EDBT 2026 Demo / reviewers in the wild / expert
Rolando Martins
dblp:34/2078
· DBLP profile ↗
21ranked-venue papers
3as first author
7since 2021 · last 2026
0000-0002-1838-1417ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 2 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021Computer networks · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Progressive state transfer for BFT with larger-than-memory stateabstract• Introduces a novel checkpoint algorithm for divisible states, possibly larger-than-memory, named Progressive State Transfer, that partitions states into smaller components for faster, efficient fault recovery in large persistent systems. • Defines divisible state and state partition formally, proposing a generalized methodology and differential checkpoint algorithm for key-value stores, enabling customizable part sizes, and allowing distributing the recovery effort across all replicas. • Separates transfer process from checkpoint creation, allowing the development of application-specific partitioning methods using the proposed state transfer method for generic parts. • Analyzes and compares our algorithm experimentally with a nondivisible, i.e., the traditional approach, state algorithm, highlighting advantages, disadvantages, and suitable scenarios for each. Efficient recovery of replicas is a key but often overlooked practical requirement to make Byzantine Fault Tolerant State Machine Replication (BFT-SMR) systems viable for real world use. The state transfer part of recovery consists of transferring a checkpoint of the state and a log of operations executed after the checkpoint was created. Unlike the log, which is efficient to record, and often bounded, checkpoints grow according to the state size. Consequently, the transfer and creation of checkpoints can have increasingly negative impacts on system performance. In this paper, we introduce Progressive State Transfer, a checkpoint state transfer algorithm that is designed for divisible state applications. Along with this algorithm, we explore the concept of divisible state, presenting a differential checkpoint creation method that builds partitioned incremental checkpoints. Progressive state transfer receives small parts rather than a complete state, which allows us to reduce the amount of information transferred from other replicas. Moreover, it allows a recovering replica to gather parts in parallel from different replicas, further reducing recovery time and balancing effort across replicas. We also present a differential checkpoint algorithm, that only updates the parts of the state that changed since the last checkpoint; this enables checkpoints to be performed incrementally and thus can vastly reduce checkpoint times in sizable states, consequently minimizing the impact of checkpointing on overall throughput. In our analysis, we compare our approach to a traditional non-divisible checkpoint algorithm, examining the differences in performance. The findings indicate that progressive state transfer can lead to a significant reduction in state transfer time, achieving up to twelve times faster transfers under similar conditions. Additionally, the implementation of differential checkpoints shows improved performance, maintaining similar levels of performance in less optimal scenarios. Amadeu Marques, Nuno Neto, Rolando Martins, Luís Veiga |
J. Parallel Distributed Comput. | 3 |
| 2025 | EVSOAR: Security Orchestration, Automation and Response via EV Charging StationsabstractVehicle cybersecurity has emerged as a critical concern, driven by innovation in the automotive industry, e.g., autonomous, electric, or connected vehicles. Current efforts to address these challenges are constrained by the limited computational resources of vehicles and the reliance on connected infrastructures. This motivated the foundation of Vehicle Security Operations Centers (VSOCs) that extend IT-based Security Operations Centers (SOCs) to cover the entire automotive ecosystem, both the in-vehicle and off-vehicle scopes. Security Orchestration, Automation, and Response (SOAR) tools are considered key for implementing an effective cybersecurity solution. However, existing state-of-the-art solutions depend on infrastructure networks such as 4G, 5G, and WiFi, which often face scalability and congestion issues. To address these limitations, we propose a novel SOAR architecture EVSOAR that leverages the EV charging stations for connectivity and computing to enhance vehicle cybersecurity. Our EV-specific SOAR architecture enables real-time analysis and automated responses to cybersecurity threats closer to the EV, reducing cellular latency, bandwidth, and interference limitations. Our experimental results demonstrate a significant improvement in latency, stability, and scalability through the infrastructure and the capacity to deploy computationally intensive applications that are otherwise infeasible within the resource constraints of individual vehicles. Tadeu Freitas, Erick Silva, Rehana Yasmin, Ali Shoker, Manuel Eduardo Correia, Rolando Martins, Paulo Veríssimo |
VTC2025-Spring | 6 |
| 2025 | Atlas, a modular and efficient open-source BFT framework
Nuno Neto, Rolando Martins, Luís Veiga |
