EDBT 2026 Demo / reviewers in the wild / expert
Marco De Vincenzi 0001
dblp:305/4735-1
· DBLP profile ↗
12ranked-venue papers
5as first author
12since 2021 · last 2026
0000-0002-2706-2936ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Ontology-Driven Detection of Traffic Light Manipulation in Intelligent Transportation Systems
Elena Cardillo, Marco De Vincenzi 0001, Maria Taverniti, Ilaria Matteucci |
ICISSP (2) | 2 |
| 2025 | OLIVE: Adaptive Containerized Architecture for Multi-Factor Authentication in V2XabstractOLIVE is a containerized Multi-Factor Authentication (MFA) architecture designed to adapt to diverse security requirements in Vehicle-to-Everything (V2X) communications. By integrating multiple authentication factors, it provides adaptability and scalability to match the required level of security. Beyond the standard three authentication factors, OLIVE supports additional custom factors housed in independent containers. The nature of this modular design and its alignment with current security standards enable efficient resource management while ensuring compatibility with both autonomous and nonautonomous vehicles. OLIVE's adaptability positions it as a versatile solution for various applications, including dynamic Electric Vehicle (EV) charging and zero-trust architectures. Marco De Vincenzi 0001, Chiara Bodei, Ilaria Matteucci |
VTC2025-Spring | 1 |
| 2025 | TLM: A Spatial Messaging Language for Autonomous Vehicle NavigationabstractAutonomous Vehicles (AVs) rely on sensor-based perception systems and high-definition maps for navigation. How-ever, their performance may degrade in challenging conditions such as poor visibility, unpredictable traffic conditions, or GNSS-denied environments like urban canyons or temporary construction zones. To address these limitations, we introduce Time-Logic-Map (TLM), a spatial messaging language that enables the road infrastructure to broadcast structured, machine-readable messages to supplement AV perception and support decision-making. This approach reduces the dependence on onboard sensors and describes road logic through machine-oriented language. TLM organizes road information into three layers: map, defining road geometry and a local 3D Cartesian coordinate system; logic, encoding the structural layout of roads and the precedence rules governing vehicle movements; and time, broadcasting real-time information like traffic signal phases. We describe modular design using multiple practical examples in standard and complex intersections, as well as in road construction zones. Marco De Vincenzi 0001, Chiara Bodei, Ilaria Matteucci, Sanjay E. Sarma, Stephen S. Ho |
VTC2025-Fall | 1 |
| 2024 | Formal analysis of an AUTOSAR-based basic software moduleabstractAbstract The widespread use of advanced driver assistance systems in modern vehicles, together with their integration with the Internet and other road nodes, has made vehicle more vulnerable to cyber-attacks. To address these risks, the automotive industry is increasingly focusing on the development of security solutions: formal methods and software verification techniques, which have been successfully applied to a number of safety-critical systems, could be a promising approach in the automotive area. In this work, we concentrate on in-vehicle communications, provided by many Electronic Control Units (ECUs) that work together thanks to serial protocols such as Controller Area Network (CAN). However, increasing connectivity exposes the internal network to a variety of cyber-risks. Our aim is to formally verify the AUTOSAR-based Basic Software module called CINNAMON, designed to ensure confidentiality, integrity, and authentication at the same time for traffic exchanged over CAN protocol. More precisely, it adds confidentiality guarantees to the Secure Onboard Communication (SecOC) module. We formally analyze CINNAMON with the verification tool Tamarin. Our analysis shows that CINNAMON could be an effective security solution, as it can ensure the desired properties, in particular, confidentiality in a send-receive scenario between two ECUs. Finally, we describe a potential application scenario. Chiara Bodei, Marco De Vincenzi 0001, Ilaria Matteucci |
Int. J. Softw. Tools Technol. Transf. | 2 |
