EDBT 2026 Demo / reviewers in the wild / expert
Rebecca Montanari
dblp:38/5309
· DBLP profile ↗
54ranked-venue papers
1as first author
19since 2021 · last 2026
0000-0002-3687-0361ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 24 · 7 since 2021Systems, architecture and hardware · 6 · 4 since 2021Security and privacy · 5 · 3 since 2021Databases, data management, data science and information retrieval · 5Software engineering, systems software and programming languages · 4 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | TrustFLow: A traceable federated learning framework to enable trustworthy digital twinsabstract• Comprehensive tracking system using Decentralized Identifiers and Verifiable Credentials to ensure Federated Learning (FL) process governance. • Robust influence estimation to quantify the trustworthiness of clients and data contributions. • Automated policy-driven revocation mechanism for models and data based on established open standards. • Seamless integration into FL-based architectures, enabling the development of transparent and trustworthy models supporting Digital Twin functions. • Extensive experiments conducted on a real prototype across diverse settings demonstrate the effectiveness and efficiency of the solution. As Digital Twin (DT) ecosystems increasingly rely on distributed and collaborative intelligence, ensuring trust and reliability of the underlying Machine Learning (ML) models becomes critical, especially when raw data cannot be centrally aggregated due to privacy or security concerns. Federated Learning (FL) has emerged as a promising paradigm for collaborative model training across distributed data sources while preserving data privacy. However, the inherent opacity of the FL process introduces several challenges; individual data contributions, as well as local node updates, remain inaccessible to centralized oversight, hindering the overall trustworthiness of the global model training process. In addition, data and updates of the local model can be biased, or even maliciously modified, negatively affecting the global model. In the context of DTs, such vulnerabilities can directly compromise decision-making, leading to operational safety risks and affecting the system’s reliability. To this end, we propose TrustFLow, a comprehensive framework that integrates Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs) deployed over a distributed ledger infrastructure to securely trace the provenance of data and evolution of models in FL. TrustFLow tracking capabilities enable linking data to sources, tamper-proof monitoring, and process traceability. In addition, TrustFLow provides crucial functionalities for estimating the influence of individual producers (datasets) on the global model and for revoking both biased data and the global model(s) influenced by them. These features contribute to a broader vision of federated governance, where accountability, transparency, and trust are enforced between all participants. In addition, our framework offers the benefit of seamless integration into any FL-driven DT architecture. To evaluate our proposal, we have conducted an extensive set of experiments that measure the efficiency and effectiveness of the framework under different settings. Nicolò Romandini, Andrea Roberta Costagliola, Armir Bujari, Rebecca Montanari |
Future Gener. Comput. Syst. | 4 |
| 2025 | Compact and Selective Disclosure for Verifiable CredentialsabstractSelf-Sovereign Identity (SSI) is a novel identity model that empowers individuals with full control over their data, enabling them to choose what information to disclose, with whom, and when. This paradigm is rapidly gaining traction worldwide, supported by numerous initiatives such as the European Digital Identity (EUDI) Regulation or Singapore's National Digital Identity (NDI). For instance, by 2026, the EUDI Regulation will enable all European citizens to seamlessly access services across Europe using Verifiable Credentials (VCs). A key feature of SSI is the ability to selectively disclose only specific claims within a credential, enhancing the privacy protection of the identity owner. This paper proposes a novel mechanism designed to achieve Compact and Selective Disclosure for VCs (CSD-JWT). Our method leverages a cryptographic accumulator to encode claims within a credential into a unique, compact representation. We implemented CSD-JWT as an open-source solution and extensively evaluated its performance under various conditions. CSD-JWT provides significant memory savings, lowering usage by up to 46% compared to the state-of-the-art. It also minimizes network overhead by producing remarkably smaller Verifiable Presentations (VPs), with size reduction from 27% to 93%. Such features make CSD-JWT especially well-suited for resource-constrained devices, including hardware wallets designed for managing credentials. Alessandro Buldini, Carlo Mazzocca, Rebecca Montanari, A. Selcuk Uluagac |
ACSAC | 3 |
| 2025 | Federated Unlearning in Healthcare: Why It MattersabstractIn healthcare scenarios, privacy poses significant challenges due to the sensitivity of patient data. Federated Learning (FL) has emerged as a promising solution to unlock their potential while maintaining compliance with privacy-preserving regulations. It enables data contributors to train a global model without sharing raw data. However, FL introduces complexities in complying with the right to be forgotten, a fundamental principle of the European General Data Protection Regulation (GDPR). This right ensures clients can request the removal of their influence from the global model. Unfortunately, the intrinsic decentralized nature of FL makes retraining the model from scratch and Machine Unlearning (MU) methods unfeasible. This challenge has led to Federated Unlearning (FU), which aims to efficiently remove a client’s influence through post-processing the global model. FU ensures the unlearned model performs as if the forgotten data were never seen while minimizing performance degradation on other data. As unlearning strategies typically require multiple rounds to restore model performance on retained data, this paper investigates the natural attenuation of a client’s contributions over time without FU algorithms. We use the ProstateMRI dataset, a real-world federated healthcare dataset that naturally exhibits feature heterogeneity across parties. We evaluate metrics such as loss, accuracy, and Membership Inference Attacks (MIAs). Our findings highlight the necessity of FU methods to ensure compliance with privacy regulations and effectively erase client contributions from the global model. Code available at: https://github.com/alessiomora/medical federated unlearning Alessio Mora, Carlo Mazzocca, Rebecca Montanari, Paolo Bellavista |
IJCNN | 3 |
| 2025 | VESPACE: A verifiable blockchain-based data space solution to empower the data economyabstractIn the rapidly evolving data economy, the ability to securely and efficiently share data between organizations has become paramount, unlocking new opportunities for innovation and growth. In this context, different initiatives have worked on conceptual proposals and enabling technological building blocks, addressing design aspects of data spaces. However, the current landscape lacks practical implementations and integration of secure data-sharing primitives supporting a decentralized data ecosystem. To this end, we conduct an analysis of previous efforts and initiatives, identifying gaps. We then introduce VESPACE , a blockchain-based platform for data spaces that enables participants to selectively and securely share verifiable data with authorized users while maintaining control over their access. Our framework incorporates data sovereignty principles implemented through Decentralized Identifiers (DIDs), Verifiable Credentials (VCs), and blockchain technology, qualifying decentralized identity and access control as key features to establish user trust in decentralized data ecosystems. We present a prototype system implementation of VESPACE , evaluating the design choices, showcasing the feasibility of our proposal. • We analyze standards and projects to guide verifiable, auditable data space design • We propose VESPACE , a verifiable data space aligned with FAIR and SSI principles. • We evaluate a prototype to assess the scalability of the implemented security primitives. Andrea Roberta Costagliola, Carlo Mazzocca, Armir Bujari, Rebecca Montanari, Paolo Bellavista |