J. Syst. Softw. | 2 |
| 2025 | A Risk Manager for Intrusion Tolerant Systems: Enhancing HAL 9000 With New Scoring and Data SourcesabstractABSTRACT Background Intrusion Tolerant Systems (ITS) aim to maintain system security despite adversarial presence by limiting the impact of successful attacks. Current ITS risk managers rely heavily on public databases like NVD and Exploit DB, which suffer from long delays in vulnerability evaluation, reducing system responsiveness. Objective This work extends the HAL 9000 Risk Manager to integrate additional real‐time threat intelligence sources and employ machine learning techniques to automatically predict and reassess vulnerability risk scores, addressing limitations of existing solutions. Methods A custom‐built scraper collects diverse cybersecurity data from multiple Open Source Intelligence (OSINT) platforms, such as NVD, CVE, AlienVault OTX, and OSV. HAL 9000 uses machine learning models for CVE score prediction, vulnerability clustering through scalable algorithms, and reassessment incorporating exploit likelihood and patch availability to dynamically evaluate system configurations. Results Integration of newly scraped data significantly enhances the risk management capabilities, enabling faster detection and mitigation of emerging vulnerabilities with improved resilience and security. Experiments show HAL 9000 provides lower risk and more resilient configurations compared to prior methods while maintaining scalability and automation. Conclusions The proposed enhancements position HAL 9000 as a next‐generation autonomous Risk Manager capable of effectively incorporating diverse intelligence sources and machine learning to improve ITS security posture in dynamic threat environments. Future work includes expanding data sources, addressing misinformation risks, and real‐world deployments. Tadeu Freitas, Carlos Novo, Inês de Castro Dutra, João Soares 0003, Manuel Eduardo Correia, Benham Shariati, Rolando Martins |
Softw. Pract. Exp. | 7 |
| 2023 | Deterministic or probabilistic? - A survey on Byzantine fault tolerant state machine replicationabstractByzantine Fault tolerant (BFT) protocols are implemented to guarantee the correct system/application behavior even in the presence of arbitrary faults (i.e., Byzantine faults). Byzantine Fault tolerant State Machine Replication (BFT-SMR) is a known software solution for masking arbitrary faults and malicious attacks (Liu et al., 2020). In this survey, we present and discuss relevant BFT-SMR protocols, focusing on deterministic and probabilistic approaches. The main purpose of this paper is to discuss the characteristics of proposed works for each approach, as well as identify the trade-offs for each different approach. Tadeu Freitas, João Soares 0003, Manuel Eduardo Correia, Rolando Martins |
Comput. Secur. | 4 |
| 2021 | ZERMIA - A Fault Injector Framework for Testing Byzantine Fault Tolerant Protocols
João Soares 0003, Ricardo Fernandez, Tadeu Freitas, Rolando Martins |
NSS | 5 |
| 2021 | Hardening cryptographic operations through the use of secure enclaves
André Brandão, João S. Resende, Rolando Martins |
Comput. Secur. | 3 |
| 2020 | Employment of Secure Enclaves in Cheat Detection Hardening
André Brandão, João S. Resende, Rolando Martins |
TrustBus | 3 |
| 2020 | Empowering Users Through a Privacy Middleware Watchdog
Patrícia R. Sousa, Rolando Martins, Luis Filipe Coelho Antunes |
TrustBus | 2 |
| 2019 | Security and Fairness in IoT Based e-Health System: A Case Study of Mobile Edge-CloudsabstractThrough IoT, humans and objects can be connected seamlessly, to guaranty improved quality of service (QoS). IoT-driven e-Health systems benefit from such rich network setting, to transmit health information and deliver health services. It is expected to grow massively in scale, but for that to happen, several issues need to be addressed, including security and trust. Edge computing paradigms, such as Fog computing and Cloudlet, are already popular in IoT based e-Health domain. Fog nodes are leveraged to reduce latency between IoT devices and remote cloud computing infrastructure. In this work, we explain how Mobile edge-clouds, which is a less popular edge computing paradigm, can be employed to achieve similar or lower latency, at a lower cost. We also propose a lightweight mechanism for security and fairness in e-Health protocols that are based on mobile edge-clouds and other paradigms. Detailed simulation experiments show that the proposed method is scalable and can efficiently mitigate attacks that are targeted at e-Health information and the network. Francis N. Nwebonyi, Rolando Martins, Manuel Eduardo Correia |
WiMob | 2 |
| 2019 | Iris: Secure reliable live-streaming with opportunistic mobile edge cloud offloading
Rolando Martins, Manuel Eduardo Correia, Luis Filipe Coelho Antunes, Fernando M. A. Silva |
Future Gener. Comput. Syst. | 1 |
| 2019 | Reputation based approach for improved fairness and robustness in P2P protocols
Francis N. Nwebonyi, Rolando Martins, Manuel Eduardo Correia |
Peer-to-Peer Netw. Appl. | 2 |