| 2023 | Application of Secure Two-Party Computation in a Privacy-Preserving Android AppabstractData privacy has become increasingly important in recent years, with the rise of cyber threats and the unauthorized sharing of sensitive information. Our work within the E-Corridor project has focused on developing a secure framework for sharing information in multimodal transport systems, while ensuring data privacy is maintained. Our implementation of a two-party computation schema using Yao’s garbled circuits in an Android mobile setting has enabled us to create an application that allows users to find points of interest, e.g., restaurants or hotels, near specific areas without sharing any personal information. The application matches user requests using the secure two-party without disclosing any of the user’s preferences with external actors. We design a threat model based on LINDDUN to show the reliability of our project. It highlights also the potential of using secure computing techniques to enable information sharing while maintaining privacy. Our work demonstrates the importance of prioritizing data privacy in our increasingly interconnected world and the potential of secure two-party computing techniques in achieving this goal. Besides, this framework is flexible and can be extended to various domains where data privacy is of utmost importance. Marco De Vincenzi 0001, Ilaria Matteucci, Fabio Martinelli, Stefano Sebastio |
ARES | 1 |
| 2023 | Securing Automotive Ethernet: Design and Implementation of Security Data Link SolutionsabstractIn recent years, the automotive industry has undergone a revolution in which data has become one of the most important element of vehicle functionality. However, most of the in-vehicle networking paradigms have limitations in accommodating this data surge. To address this need, Automotive Ethernet (AE) has emerged as a promising solution. Concurrently, there is an urgent demand to guarantee data security and privacy within vehicle networks by designing ad hoc vehicular solutions. For this reason, our study undertakes the design and evaluation of four distinct ISO/OSI layer 2 security configurations, here named profiles, tailored to AE. By leveraging advanced security techniques such as MACsec and SecOC-related solutions, these profiles are engineered to ensure robust data confidentiality, integrity, and authenticity. To assess their efficacy, we created a testbed with Raspberry units to emulate an in-vehicle environment. We carried out a comprehensive timing analyses to uncover the performance attributes of each solution. We aim to provide insights for the development of secure and efficient data communication systems within the in-vehicle networks. Marco De Vincenzi 0001, Chiara Bodei, Ilaria Matteucci |
AICCSA | 1 |
| 2023 | Vehicle Data Collection: A Privacy Policy Analysis and ComparisonabstractIn recent years, data can be considered the new fuel for road vehicle functionalities like driver-assistance systems or customized services. Therefore, the carmakers with their phone apps, synced with the infotainment system, can collect information from the drivers and vehicles to be processed inside or outside the car. In this context, we analyze different carmakers’ privacy policies to define their readability and compliance with the EU General Data Protection Regulation, and provide analysis of carmakers’ data collection. Besides, for the first time, we compare the most significant privacy regulations in automotive. Finally, we create an interactive dashboard to compare the different carmakers’ policies and provide users with an efficient instrument to understand some relevant privacy aspects like which data the carmakers declare to collect. We find that carmakers could collect a large number of users and vehicle data, but, in some cases, the privacy policies seem to be quite challenging to read and do not provide some information like how collected data are protected or stored. Chiara Bodei, Gianpiero Costantino, Marco De Vincenzi 0001, Ilaria Matteucci, Anna Monreale |
ICISSP | 3 |
| 2023 | From Hardware-Functional to Software-Defined Vehicles and their Security IssuesabstractOver the next few years, the automotive industry is set to experience a revolutionary transformation driven by several interconnected trends such as autonomous driving, connected vehicles, and electrification. Our research focuses on Software-Defined Vehicles (SDVs), their definition, and an analysis of their possible cybersecurity issue. SDV is a new concept that is changing the definition of vehicles from purely hardware-based to software-oriented. The research analyzes the SDV security following the ISO/SAE 21434 guidelines, performing a complete vulnerability assessment to determine the main possible threats and their impact on different aspects like safety and operations. The findings suggest that SDVs may be the future of the automotive industry and will offer greater convenience and sustainability, throughout the vehicle life cycle but only if appropriate solutions to mitigate potential security threats like denial-of-service or jamming attacks, will be implemented. Chiara Bodei, Marco De Vincenzi 0001, Ilaria Matteucci |
INDIN | 2 |