Comput. Commun. | 4 |
| 2025 | Benchmarking Selective Disclosure Mechanisms for Verifiable Credentials: A Systematic Comparison for Security and PrivacyabstractIn a world where digitalization isreshapingevery aspect of society, digital identity has become more crucial than ever to establish trust and accountability across all entities, whether human, organizational, or machine-based. Numerous initiatives are emerging worldwide, such as the United States mobile driver’s license (mDLs) and Singapore’s National Digital Identity (NDI). In May 2024, the European Union introduced Regulation 2024/1183, establishing the European Digital Identity Framework. By 2026, this framework will provide all European citizens with a European Digital Identity Wallet (EUDIW), allowing them to access both online and offline public and private services while maintaining full control over their data. Individuals can selectively disclose only the required information to access services. However, the current EUDIW design relies on Selective Disclosure for JSON Web Token (SD-JWT), which does not fully meet the privacy requirements outlined in the regulation. This paper presents a comprehensive comparison of the main selective disclosure mechanisms. Specifically, we identify relevant threat models, formalize associated security and privacy properties, and assess the extent to which existing mechanisms satisfy these properties in mitigating the identified threats. Furthermore, we introduce an open-source benchmark that evaluates multiple selective disclosure across key performance indicators, including computational latency, bandwidth consumption, and storage requirements. Alessandro Buldini, Carlo Mazzocca, Rebecca Montanari, A. Selcuk Uluagac |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Federated Unlearning: A Survey on Methods, Design Guidelines, and Evaluation MetricsabstractFederated learning (FL) enables collaborative training of a machine learning (ML) model across multiple parties, facilitating the preservation of users' and institutions' privacy by maintaining data stored locally. Instead of centralizing raw data, FL exchanges locally refined model parameters to build a global model incrementally. While FL is more compliant with emerging regulations such as the European General Data Protection Regulation (GDPR), ensuring the right to be forgotten in this context-allowing FL participants to remove their data contributions from the learned model-remains unclear. In addition, it is recognized that malicious clients may inject backdoors into the global model through updates, e.g., to generate mispredictions on specially crafted data examples. Consequently, there is the need for mechanisms that can guarantee individuals the possibility to remove their data and erase malicious contributions even after aggregation, without compromising the already acquired "good" knowledge. This highlights the necessity for novel federated unlearning (FU) algorithms, which can efficiently remove specific clients' contributions without full model retraining. This article provides background concepts, empirical evidence, and practical guidelines to design/implement efficient FU schemes. This study includes a detailed analysis of the metrics for evaluating unlearning in FL and presents an in-depth literature review categorizing state-of-the-art FU contributions under a novel taxonomy. Finally, we outline the most relevant and still open technical challenges, by identifying the most promising research directions in the field. Nicolò Romandini, Alessio Mora, Carlo Mazzocca, Rebecca Montanari, Paolo Bellavista |
IEEE Trans. Neural Networks Learn. Syst. | 4 |
| 2024 | Certifying IoT Data with Verifiable CredentialsabstractThe Internet of Things (IoT) is a major contributor to the vast amount of data generated worldwide, significantly impacting the big data market. However, this data holds value only when utilized for insights and applications. Many organizations hesitate to use third-party data due to concerns about accuracy, reliability, and integrity. Enhancing trustworthiness in data is crucial to unlock their full potential, especially in critical domains such as healthcare where erroneous data can have severe consequences. The Identity of Things (IDoT) paradigm addresses this need by identifying trustworthy devices using Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs), offering promising solutions for digital identification. Although DIDs and VCs have primarily been used for mutual trust and access control, their potential for data certification in IoT remains underexplored. This paper is the first to investigate the feasibility of IoT devices to use VCs for certifying data. We evaluated devices with varying capabilities, focusing on the latency, computing, and storage requirements for issuing VCs. Our findings demonstrate that IoT devices can issue VCs with up to 100 claims in less than 90 ms, with storage requirements growing linearly and remaining below 4 KB. Using VCs for data certification does not introduce significant computational overhead, suggesting its practicality for IoT environments. Carlo Mazzocca, Stefano Allevi, Rebecca Montanari |
NCA | 3 |
| 2024 | EVOKE: Efficient Revocation of Verifiable Credentials in IoT Networks
Carlo Mazzocca, Abbas Acar, A. Selcuk Uluagac, Rebecca Montanari |
USENIX Security Symposium | 4 |
| 2024 | DIVA: A DID-based reputation system for secure transmission in VANETs using IOTAabstractToday’s advancement in Vehicular Ad-hoc Networks (VANET) constitutes a cornerstone in ensuring traffic safety in Intelligent Transportation Systems (ITS). In this context, vehicle-to-vehicle (V2V) communications are a pivotal enabler for road safety, traffic optimization, and pedestrian protection. However, V2V communications lack effective and efficient security solutions that can adequately ensure the trustworthiness of the source of the transmitted content. In this work, we originally propose DIVA, i.e., a Decentralized Identifier-based reputation system for secure transmission in VAnets. In particular, we claim the suitability of utilizing IOTA, a Direct Acyclic Graph (DAG)-based ledger, to securely store reputation scores and of leveraging Decentralized Identifiers (DIDs) to identify participating vehicles. DIVA also incorporates and implements a reputation algorithm that computes reputation scores by analyzing both safety and non-safety messages, exchanged among vehicles and Road Side Units (RSUs) in compliance with the related European Telecommunications Standards Institute (ETSI) standards. Thus, DIVA can effectively identify malicious contributors and decrease their reputation scores. The reported experimental results clearly show the feasibility and effectiveness of DIVA, by working on an extended and comprehensive dataset of realistic V2V messages; the dataset has been made openly accessible to the research community, also to increase result reproducibility. Angelo Feraudo, Nicolò Romandini, Carlo Mazzocca, Rebecca Montanari, Paolo Bellavista |
Comput. Networks | 4 |
