Twin for STRIDE-based security testing
abstract
Time-sensitive networking is set to play a pivotal role in the evolution of modern industrial and 5G networks, enabling them to meet the strictest communication requirements for guaranteed low latency and high reliability. Given the critical and complex environments in which TSN will be deployed, such as industrial automation, autonomous systems, and mission-critical applications, ensuring robust protection against security threats becomes an essential design consideration. The inherent low-latency and deterministic characteristics of TSN, while beneficial for performance, also introduce unique vulnerabilities that attackers could exploit. Consequently, safeguarding time-sensitive networks is fundamental to their successful implementation and reliability in real-world applications. In this paper, we present a flexible and reconfigurable Digital Twin for TSN protocol validation and security testing. Its deployment in different and heterogeneous testing scenarios is fully automated via the Infrastructure as Code approach. Our proposed TSN Digital Twin employs advanced virtualization technologies and network emulation tools to replicate the stringent requirements of TSN. It also implements advanced Linux queuing disciplines to emulate TSN scheduling and traffic shaping. Finally, we assess the potential for adaptability of the proposed architecture for TSN security testing by simulating two attack scenarios derived from the TSN STRIDE threat model.
Andrea Melis 0001, Andrea Giovine, Lorenzo Rinieri
EURASIP J. Inf. Secur.1
2025 Investigating operational technology attacks as code
abstract
Abstract Industrial Operational Technology (OT) environments face escalating cybersecurity challenges due to increasing interconnectedness, device heterogeneity, and the integration of legacy systems not designed with modern security requirements. Operators struggle with security validation in OT settings due to the complexity of static reasoning across multilayered architectures and the impracticality of in-production testing, which risks operational disruptions and safety hazards. To address these limitations, we propose SAFARI, a framework that leverages the concepts of digital twin and cyber range to enable Security-Investigation-as-Code for OT environments, automating the creation, deployment, and security testing of faithful OT architecture replicas. SAFARI uses technologies such as Terraform, Proxmox SDN, and MITRE Caldera to provide scalable, reproducible security assessment capabilities while maintaining complete air-gapping for safe malware testing. We demonstrate SAFARI’s effectiveness through a comprehensive case study examining three industrial network architectures exhibiting increasing segmentation. Our results show that SAFARI successfully automates complex security scenarios, enables regression testing of architectural refinements, and provides quantifiable insights into attack resistance improvements. The framework represents a significant advancement in OT security testing methodology, offering security operators a practical tool for systematic vulnerability assessment and architectural validation without compromising operational continuity.
Franco Callegati, Saverio Giallorenzo, Andrea Melis 0001, Simone Melloni, Marco Prandini, Alessandro Vannini
Empir. Softw. Eng.3
2024 On the Trade-Off Between Privacy and Information Quality in Location Based Services
abstract
Location based services (LBS) are leveraged in everyday services and applications, as they can provide contextual and relevant information for the user needs. These services require the location of the user to be sent along with other relevant information, to provide the data in return that is relevant to the sent position. Although this opens up exciting scenarios for users, it has also been studied since it encompasses several potential privacy issues, which range from the re-identification of the user to the discovery of habits and routines. In this work, we present a study on the tradeoff between the information quality obtained from an LBS and the location precision sent by the user. Our results indicate that by sending out queries with imprecise location enhances the privacy of the users, while still providing a satisfactory quality of information.
Francesco Apollonio, Luca Bedogni, Giacomo Gori, Andrea Melis 0001, Marco Prandini
CCNC4
2024 Wi-Fi Sensing for Human Identification Through ESP32 Devices: An Experimental Study
abstract
Recent studies explore the possibility of detecting events in a room via Wi-Fi Sensing. This practice exploits the interaction between waves carrying Wi-Fi signals and the elements present in an environment. These interactions are called Channel State Information (CSI) and can be analyzed and exploited to infer information about the environment, such as “device-free” Human Activity Recognition, Human Identification, and more. Considering identification, we recently saw an increasing trend in the usage of low-end devices such as ESP32. Being small and low-power, they are cheap and versatile, however, the quality of the collected data is inferior. In this work, we use state-of-the-art tools to perform Human Identification using the ESP32. Software is created to act as an interface between the collected data and the algorithms suitable for Wi-Fi Sensing. To evaluate the final design, we performed a data collection in a controlled environment. The experiments show an accuracy of 95% in distinguishing two users while 74% in distinzuishing three.