| 2023 | Electric Vehicle Security and Privacy: A Comparative Analysis of Charging MethodsabstractIn the next decade, electric road vehicles have the potential to reduce climate change and improve mobility. However, not all charging methods are equally secure and private, so this work provides a comprehensive analysis of the security and privacy of various EV charging methods and highlights the importance of addressing vulnerabilities to meet homologation standards. Five charging methods are described in terms of physical components, communication protocols, and standards. This research identifies weaknesses in each method and determines which are less prone to cyber attacks or privacy disclosures. The impact of different charging methods on vehicle homologation is also discussed, as required by the cybersecurity regulation UNECE R155. A mapping is provided between vulnerabilities and suggested mitigations from the regulation. The evidence suggests that different charging methods result in different security and privacy levels, with conductive methods being more vulnerable to security attacks and privacy disclosure, while methods with fewer components may reduce security and privacy risks. Gianpiero Costantino, Marco De Vincenzi 0001, Fabio Martinelli, Ilaria Matteucci |
VTC2023-Spring | 2 |
| 2023 | A Privacy-Preserving Solution for Intelligent Transportation Systems: Private Driver DNAabstractThe rising connection of vehicles with the road infrastructure enables the creation of data-driven applications to offer drivers customized services. At the same time, these opportunities require innovative solutions to protect the drivers’ privacy in a complex environment like an Intelligent Transportation System (ITS). This need is even more relevant when data are used to retrieve personal behaviors or attitudes. In our work, we propose a privacy-preserving solution, called Private Driver DNA, which designs a possible architecture, allowing drivers of an ITS to receive customized services. The proposed solution is based on the concept of Driver DNA as characterization of driver’s driving style. To assure privacy, we perform the operations directly on sanitized data, using the Order Revealing Encryption (ORE) method. Besides, the proposed solution is integrated with ITS architecture defined in the European project E-Corridor. The result is an effective privacy-preserving architecture for ITS to offer customized products, which can be used to address drivers’ behaviors, for example, to environmental-friendly attitudes or a more safe driving style. We test Private Driver DNA using a synthetic dataset generated with the vehicle simulator CARLA. We compare ORE with another encryption method like Homomorphic Encryption (HE) and some other privacy-preserving schemas. Besides, we quantify privacy gain and data loss utility after the data sanitization process. Gianpiero Costantino, Marco De Vincenzi 0001, Fabio Martinelli, Ilaria Matteucci |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2022 | DRIVES: Android App for Automotive Customized ServicesabstractToday, Big Data, generated by connected vehicles, can improve road safety, lead the green transition, and direct the mobility revolution. For this reason, we develop an Android app, called DRIVES (DRIVEr Services), that allows drivers to get rewarded for their eco-driving style. In particular, DRIVES collects vehicle data from the OBD-II port, stores them in infrastructure of the European project E-Corridor, computes a driving style profile, called Driver DNA, and provides users customized services, based on the driving profiles. The offered services can span a wide range of possibilities from an energy bill discount to a personalized carsharing price, but, in any case, as a direct consequence of the rewarding process, our app can encourage safer and more sustainable mobility. In this work, we describe the app structure, its operations, and the E-Corridor architecture, where vehicle data are analyzed. Besides, we provide an insight into the possible privacy concerns caused by the usage of personal and vehicle data. The result is an Android app that has been tested in the project infrastructure with a real vehicle, and that can be used as a general schema to create other rewarding apps, also for autonomous vehicles, using driving data. Marco De Vincenzi 0001 |
AICCSA | 1 |
| 2022 | SECPAT: Security Patterns for Resilient Automotive E / E ArchitecturesabstractAutomated driving requires increasing networking of vehicles, which in turn broadens their attack surface. In this paper, we describe several security design patterns that target critical steps in automotive attack chains and mitigate their con-sequences. These patterns enable the detection of anomalies in the firmware when booting, detect anomalies in the communication in the vehicle, prevent unauthorized control units from successfully transmitting messages, offer a way of transmitting security-related events within a vehicle network and reporting them to units external to the vehicle, and ensure that communication in the vehicle is secure. Using the example of a future high-level Electrical / Electronic (E / E) architecture, we also describe how these security design patterns can be used to become aware of the current attack situation and how to react to it. Christian Plappert, Florian Fenzl, Roland Rieke, Ilaria Matteucci, Gianpiero Costantino, Marco De Vincenzi 0001 |
PDP | 6 |