| 2024 | Enabling Federated Learning at the Edge through the IOTA TangleabstractThe proliferation of Internet of Things (IoT) devices, generating massive amounts of heterogeneous distributed data, has pushed toward edge cloud computing as a promising paradigm to bring cloud capabilities closer to data sources. In many cases of practical interest, centralized Machine Learning (ML) approaches can hardly be employed due to high communication costs, low reliability, legal restrictions, and scalability issues. Therefore, Federated Learning (FL) is emerging as a promising distributed ML approach that enables models to be trained on remote devices using their local data. However, “traditional” FL solutions still present open technical challenges, such as single points of failure and lack of trustworthiness among participants. To address these open challenges, some researchers have started to propose leveraging blockchain technologies. However, the adoption of blockchain for FL at the edge is limited by several factors nowadays, such as long waiting times for transaction confirmation and high energy consumption. In this work, we conduct an original and comprehensive analysis of the key design challenges to address towards an efficient implementation of FL at the edge, and analyze how Distributed Ledger Technologies (DLTs) can be employed to overcome them. Then, we present a novel architecture that enables FL at the edge by leveraging the IOTA Tangle, a next-generation DLT whose data structure is a directed acyclic graph (DAG), and the InterPlanetary File System (IPFS) to store and share partial models. Experimental results demonstrate the feasibility and efficiency of our proposed solution in real-world deployment scenarios. Carlo Mazzocca, Nicolò Romandini, Rebecca Montanari, Paolo Bellavista |
Future Gener. Comput. Syst. | 3 |
| 2024 | SpatialSSJP: QoS-Aware Adaptive Approximate Stream-Static Spatial Join ProcessorabstractThe widespread adoption of Internet of Things (IoT) motivated the emergence of mixed workload scenarios in smart cities, where fast arriving geo-referenced massive amounts data streams need to be joined with archive tables, at scale. This aims at enriching streams with descriptive attributes that enable deeper insightful analytics. More applications are now relying on finding, in real-time, to which geographical region each data streaming spatially-tagged tuple belongs. This problem requires a computationally intensive stream-static join operation, where one side of join is a dynamic stream while the other is a disk-resident static table. Even with emergence of some libraries that solve this problem in static-static fashion, their adoption for live scenarios is challenging because join operations are expensive in real-time. In addition, the time-varying nature of fluctuation and skewness in the geospatial data loads arriving online calls for an approximate solution that can trade-off QoS constraints in a way which ensures that the system survives sudden spikes in data loads. In this paper, we present SpatialSSJP, an adaptive spatial-aware approximate query processing system that specifically focuses on stream-static joins in a way that guarantees achieving an agreed set of Quality-of-Service goals and maintains geo-statistics of stateful online aggregations over stream-static join results. SpatialSSJP employs a state-of-art stratified-like sampling design to select well-balanced representative geospatial data stream samples and serve them to a stream-static geospatial join operator downstream. We implemented a prototype atop Spark Structured Streaming. Our extensive evaluations on big real datasets show that our system can survive and mitigate harsh join workloads and outperform state-of-art baselines by significant magnitudes, without risking rigorous error bounds in terms of the accuracy of the output results. SpatialSSJP achieves a relative accuracy gain against plain Spark joins of approximately 10% in worst cases but reaching up to 50% in best case scenarios. Isam Mashhour Aljawarneh, Paolo Bellavista, Antonio Corradi, Luca Foschini 0001, Rebecca Montanari |
IEEE Trans. Parallel Distributed Syst. | 5 |
| 2023 | Federated Learning Meets Blockchain: a Power Consumption Case StudyabstractFederated learning (FL) is emerging as the most promising approach to collaboratively train a machine learning (ML) model on a common task without centralizing data. During each FL round, participants locally train a partial model with its on-premises data. Such models are subsequently aggregated to derive a global one. How these partial models are combined is a primary concern. Traditional approaches usually rely on a parameter server that introduces many weaknesses such as single point of failure, lack of trustworthiness among unknown participants, and incapacity to handle the traffic generated from millions of devices. Thus, to overcome such concerns, blockchain has recently been proposed as a valuable solution to improve the robustness of FL approaches. The full-blown benefits of using blockchain enable tackling the limits of centralized servers. However, energy consumption is still one of the significant factors inhibiting its widespread due to the current discussions on climate change and sustainability. Recently, a growing number of research works have been focusing on integrating FL and blockchain, nevertheless, adequate analysis and estimate of their energy and power consumption are often lacking. This paper presents an estimate of the power consumption of FlowChain, an architecture that integrates FL with blockchain to simplify the use of FL. Experimental results demonstrate that the overall power consumption significantly depends on the ML model adopted. Nicolò Romandini, Carlo Mazzocca, Rebecca Montanari |
PDP | 3 |
| 2023 | TruFLaaS: Trustworthy Federated Learning as a ServiceabstractThe increasing availability of data generated by Internet of Things (IoT) and Industrial Internet of Things (IIoT) devices, as well as privacy and law regulations, have significantly boosted the interest in collaborative machine learning (ML) approaches. In this direction, we claim federated learning (FL) as a promising ML paradigm where participants collaboratively train a global model without outsourcing on-premises data. However, setting up and using FL can be extremely costly and time-consuming. To effectively promote the adoption of FL in real-world scenarios, while limiting the overhead and knowledge of the underlying technology, service providers should offer federated learning as a service (FLaaS). One of the major concerns while designing an architecture that provides FLaaS is achieving trustworthiness among involved typically unknown participants. This article presents a blockchain-based architecture that achieves Trustworthy federated learning as a service (TruFLaaS). Our solution provides trustworthiness among 3rd-party organizations by leveraging blockchain, smart contracts, and a decentralized oracle network. Specifically, during each FL round, the service provider supplies a sample, without overlapping, of its validation set to validate all partial models submitted by clients. By doing so, poor models, which tend to degrade performance or introduce malicious backdoors, are identified and discarded. Due to the transparency of the blockchain, not changing the validation set would enable participants to forge a malicious partial model that passes the validation phase. We evaluate our approach over two well-known IIoT datasets: the reported experimental results show that TruFLaaS outperforms the state-of-the-art literature solutions in the field. Carlo Mazzocca, Nicolò Romandini, Matteo Mendula, Rebecca Montanari, Paolo Bellavista |
IEEE Internet Things J. | 4 |