| 2018 | Reputation-Based Security System For Edge ComputingabstractGiven the centralized architecture of cloud computing, there is a genuine concern about its ability to adequately cope with the demands of connecting devices which are sharply increasing in number and capacity. This has led to the emergence of edge computing technologies, including but not limited to mobile edge-clouds. As a branch of Peer-to-Peer (P2P) networks, mobile edge-clouds inherits disturbing security concerns which have not been adequately addressed in previous methods. P2P security systems have featured many trust-based methods owing to their suitability and cost advantage, but these approaches still lack in a number of ways. They mostly focus on protecting client nodes from malicious service providers, but downplay the security of service provider nodes, thereby creating potential loopholes for bandwidth attack. Similarly, trust bootstrapping is often via default scores, or based on heuristics that does not reflect the identity of a newcomer. This work has patched these inherent loopholes and improved fairness among participating peers. The use cases of mobile edge-clouds have been particularly considered and a scalable reputation based security mechanism was derived to suit them. BitTorrent protocol was modified to form a suitable test bed, using Peersim simulator. The proposed method was compared to some related methods in the literature through detailed simulations. Results show that the new method can foster trust and significantly improve network security, in comparison to previous similar systems. Francis N. Nwebonyi, Rolando Martins, Manuel Eduardo Correia |
ARES | 2 |
| 2018 | How-to Express Explicit and Auditable ConsentabstractWhile the importance of consent request in today's society is increasing, specially online as a lawful basis for the processing of personal data, no detailed analysis of current technological solutions is available. In this work, we describe the existing technological solutions to express online consent in a positive fashion, including all the properties that an online solution should hold. We conclude by offering a risk proposal based on the linear combination of the rating of each one of these properties. We observe a low agreement between observers, highlighting that it is not easy to fulfill the requirements of the GDPR and showing that these studies are important when performing a Data Protection Impact Assessment. To overcome the low agreement, we propose the median of the observers' rate. Ana C. Carvalho, Rolando Martins, Luis Filipe Coelho Antunes |
PST | 2 |
| 2018 | Enforcing Privacy and Security in Public Cloud StorageabstractCloud storage allows users to remotely store their data, giving access anywhere and to anyone with an Internet connection. The accessibility, lack of local data maintenance and absence of local storage hardware are the main advantages of this type of storage. The adoption of this type of storage is being driven by its accessibility. However, one of the main barriers to its widespread adoption is the sovereignty issues originated by lack of trust in storing private and sensitive information in such a medium. Recent attacks to cloud-based storage show that current solutions do not provide adequate levels of security and subsequently fail to protect users' privacy. Usually, users rely solely on the security supplied by the storage providers, which in the presence of a security breach will ultimate lead to data leakage. In this paper, we propose and implement a broker (ARGUS) that acts as a proxy to the existing public cloud infrastructures by performing all the necessary authentication, cryptography and erasure coding. ARGUS uses erasure code as a way to provide efficient redundancy (opposite to standard replication) while adding an extra layer to data protection in which data is broken into fragments, expanded and encoded with redundant data pieces that are stored across a set of different storage providers (public or private). The key characteristics of ARGUS are confidentiality, integrity and availability of data stored in public cloud systems. João S. Resende, Rolando Martins, Luis Filipe Coelho Antunes |
PST | 2 |
| 2017 | Using Edge-Clouds to Reduce Load on Traditional WiFi Infrastructures and Improve Quality of ExperienceabstractCrowd-sourcing the resources of mobile devices is a hot topic of research given the game-changing applications it may enable. In this paper we study the feasibility of using edge-clouds of mobile devices to reduce the load in traditional WiFi infrastructures for video dissemination applications. For this purpose, we designed and implemented a mobile application for video dissemination in sport venues that retrieves replays from a central server, through the access points in the WiFi infrastructure, into a smartphone. The fan's smartphones organize themselves into WiFi-Direct groups and exchange video replays whenever possible, bypassing the central server and access points. We performed a real-world experiment using the live TV feed for the Champions League game Benfica-Besiktas with the help of a group of volunteers using the application at the student's union lounge. The analysis of the logs strongly suggests that edge-clouds can significantly reduce the load in the access points at such large venues and improve quality of experience. Indeed, the edge-clouds formed were able to serve up to 80% of connected users and provide 56% of all downloads requested from within. Pedro M. Pinto Silva, João Rodrigues 0003, Joaquim Silva 0001, Rolando Martins, Luís M. B. Lopes, Fernando M. A. Silva |