Fabio Gaiba, Luca Bedogni, Giacomo Gori, Andrea Melis 0001, Marco Prandini
CCNC4
2024 Choreography-Defined Networks: A Case Study on DoS Mitigation
Saverio Giallorenzo, Jacopo Mauro, Andrea Melis 0001, Fabrizio Montesi, Marco Peressotti, Marco Prandini
ICSOC (2)3
2024 In-Network Encryption for Secure Industrial Control Systems Communications
abstract
In this manuscript, we present a solution to provide secure communication in Industry 4.0 environments. Legacy ICS components that do not have encryption capabilities will be able to communicate using secured channels by means of P4 programmable switches that implement security in the data plane. We will compare the proposed solution with TLS end-to-end encryption, showing that it offers similar performance with no need to interact with the end hosts.
Lorenzo Rinieri, Antonio Iacobelli, Amir Al Sadi, Andrea Melis 0001, Franco Callegati, Marco Prandini
NetSoft4
2024 Leveraging Data Plane Programmability to enhance service orchestration at the edge: A focus on industrial security
abstract
The Edge Computing paradigm is increasingly gaining traction in modern telecommunication scenarios, as it enables the offloading of computational tasks from end devices to a variety of nodes located in close proximity to them. This approach is essential for meeting the ever-stricter Quality of Service requirements imposed by modern applications. Concurrently, the advent of Data Plane Programmability allows for unmatched flexibility on the networking plane, supporting processing of multiple protocols in a logically centralized fashion with simple in-line computation, and offering the possibility to offload additional services to networking equipment. Reaping those benefits necessitates heedful management of resources and infrastructure. This, in turn, calls for the introduction of a service orchestration entity, capable of taking advantage of device heterogeneity to enable efficient and swift service provisioning. This work delves into the potential of introducing an orchestration system able to cope with the challenges of offloading security tasks at the Edge. This effort involves developing and implementing novel architectural components that capitalize on the heterogeneous nature of the Edge infrastructure as well as of the Programmable Data Plane as a potential tool for service offloading. To establish the feasibility and performance of this approach, an industrial scenario is considered, where the integrity of data from legacy devices must be ensured. Following an evaluation of the hashing performance of the Programmable Data Plane in comparison to general-purpose devices, a simulation study is conducted on the overall orchestration system, demonstrating the viability of the proposed approach.
Gaetano Francesco Pittalà, Lorenzo Rinieri, Amir Al Sadi, Gianluca Davoli, Andrea Melis 0001, Marco Prandini, Walter Cerroni
Comput. Networks5
2024 Unleashing Dynamic Pipeline Reconfiguration of P4 Switches for Efficient Network Monitoring
abstract
As it is happening in many fields that need efficient and effective classification of data, Machine Learning (ML) is becoming increasingly popular in network management and monitoring. In general we can say that ML algorithms are complex, therefore better suited for execution in the centralized control plane of modern networks, but are also heavily reliant on data, that are necessarily collected in the data plane. The inevitable consequence is that may arise the need to transfer lots of data from the data plane to the control plane, with the risk to cause congestion on the control communication channel. This may turn into a major drawback, since congestion on the control channel may have a significant impact on network operations. Therefore it is of paramount importance to design systems capable of minimizing the interaction between data and control planes while ensuring good monitoring performance. The most recent generation of data plane programmable switches supporting the P4 language can help mitigate this problem by preprocessing traffic data at line rate. In this manuscript we follow this approach and propose P4RTHENON: an architecture to distill in the data plane the relevant information to be mirrored to the control plane, where complex analysis can be performed. P4RTHENON leverages the P4-native support for runtime data plane pipeline reconfiguration to minimize the interaction between data and control planes while ensuring good monitoring performance. We tested our scheme on the volumetric DDoS detection use case: P4RTHENON reduces the volume of exchanged data by almost 75% compared to a pure control-plane-based solution, guarantees low memory consumption in the data plane, and does not degrade the overall DDoS detection capabilities.
Amir Al Sadi, Marco Savi, Andrea Melis 0001, Marco Prandini, Franco Callegati
IEEE Trans. Netw. Serv. Manag.3
2023 Towards the Creation of Interdisciplinary Consumer-Oriented Security Metrics
abstract
Information systems are evolving: IoT devices and Cyber-physical systems (CPS) impact on the security of assets and people in the real world. Old cybersecurity approaches, which focused on seeing humans “as a problem”, could be substitute by new paradigms of seeing humans “as a solution”. Therefore, consumers awareness will be one of the building blocks, as well as initiative that aim to create a set of standardized security metrics that can evaluate the security of systems. In order to do that, researchers need to study which are the essential factors that our future metrics should focus on. In this paper we analyzed this problem over CPS while assuming the consumer perspective. We summarize the state of the art in security metrics and advocate the need for a research effort aimed at taking the field to a new level of formal soundness and practical usability by considering interdisciplinary implications on cybersecurity.