| 2023 | FRAMH: A Federated Learning Risk-Based Authorization Middleware for HealthcareabstractModern healthcare systems operate in highly dynamic environments requiring adaptable access control mechanisms. Access to sensitive data and medical equipment should be granted or denied according to the current health situation of the patient. To handle the need for adaptable access control of healthcare scenarios, we propose a novel model that allows dynamic access control decisions based on the context characterizing the source, type of access request, patient, and estimated risk corresponding to the conditions of the patient. Estimating patient status risk requires analyzing vital physiological data whose availability is growing, thanks to the widespread diffusion of the Internet of Medical Things (IoMT) devices. Inferring the patient health status risk through machine learning (ML) techniques is possible, but to achieve better accuracy, the training phase requires the aggregation of vast amounts of data from different sources. This aggregation could be difficult or even impossible due to organization regulations and privacy laws. To address these issues, this article proposes a novel federated learning risk-based authorization middleware for healthcare (FRAMH) that supports risk-based access control to deal with changing and unforeseen medical situations. Our solution infers the risk of health status through a federated learning (FL) approach enriched with blockchain to avoid the weaknesses of centralized servers. The implemented prototype and a large set of experimental results demonstrate the advantages of FL in estimating the risk in healthcare scenarios. Through this approach, even a medical institution with a limited dataset can achieve a satisfying risk estimation and efficient access control enforcement. Carlo Mazzocca, Nicolò Romandini, Michele Colajanni, Rebecca Montanari |
IEEE Trans. Comput. Soc. Syst. | 4 |
| 2022 | Efficient Geospatial Analytics on Time Series Big DataabstractIn smart city advanced analytical scenarios, tremendous amounts of georeferenced big time series data arrive continuously to time series databases, requiring the shared analytics on both geospatial and time dimensions. Mostly, the focus has been given to optimizing the storage and processing of each workload alone, either geospatial or time dimensions. To close this gap, in this paper, we have designed a pyramid-like indexing scheme that we term as geoTSI (short for geo time series index) which twists two dimensionality reduction geospatial encoding methods (geohash and S2) sequentially with a time series index to efficiently enable such mixed workload scenarios. This method enables geospatial and time indexes to collaborate synergistically in an aim to reduce the time required for accessing the disk and retrieving the time series data that comprises the answer for the mixed workload query. We show how our indexing scheme can be efficiently exploited to run a hybrid geospatial proximity query on time series data. Also, we evaluate our index on real-world georeferenced time series data, where we obtain, on average, a significant 34 % reduction in the query running time by applying our method against the baseline. Isam Mashhour Aljawarneh, Paolo Bellavista, Antonio Corradi, Luca Foschini 0001, Rebecca Montanari |
ICC | 5 |
| 2022 | A Fully Decentralized Architecture for Access Control Verification in Serverless EnvironmentsabstractServerless computing is a novel paradigm that has been widely adopted, in recent years, across many sectors due to its fine-grained scalability and fast time-to-market. This paradigm aims at offloading users from heavy burden tasks including those related to authentication and authorization. However, existing security mechanisms provided by cloud providers do not seem to be adequate to completely secure serverless platforms. In particular, typical access control solutions rely either on centralized authorization services or implement access control verification within the business logic. These approaches respectively degrade system performance and lead to security issues derived from the tight coupling among code and authorization verification. In this paper, we present a solution to address these problems with a fully decentralized architecture integrating access control verification in serverless environments. We implemented a prototype of the proposed architecture and evaluated its performance under different load conditions. Experiments show that our proposal outperforms other approaches. Andrea Sabbioni, Carlo Mazzocca, Michele Colajanni, Rebecca Montanari, Antonio Corradi |
ISCC | 4 |
| 2021 | Context Incorporation Techniques for Social Recommender SystemsabstractThe problem of information overloading is prevalent in recommendations websites and social networks. Users seek relevant recommendations from like-minded connections. User-item interactions (i.e., ratings) are prevalent in recommendation websites such as Netflix, whereas user-user connections are the interaction sought in social websites such as Twitter. Social recommender systems seek to generate recommendations for users based on similar preferences of their close friends. Because social networks do not normally contain user-item interactions, social recommender systems are typically hybridized with other recommenders (e.g., website recommenders such as Netflix) that provide such interaction. However, current systems are unaware of the user’s additional contextual information when coupled with social counterparts. In this paper, we propose a context-aware deep learning-based recommender system, US-NCF, in support for social recommender systems. Our experiments show US-NCF outperforms state-of-art counterparts. Isam Mashhour Aljawarneh, Paolo Bellavista, Antonio Corradi, Luca Foschini 0001, Rebecca Montanari |
ICC | 5 |
| 2021 | Edge-enabled Mobile Crowdsensing to Support Effective Rewarding for Data Collection in Pandemic EventsabstractSmart cities use Information and Communication Technologies (ICT) to enrich existing public services and to improve citizens' quality of life. In this scenario, Mobile CrowdSensing (MCS) has become, in the last few years, one of the most prominent paradigms for urban sensing. MCS allow people roaming around with their smart devices to collectively sense, gather, and share data, thus leveraging the possibility to capture the pulse of the city. That can be very helpful in emergency scenarios, such as the COVID-19 pandemic, that require to track the movement of a high number of people to avoid risky situations, such as the formation of crowds. In fact, using mobility traces gathered via MCS, it is possible to detect crowded places and suggest people safer routes/places. In this work, we propose an edge-anabled mobile crowdsensing platform, called ParticipAct, that exploits edge nodes to compute possible dangerous crowd situations and a federated blockchain network to store reward states. Edge nodes are aware of all critical situation in their range and can warn the smartphone client with a smart push notification service that avoids firing too many messages by adapting the warning frequency according to the transport and the specific subarea in which clients are located. Luca Foschini 0001, Giuseppe Martuscelli, Rebecca Montanari, Michele Solimando |
J. Grid Comput. | 3 |
| 2021 | Efficient QoS-Aware Spatial Join Processing for Scalable NoSQL Storage FrameworksabstractCurrent cloud-enabled NoSQL database frameworks support flexible and scalable storage of huge amounts of data arriving through various and often heterogeneous channels. However, they do not natively provide optimised processing of spatial data, thus making it more difficult to perform accurate data analytics needed in many smart city application scenarios. To improve the performance of spatial data computation in the NoSQL MongoDB storage framework, this article proposes a novel data partitioning method based on dimensionality reduction. The underlying key idea is to reduce a spatial data representation from multi to single dimensionality, by still maintaining its geometrical meaning and by employing a specific geo-encoding scheme, i.e., a geohash string. In particular, the geohash string is used as a sharding key in order to store geometrically-nearby objects into the same chunks (and consequently into the same shard). In addition, as a distinctive feature, we have extended the MongoDB framework with a custom spatial QoS-aware optimizer that exploits our novel partitioning scheme to support two, typically expensive, types of spatial queries with QoS guarantees. Those queries are containment (and consequently top-N) and proximity. The paper also contributes to the existing literature with extensive experimental results