ICFEC | 4 |
| 2016 | Benchmarking Wireless Protocols for Feasibility in Supporting Crowdsourced Mobile ComputingabstractRecent advances in mobile device technology have triggered research on using their aggregate computational and/or storage resources to form edge-clouds. Whilst traditionally viewed as simple clients, smartphones and tablets today have hardware resources that allow more sophisticated software to be installed, and can be used as thick clients or even thin servers. Simultaneously, new standards and protocols, such as Wi-Fi Direct and Wi-Fi TDLS (Tunneled Direct Link Setup), have been established that allow mobile devices to talk directly with each other, as opposed to over the Internet or across Wi-Fi access points. This can, potentially, lead to ubiquitous, low-latency, device-to-device (D2D) communication. In this paper, we study whether D2D protocols can support mobile-edge clouds by benchmarking different protocols and configurations for a specific application. The results show that decentralized device-to-device techniques can be used to efficiently disseminate multi- media contents while diminishing contention in the wireless infrastructure, allowing for up to 65 % traffic reduction at the access points. João Rodrigues 0003, Joaquim Silva 0001, Rolando Martins, Luís M. B. Lopes, Utsav Drolia, Priya Narasimhan, Fernando M. A. Silva |
DAIS | 3 |
| 2014 | STOVEPipe: Observable Access Control of User Data for Untrusted Applications on Mobile DevicesabstractThe rapid growth in mobile devices will give rise to the trend of the leasing out of compute and data resources on mobile devices to third-parties for applications to be run on multiple mobile devices. However, these third-party applications running on leased mobile devices are typically written by unknown entities, and cannot be trusted by mobile device owners. Current mobile device platforms (e.g. Android) have permissions and access control systems designed for mobile apps that are written by reputable developers and vetted by authoritative app stores, and they are not suitable for untrusted apps. We propose STOVEPipe, an observable access control system for user data on mobile devices for untrusted third-party applications. STOVEPipe ensures that untrusted code is isolated and cannot directly access system data, and performs all data accesses on behalf of untrusted apps. This enables STOVEPipe to observe all data accessed by untrusted apps, implement content-based access control, perform accounting and auditing on accessed data easily, and perform privacy-preserving data transformations. Jiaqi Tan 0001, Utsav Drolia, Rolando Martins, Rajeev Gandhi, Priya Narasimhan |
CloudCom | 3 |
| 2014 | Short paper: CHIPS: content-based heuristics for improving photo privacy for smartphonesabstractThe Android permissions system provides all-or-nothing access to users' photos stored on smartphones, and the permissions which control access to stored photos can be confusing to the average user. Our analysis found that 73% of the top 250 free apps on the Google Play store have permissions that may not reflect their ability to access stored photos. We propose CHIPS, a unique content-based fine-grained run-time access control system for stored photos for Android which requires minimal user assistance, runs entirely locally, and provides low-level enforcement. CHIPS can recognize faces with minimal user training to deny apps access to photos with known faces. CHIPS's privacy identification has low overheads as privacy checks are cached, and is accurate, with false-positive and false-negative rates of less than 8%. Jiaqi Tan 0001, Utsav Drolia, Rolando Martins, Rajeev Gandhi, Priya Narasimhan |
WISEC | 3 |
| 2013 | Experiences with Fault-Injection in a Byzantine Fault-Tolerant Protocol
Rolando Martins, Rajeev Gandhi, Priya Narasimhan, Soila M. Pertet, António Casimiro, Diego Kreutz, Paulo Veríssimo |
Middleware | 1 |
| 2010 | Lightweight Fault-Tolerance for Peer-to-Peer MiddlewareabstractWe address the problem of providing transparent, lightweight, fault-tolerance mechanisms for generic peer-to-peer middleware systems. The main idea is to use the peer-to-peer overlay to provide for fault-tolerance rather than support it higher up in the middleware architecture, e.g. in the form of services. To evaluate our approach we have implemented a fault-tolerant middleware prototype that uses a hierarchical peer-to-peer overlay in which the leaf peers connect to sensors that provide data streams. Clients connect to the root of the overlay and request streams that are routed upwards through intermediate peers in the overlay up to the client. We report encouraging preliminary results for latency, jitter and resource consumption for both the non-faulty and faulty cases. Rolando Martins, Priya Narasimhan, Luís M. B. Lopes, Fernando M. A. Silva |
SRDS | 1 |