Giacomo Gori, Andrea Melis 0001, Davide Berardi, Marco Prandini, Amir Al Sadi, Franco Callegati
CCNC2
2023 A Structured Approach to Insider Threat Monitoring for Offensive Security Teams
abstract
In many countries, government agencies resort to third parties to acquire security services of many kinds, including Red Team operations to test the effectiveness of own defenses mechanisms. Absolute trust is a key requirement, lest a potentially devastating finding be exploited by a treacherous Red Team against the same entity which commissioned the operation, or sold to its adversaries. In our endeavour as a joint private-academic initiative to address this peculiar market, we observed that a structured approach to this issue is much less common than we would have expected. In this work, we outline the process we are devising to offer customers a verified environment, but integrating it with an evidence-based proof of their correct behavior during the operation, striving to solve the “Quis custodiet ipsos custodes” struggle in an offensive setting.
Amir Al Sadi, Davide Berardi, Franco Callegati, Andrea Melis 0001, Marco Prandini, Luca Tolomei
CCNC4
2023 Poster: Continual Network Learning
abstract
We make a case for in-network Continual Learning as a solution for seamless adaptation to evolving network conditions without forgetting past experiences. We propose implementing Active Learning-based selective data filtering in the data plane, allowing for data-efficient continual updates. We explore relevant challenges and propose future research directions.
Nicola Di Cicco, Amir Al Sadi, Chiara Grasselli, Andrea Melis 0001, Gianni Antichi, Massimo Tornatore
SIGCOMM4
2023 Data Flooding against Ransomware: Concepts and Implementations
abstract
Ransomware is one of the most infamous kinds of malware, particularly the “crypto” subclass, which encrypts users’ files, asking for some monetary ransom in exchange for the decryption key. Recently, crypto-ransomware grew into a scourge for enterprises and governmental institutions. The most recent and impactful cases include an oil company in the US, an international Danish shipping company, and many hospitals and health departments in Europe. Attacks result in production lockdowns, shipping delays, and even risks to human lives. To contrast ransomware attacks (crypto, in particular), we propose a family of solutions, called Data Flooding against Ransomware, tackling the main phases of detection, mitigation, and restoration, based on a mix of honeypots, resource contention, and moving target defence. These solutions hinge on detecting and contrasting the action of ransomware by flooding specific locations (e.g., the attack location, sensible folders, etc.) of the victim’s disk with files. Besides the abstract definition of this family of solutions, we present an open-source tool that implements the mitigation and restoration phases, called Ranflood. In particular, Ranflood supports three flooding strategies, apt for different attack scenarios. At its core, Ranflood buys time for the user to counteract the attack, e.g., to access an unresponsive, attacked server and shut it down manually. We benchmark the efficacy of Ranflood by performing a thorough evaluation over 6 crypto-ransomware (e.g., WannaCry, LockBit) for a total of 78 different attack scenarios, showing that Ranflood consistently lowers the amount of files lost to encryption.
Davide Berardi, Saverio Giallorenzo, Andrea Melis 0001, Simone Melloni, Loris Onori, Marco Prandini
Comput. Secur.3
2023 Time sensitive networking security: issues of precision time protocol and its implementation
abstract
Abstract Time Sensitive Networking (TSN) will be an integral component of industrial networking. Time synchronization in TSN is provided by the IEEE-1588, Precision Time Protocol (PTP) protocol. The standard, dating back to 2008, marginally addresses security aspects, notably not encompassing the frames designed for management purposes (Type Length Values or TLVs). In this work we show that the TLVs can be abused by an attacker to reconfigure, manipulate, or shut down time synchronization. The effects of such an attack can be serious, ranging from interruption of operations to actual unintended behavior of industrial devices, possibly resulting in physical damages or even harm to operators. The paper analyzes the root causes of this vulnerability, and provides concrete examples of attacks leveraging it to de-synchronize the clocks, showing that they can succeed with limited resources, realistically available to a malicious actor.
Davide Berardi, Nils Ole Tippenhauer, Andrea Melis 0001, Marco Prandini, Franco Callegati
Cybersecur.3
2022 Metrics for Cyber-Physical Security: a call to action
abstract
Cyber-physical systems, by definition, have an effect on assets and people in the real world. Security factors, thus, should play a central role in every decision regarding their deployment and configuration, but this is possible only if said factors are properly defined and can be objectively measured. In this paper, we summarize the state of the art in security metrics, and advocate the need for a research effort aimed at taking the field to a new level of formal soundness and practical usability.