about the performance of both our partitioning method and query optimizer; the reported results show that our solutions outperform baselines by orders of magnitude. Isam Mashhour Aljawarneh, Paolo Bellavista, Antonio Corradi, Luca Foschini 0001, Rebecca Montanari |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2020 | An Edge-based Distributed Ledger Architecture for Supporting Decentralized Incentives in Mobile CrowdsensingabstractNowadays, the exploitation of distributed ledger technology (DLT) is increasing among different domains and use cases. Not only within the context of cryptocurrencies, DLT could help the cooperation among untrusted parties in a wide variety of application scenarios. In particular, crowdsensing platforms can benefit from DLT because they need to federate systems belonging to different organizations to share end-user profiles, finally free to move within different domains, maintaining their identity. In this paper, we propose an edge-based distributed ledger architecture for supporting decentralised incentives in a specific mobile crowdsensing paltform called ParticipAct. To motivate the choice we describe two different deployments of ParticipAct, one based on a classical client-server architecture and the other one based on an edge-based model, and we highlight their pro and cons. In particular, our more notable findings rely on an approach based on edge computing and highlight how the three-tier solution improves the scalability, the performance, the security and the fault tolerance of the infrastructure responsible for the management of the federation among untrusted crowdsensing platforms. Paolo Bellavista, Marco Cilloni, Giuseppe Di Modica, Rebecca Montanari, Pasquale Carlo Maiorano Picone, Michele Solimando |
CCGRID | 4 |
| 2020 | Locality-Preserving Spatial Partitioning for Geo Big Data Analytics in Main Memory FrameworksabstractThe easily reachable IoT edge devices have caused the accumulation of vast amounts of geo-referenced data traces that can help in performing deep insightful analytics. Geospatial data in real geometries are normally clumped into batches and has strong autocorrelation properties which can be exploited in discovering interesting insights. Current plain Cloud computing frameworks are not attuned to the shape of data. Most importantly, data splitting is an important precursor in data parallelization mechanisms. Current systems mostly focus on general data workloads, thus are giving attention mostly to load balancing while splitting the data to Cloud computing resources. However, many benefits can be reaped by being attuned to the spatial characteristics while distributing the data, thus striking a plausible balance between load balancing and spatial data locality preservation normally leads to achieving better time-based QoS goals, which then leads to an optimized provisioning of Cloud computing resources. In this paper, we have designed a spatial batch processing engine that comprises a custom spatial data locality aware partitioning method for disseminating spatial data loads in Cloud computing clusters. We have also extended a state-of-art benchmark density-based clustering method that is known as DBSCAN-MR and implemented a standard compliant prototype on top of a best-in-breed de facto Cloud-based main memory processing framework, Apache Spark. Our results show that our partitioning method with the associated spatial query optimizers can achieve gains that significantly outperform baselines. Isam Mashhour Aljawarneh, Paolo Bellavista, Antonio Corradi, Luca Foschini 0001, Rebecca Montanari |
GLOBECOM | 5 |
| 2020 | Hyperledger Fabric Blockchain: Chaincode Performance AnalysisabstractHyperledger Fabric, created and supported by the Linux Foundation and IBM, is one of the most popular open-source blockchain permissioned platforms that has been already used in many industrial scenarios. One of the main characteristics of this platform is that it provides a smart contract system that relies on general-purpose languages instead of an ad hoc one. In fact, a chaincode in the Fabric platform (the equivalent of the Ethereum smart contract) is a software program which encapsulates the business logic for the creation and modification of logical assets in the ledger that can be written in different general-purpose programming languages (currently Java, Go, and Node.js). This paper analyses the transaction performance of the Fabric platform by identifying at a fine-grained degree level the factors that most contribute to the overall overhead. In particular, we focus on how the transaction latency is affected by the programming language adopted for implementing the chaincode and by varying the number of participating endorser peers. Finally, the paper shows a thorough test assessment aimed at evaluating the impact of the different chaincode implementation on performance overhead. As it emerges from our experimental results, Go is the most performing programming language. Luca Foschini 0001, Andrea Gavagna, Giuseppe Martuscelli, Rebecca Montanari |
ICC | 4 |
| 2019 | Spatial-Aware Approximate Big Data Stream ProcessingabstractThe widespread adoption of ubiquitous IoT edge devices and modern telemetry spewing out unprecedented avalanches of spatially-tagged datasets that if could interactively be explored would offer deep insights into interesting natural phenomena, which might remain otherwise illusive. Online application of spatial queries is expensive, a problem that is further inflated by the fact that we, more than often, do not have access to a full dataset population in non- stationary settings. As a way of coping up, sampling stands out as a natural solution for approximating estimators such as averages and totals of some interesting correlated parameters. In any sampling design, representativeness remains the main issue upon which a method is regarded good or bad. In a loose way, in a spatial context, this means fairly sampling quantities in a way that preserves spatial characteristics so as to provide more accurate approximates for spatial query responses. Current big data management systems either do not offer over-the-counter spatial-aware online sampling solutions or, at best, rely on randomness, which causes too many imponderables for an overall estimation. We herein have designed a QoS- spatial-aware online sampling method that outperforms vanilla baselines by statically significant magnitudes. Our method sits atop Apache Spark Structured Streaming's codebase and have been tested against a benchmark that is consisting of millions-records of spatially- augmented dataset. Isam Mashhour Aljawarneh, Paolo Bellavista, Luca Foschini 0001, Rebecca Montanari |
GLOBECOM | 4 |
| 2019 | Container Orchestration Engines: A Thorough Functional and Performance ComparisonabstractIn the last decade, novel software architectural patterns, such as microservices, have emerged to improve application modularity and to streamline their development, testing, scaling, and component replacement. To support these new trends, new practices as DevOps methodologies and tools, promoting better cooperation between software development and operations teams, have emerged to support automation and monitoring throughout the whole software construction lifecycle. That affected positively several IT companies, but also helped the transition to the softwarization of complex telco infrastructures in the last years. Container-based technologies played a crucial role by enabling microservice fast deployment and their scalability at low overhead; however, modern container-based applications may easily consist of hundreds of microservices services with complex interdependencies and call for advanced orchestration capabilities. While there are several emerging container orchestration engines, such as Docker Swarm, Kubernetes, Apache Mesos, and Cattle, a thorough functional and performance assessment to help IT managers in the selection of the most appropriate orchestration solution is still missing. This paper aims to fill that gap. Collected experimental results show that Kubernetes outperforms its counterparts for very complex application deployments, while other engines can be a better choice for simpler deployments. Isam Mashhour Aljawarneh, Paolo Bellavista, Filippo Bosi, Luca Foschini 0001, Giuseppe Martuscelli, Rebecca Montanari, Amedeo Palopoli |