Giacomo Gori, Andrea Melis 0001, Lorenzo Rinieri, Marco Prandini, Amir Al Sadi, Franco Callegati
ISNCC2
2022 An Industrial Network Digital Twin for enhanced security of Cyber-Physical Systems
abstract
In this manuscript we describe the implementation of a digital twin for industrial networks. The aim is to provide a playground for cyber-security analysis and validation without the risk of interfering to any extent with the real cyber-physical system and its environment. The proposed implementation methodology provides a very high degree of automation, following the telecom-oriented NFV-MANO approach, and shows that different network topologies may be activated in a matter of just a few minutes. Each topology may then be used as a sort of cyber-range for the experimentation of possible attacks and validation of related countermeasures.
Chiara Grasselli, Andrea Melis 0001, Lorenzo Rinieri, Davide Berardi, Giacomo Gori, Amir Al Sadi
ISNCC2
2021 P-SCOR: Integration of Constraint Programming Orchestration and Programmable Data Plane
abstract
In this manuscript we present an original implementation of network management functions in the context of Software Defined Networking. We demonstrate a full integration of an artificial intelligence driven management, an SDN control plane, and a programmable data plane. Constraint Programming is used to implement a management operating system that accepts high level specifications, via a northbound interface, in terms of operational objective and directives. These are translated in technology-specific constraints and directives for the SDN control plane, leveraging the programmable data plane, which is enriched with functionalities suited to feed data that enable the most effective operation of the “intelligent” control plane, by exploiting the P4 language.
Andrea Melis 0001, Siamak Layeghy, Davide Berardi, Marius Portmann, Marco Prandini, Franco Callegati
IEEE Trans. Netw. Serv. Manag.1
2020 TechNETium: Atomic Predicates and Model Driven Development to Verify Security Network Policies
abstract
Fifth-generation (5G) networks will deliver unprecedented levels of quality of service for online gaming and multimedia-rich social interaction, providing virtual environments optimized for vertical applications through innovative approaches to physical resource management. These techniques must consider security aspects in all phases and at every layer. Trusted communications between individuals and reliable platforms running services for social good depend on the resiliency to network-level attacks such as hijacking and denial-of-service. The verification of topological properties represents a well-suited approach to address these issues in a 5G environment. This paper illustrates moves from formal methods existing in literature, namely atomic predicates (AP) and header space analysis (HSA). It describes a method of integrating AP in Software Defined Network architectures, achieving the same expressive power as HSA without its performance hit, to make topology verification viable for real-time security applications.
Davide Berardi, Franco Callegati, Andrea Melis 0001, Marco Prandini
CCNC3
2019 Gamifying cultural experiences across the urban environment
Catia Prandi, Andrea Melis 0001, Marco Prandini, Giovanni Delnevo, Lorenzo Monti, Silvia Mirri, Paola Salomoni
Multim. Tools Appl.2
2018 Cloud-of-Things meets Mobility-as-a-Service: An insider threat perspective
Franco Callegati, Saverio Giallorenzo, Andrea Melis 0001, Marco Prandini
Comput. Secur.3
2018 Integrating Personalized and Accessible Itineraries in MaaS Ecosystems Through Microservices
Andrea Melis 0001, Silvia Mirri, Catia Prandi, Marco Prandini, Paola Salomoni, Franco Callegati
Mob. Networks Appl.1
2017 I want to ride my bicycle: A microservice-based use case for a MaaS architecture
abstract
This work presents a use case on multimodal urban paths in a smart mobility context. The proposed solution builds on the experience already matured and developed by the authors in different fields: crowdsourcing and sensing done by users to gather data related to urban barriers and facilities, computation of personalized paths for users with special needs, and integration of open data provided by bus companies to identify the actual accessibility features and estimate the real arrival time of vehicles at stops. In terms of functionality, the first “monolithic” prototype fulfilled the goal of composing the aforementioned pieces of information to support citizens with reduced mobility (users with disabilities and/or elderly people) in their urban movements. In this paper, we describe a service-oriented architecture that exploits the microservices orchestration paradigm to enable the creation of new services and to make the management of the various data sources easier and more effective. The manuscript demonstrates the effectiveness of the approach showing a successful use case of a service that take into account multimodal paths, by involving cyclists, bicycle lanes, and bike sharing services in a urban environments. Such a use case take into account the user's interface and interaction mechanisms, which are strongly affected by the context of use.
Franco Callegati, Giovanni Delnevo, Andrea Melis 0001, Silvia Mirri, Marco Prandini, Paola Salomoni
ISCC3