ICC | 6 |
| 2019 | Clustering of Spatial Data with DBSCAN: An Assessment of STARKabstractThe ever-increasing diffusion rate of mobile devices, able to continuously gather sensing data, creates favorable conditions for the development of smart city infrastructures. In this field the analysis of spatial data plays a pivotal role, due to the relevance they assume in urban scenarios. To satisfy this need, the usage of large distributed computing infrastructures comes into play, supported by efficient frameworks, such as Apache Spark, one of the most relevant platforms to date. However, in order to better take advantage of data and computing resources, it is also necessary to have at disposal flexible and easy-to-use specialized instruments, granting domain specific capabilities for the analysis of spatial data. This paper focuses on a novel framework for processing of spatial data called STARK, giving an overview of its functionalities and presenting an in-depth assessment study of its performances when implementing spatial data clustering, namely DBSCAN. In particular, we focus on two implementations, called MR-DBSCAN and NG-DBSCAN. Of the latter we introduced an implementation in STARK, in order to enrich the framework and to test its capabilities. Paolo Bellavista, Mattia Campestri, Luca Foschini 0001, Rebecca Montanari |
ISCC | 4 |
| 2019 | Simplifying Multi-layer and Multi-tenant Support in OpenStack: The SACHER Use CaseabstractThe majority of cloud computing deployment environments follow the typical service delivery models, i.e., Software as a Service (SaaS), Platform as a Service (PaaS) and the Infrastructure as a Service (IaaS), that provide specific functionalities to users depending on the service delivery layer and clear resource isolation among different tenants. However, in certain scenarios, such as the Cultural heritage one, it is often required to provide SaaS, IaaS and PaaS cross-functionality support to users and cross-tenant resource visibility among isolated tenants. In the CH scenario, for example, restorers and professionals may often need to connect and to share temporarily data among different tenants or to work with old customized software requiring the possibility to exploit specific management functionalities that are typically available not at the SaaS but at the IaaS or PaaS layers. This paper proposes a middleware called Registry that can provide additional functionalities to different user categories by joining the SaaS with the IaaS layer and that offers also multi-tenancy operations making private data available to certain project on-demand and enabling, in this way, cross-tenant data sharing. The Registry has been designed, developed and tested within the context of the SACHER project that provides a cloud-based infrastructure for the management of the cultural data lifecycle. Luca Foschini 0001, Giuseppe Martuscelli, Rebecca Montanari |
ISCC | 3 |
| 2019 | Mobile Cloud Support for Semantic-Enriched Speech Recognition in Social CareabstractNowadays, most users carry high computing power mobile devices where speech recognition is certainly one of the main technologies available in every modern smartphone, although battery draining and application performance (resource shortage) have a big impact on the experienced quality. Shifting applications and services to the cloud may help to improve mobile user satisfaction as demonstrated by several ongoing efforts in the mobile cloud area. However, the quality of speech recognition is still not sufficient in many complex cases to replace the common hand written text, especially when prompt reaction to short-term provisioning requests is required. To address the new scenario, this paper proposes a mobile cloud infrastructure to support the extraction of semantics information from speech recognition in the Social Care domain, where carers have to speak about their patients conditions in order to have reliable notes used afterward to plan the best support. We present not only an architecture proposal, but also a real prototype that we have deployed and thoroughly assessed with different queries, accents, and in presence of load peaks, in our experimental mobile cloud Platform as a Service (PaaS) testbed based on Cloud Foundry. Antonio Corradi, Marco Destro, Luca Foschini 0001, Spyros Kotoulas, Vanessa López, Rebecca Montanari |
IEEE Trans. Cloud Comput. | 6 |
| 2018 | A Crowdsensing Campaign and Data Analytics for Assisting Urban Mobility Pattern DeterminationabstractThe ever-progressing advancements in urban growth and technological development in recent decades have caused a noticeable increase of the phenomenon of socialenvironmental deterioration, leading to a decline in quality of life, reduction of social welfare and difficult urban mobility for people living in cities. The concept of Smart City can be used to mitigate several of the challenges arising from the aforementioned issues, relying on multiple tools and techniques (such as crowdsensing) to gather essential context data about how actual citizens consume resources and commute throughout their everyday lives. In this paper, we show how an urban mobility data analytics tool may help to determine the most visited regions and interconnections in an urban area. This information has been obtained using data gathered from a pool of users participating in a crowdsensing campaign, using the ParticipAct Brazil platform. The obtained results confirm the reliability of the information produced, highlighting the regions with the highest concentration of people during the geolocation monitoring process and their connections; therefore, this data may be used to plan possible future changes to how the city allocates its resources, to better suit the mobility needs of its citizens. Marcelo de Almeida Buosi, Marco Cilloni, Antonio Corradi, Carlos Roberto De Rolt, Julio Da Silva Dias, Luca Foschini 0001, Rebecca Montanari, Piero Zito |
ISCC | 7 |
| 2017 | LTE proximity discovery for supporting participatory mobile health communitiesabstractAdvancements in mobile communication technologies and the continuously increasingly diffusion of smartphones equipped with several physical and virtual sensors and with different network support are promoting novel mobile healthcare scenarios where patients with critical physical/behavioral conditions can be provided with anywhere and anytime care assistance even while on the move. In particular, this recent technology evolution simplifies the formation of mobile health communities (MHC) for prompt assistance in the case of emergency situations, where a MHC can be defined as a dynamic team of care givers formed by passing by mobile users physically co-located with the patient in need of help while on the move. Crowdsensing, through the massive use of smartphone sensors, further enhances the potential of supporting participatory management of MHCs for emergency scenarios. This paper presents a crowdsensing-based middleware called COLLEGA that provides several management functionalities for supporting prompt assistance to mobile patients in the case of a medical emergency. In particular, the paper claims to exploit the novel emerging LTE Direct technology to facilitate dynamic formation of MHCs and data dissemination. Our LTE-based support for participatory MHCs is described and experimental results showing the feasibility and effectiveness of the approach are also provided. Paolo Bellavista, Jacopo De Benedetto, Carlos Roberto De Rolt, Luca Foschini 0001, Rebecca Montanari |
ICC | 5 |
| 2017 | Efficient spark-based framework for big geospatial data query processing and analysisabstractThe exponential amount of geospatial data that has been accumulated in an accelerated pace has inevitably motivated the scientific community to examine novel parallel technologies for tuning the performance of spatial queries. Managing spatial data for an optimized query performance is particularly a challenging task. This is due to the growing complexity of geometric computations involved in querying spatial data, where traditional systems failed to beneficially expand. However, the use of large-scale and parallel-based computing infrastructures based on cost-effective commodity clusters and cloud computing environments introduces new management challenges to avoid bottlenecks such as overloading scarce computing resources, which may be caused by an unbalanced loading of parallel tasks. In this paper, we aim to fill those gaps by introducing a generic framework for optimizing the performance of big spatial data queries on top of Apache Spark. Our framework also supports advanced management functions including a unique self-adaptable load-balancing service to self-tune framework execution. Our experimental evaluation shows that our framework is scalable and efficient for querying massive amounts of real spatial datasets. Isam Mashhour Aljawarneh, Paolo Bellavista, Antonio Corradi, Rebecca Montanari, Luca Foschini 0001, Andrea Zanotti |
ISCC | 4 |
| 2017 | Competence-based mobile Community Response NetworksabstractThe exploitation of mobile social networking technologies merging crowdsensing systems enable mobile users to opportunistically create participatory mobile social networks based on not only common attributes, interests or contacts, but also mobility-related context, such as physical location and co-presence. Disaster management and mobile healthcare applications can benefit from the possibility of creating participatory communities based on physical closeness. Co-located people can dynamically form ad-hoc mobile community response networks (CRNs) to provide anywhere and anytime care assistance to users with critical physical/behavioral conditions after a disaster occurrence or even during their normal day-life while on the move. The effectiveness of mobile CRNs depends, however, on the possibility to select among co-located users the ones with the most appropriate competence to understand and execute required assistance actions. The paper introduces the concept of competence-based mobile CRNs and describes how competence-based mobile CRNs can be created within the specific framework of a crowdsensing-based middleware called COLLEGA that provides comprehensive management functionalities for supporting prompt assistance in emergency situations. In particular, the paper discusses our proposed competence model and its implementation within COLLEGA enabling to extract the competence of mobile CRN's members from data available on social networks, such as LinkedIn. Carlos Roberto De Rolt, Luca Foschini 0001, Fernando Alvaro Ostuni Gauthier, Danilo Hasse, Rebecca Montanari |
ISCC | 5 |
| 2016 | COLLEGA middleware for the management of participatory Mobile Health CommunitiesabstractRecent advancements in wireless technologies and the widespread availability of smartphones equipped with several physical and virtual sensors are leading to the emergence of novel mobile healthcare scenarios where patients with critical physical/behavioral conditions can be provided with anywhere and anytime care assistance even while on the move. Crowdsensing, through the massive use of smartphone sensors further enhances the potential of supporting participatory management of emergency scenarios. This paper presents a macro process modelling of crowdsourced-based participatory emergency scenarios and, accordingly, proposes a crowdsensing-based middleware called COLLEGA that provides comprehensive management functionalities for supporting prompt assistance in case of a medical emergency. In particular, through participatory and opportunistic sensing, the COLLEGA framework allows dynamic formation of ad-hoc assistance groups formed by passing-by users capable of assisting mobile patients in need of help while waiting for professional caregivers and provides support for understanding the emergency situation and effectively planning and executing assistance actions. Carlos Roberto De Rolt, Rebecca Montanari, Marcelo Luiz Brocardo, Luca Foschini 0001, Julio Da Silva Dias |
ISCC | 2 |
| 2014 | Activity recognition for Smart City scenarios: Google Play Services vs. MoST facilitiesabstractThe ever increasing diffusion of smartphones today equipped with several physical and virtual sensors allow to directly collect information about surrounding physical and logical context that range from monitoring current social pulse of individuals and entire communities to detecting user current physical activity. Enabling those advanced sensing capabilities requires complex signal processing, machine learning, and resource management algorithms that are often beyond the skills of many mobile app developers. This paper describes the relevance of these facilities for mobile crowdsensing applications in Smart City scenarios and presents our solution for activity detection, comparing it with the reference implementations provided by Google as part of the Google Play Services library. Giuseppe Cardone, Andrea Cirri, Antonio Corradi, Luca Foschini 0001, Rebecca Montanari |
ISCC | 5 |
| 2013 | Mobile social networking middleware: A survey
Paolo Bellavista, Rebecca Montanari, Sajal K. Das 0001 |
Pervasive Mob. Comput. | 2 |
| 2012 | Editorial SI: Mobile Applications and Services
Thomas Phan, Rebecca Montanari, Petros Zerfos |
Mob. Networks Appl. | 2 |
| 2008 | A self-organizing group management middleware for mobile ad-hoc networks
Dario Bottazzi, Rebecca Montanari, Giovanni Rossi |
Comput. Commun. | 2 |
| 2008 | Semantic-based discovery to support mobile context-aware service access
Alessandra Toninelli, Antonio Corradi, Rebecca Montanari |
Comput. Commun. | 3 |
| 2006 | A Semantic Context-Aware Access Control Framework for Secure Collaborations in Pervasive Computing Environments
Alessandra Toninelli, Rebecca Montanari, Lalana Kagal, Ora Lassila |
ISWC | 2 |
| 2006 | A mobile computing middleware for location- and context-aware internet data servicesabstractThe widespread diffusion of mobile computing calls for novel services capable of providing results that depend on both the current physical position of users (location) and the logical set of accessible resources, subscribed services, preferences, and requirements (context). Leaving the burden of location/context management to applications complicates service design and development. In addition, traditional middleware solutions tend to hide location/context visibility to the application level and are not suitable for supporting novel adaptive services for mobile computing scenarios. The article proposes a flexible middleware for the development and deployment of location/context-aware services for heterogeneous data access in the Internet. A primary design choice is to exploit a high-level policy framework to simplify the specification of services that the middleware dynamically adapts to the client location/context. In addition, the middleware adopts the mobile agent technology to effectively support autonomous, asynchronous, and local access to data resources, and is particularly suitable for temporarily disconnected clients. The article also presents the case study of a museum guide assistant service that provides visitors with location/context-dependent artistic data. The case study points out the flexibility and usability of the proposed middleware that permits automatic service reconfiguration with no impact on the implementation of the application logic. Paolo Bellavista, Antonio Corradi, Rebecca Montanari, Cesare Stefanelli |
ACM Trans. Internet Techn. | 3 |
| 2005 | Enabling context-aware group collaboration in MANETsabstractRecent advances in mobile ad-hoc networks (MANET) technologies promote new opportunities for anytime and anywhere impromptu collaboration and leverage the provisioning of novel collaborative services, such as emergency rescue, e-care, and troop car management. However, the design and deployment of collaborative services in MANET environments raise new group management challenges. In particular, unpredictable users/devices mobility, frequent disconnection/reconnection of devices and continuous changes in network topology call for novel middleware solutions to handle properly the transient and dynamic formation of ad-hoc groups. The paper proposes a context-aware group membership middleware (AGAPE) that bases group management decisions depending on context information, such as user location, user attributes and preferences, and access device properties. User location determines the scope of group member visibility within a network locality, whereas user requirements and device properties govern the joining to a group and influence the played role of a user within a group. AGAPE provides a set of support services to arrange/dissolve and manage ad-hoc groups on demand and propagates the visibility of available group members and of their context up to the application level to allow applications to adapt collaborative decisions and actions accordingly. The paper also presents a MANET-enabled emergency rescue application scenario to show and to evaluate the functioning of AGAPE. Dario Bottazzi, Antonio Corradi, Rebecca Montanari |
ISADS | 3 |
| 2005 | A context-aware group management middleware to support resource sharing in MANET environmentsabstractRecent advances in Mobile Ad-hoc NETworks (MANET) technologies promote new opportunities for users to share resources from ubiquitous points of attachment, when changing physical locations and even when no statically deployed network infrastructure is available. However, the highly dynamic nature of Mobile Ad-Hoc environments causes users to experience continuous changes in the set of the locally accessible resources, thus increasing the complexity of resource sharing. Novel middleware solutions are required to support the various management issues involved in resource sharing in MANETs environments. In particular, it is crucial to handle and to propagate up to the application level the visibility of both the users that are willing to group together to share their resources and of the resources they decide to share. The paper proposes a group management middleware (AGAPE) that, as a key feature, exploits the visibility of context information, e.g., user location, user attributes and preferences, access device properties, to create and discover groups of interest for resource sharing, to monitor the availability of groups members, and to dynamically arrange/requalify group members bindings to shared resources as changes in context operating conditions occur. Application developers can exploit the AGAPE support to build on top of it various application-specific resource sharing strategies and mechanisms, such as Global Virtual Data Structures. Finally, the paper presents a MANET-enabled emergency rescue application scenario to show and to evaluate the functioning of AGAPE. Dario Bottazzi, Antonio Corradi, Rebecca Montanari |
Mobile Data Management | 3 |
| 2004 | Context-Based Access Control for Ubiquitous Service ProvisioningabstractPervasive user mobility, wireless connectivity and the widespread diffusion of portable devices raise new challenges for ubiquitous service provisioning. In particular, mobility of users/devices causes frequent and unpredictable changes in physical user location and in consequently available resources and services. Users can also change portable access devices, with different capabilities, even at runtime and during the same service session, thus forcing us to consider very dynamic aspects even due to client heterogeneity. Access control to resources is crucial to leverage the provision of ubiquitous services and calls for novel solutions based on various context information, e.g., user/device location, device properties, user needs, local resource visibility. This work presents a novel access control model built upon the concept of context as the first-class design principle to rule access to resources. As key features, this model allows to associate access control permissions with contexts where users operate and users acquire/lose their permissions when entering/leaving a specific context. Unlike traditional access control solutions where user identity/role triggers policy evaluation when requesting resource access, this model exploits the user context to fully determine the set of available permissions. In addition, the proposed model allows to express context-based access control policies at a high level of abstraction cleanly separate from service logic implementation, thus promoting dynamic policy modification with no impact on the service code. The paper shows the implementation of the proposed model in the UbiCOSM framework and presents a mobile office service provisioning scenario. Antonio Corradi, Rebecca Montanari, Daniela Tibaldi |
COMPSAC | 2 |
| 2004 | Context-Awareness for Impromptu Collaboration in MANETsabstractThe growing diffusion of wireless-enabled portable devices and the recent advances in mobile ad-hoc networks (MANET) open a new scenario where users can benefit from anywhere/anytime impromptu collaboration. However, the development of collaborative services in MANET environments raises new challenges and calls for novel middleware solutions to handle properly the communication between transiently collaborating partners. The paper proposes AGAPE, a context-aware group communication middleware that permits to select collaborating partners, to schedule incoming messages and to tailor their presentation on the basis of group members context, e.g. depending on member's location, attributes, and device properties. Dario Bottazzi, Antonio Corradi, Rebecca Montanari |
NCA | 3 |
| 2004 | Context-Based Access Control Management in Ubiquitous EnvironmentsabstractWireless connectivity and the widespread diffusion of portable devices raise new challenges for ubiquitous service provisioning. Mobility of users causes frequent and unpredictable changes in user location and in consequently available resources. Access control to resources is crucial to leverage the provision of ubiquitous services and calls for novel solutions based on various context information, e.g., user location, device properties, user needs, local resource visibility. This work presents a novel access control model that proposes the adoption of context as a first-class design principle to rule access to resources. The paper proposes a context-centric access control middleware, called UbiCOSM, that dynamically determines the contexts of mobile users and effectively rules the access to them, by taking into account different types of metadata: user profiles and system/user-level authorization policies. The paper also presents a context-dependent movie-info service to evaluate the functioning of UbiCOSM. Antonio Corradi, Rebecca Montanari, Daniela Tibaldi |
NCA | 2 |
| 2003 | Policy-based Separation of Concerns for Dynamic Code Mobility ManagementabstractThe convergence between the Internet and telecommunication systems promotes an integrated scenario characterized by different flavors of mobility. Users can connect to the network from ubiquitous points of attachment and wireless portable devices can roam by maintaining continuous connectivity. Novel middleware technologies based on code mobility has the potential to enhance service provisioning to mobile users/devices. However, code mobility adds complexity to the design of applications and calls for new approaches for the programming of code mobility strategies. Separation between mobility and computational concerns is crucial to reduce the complexity of code mobility control and to favor rapid mobile code-based service prototyping, run-time configuration and maintenance. To achieve the needed degree of separation of concerns the paper advocates the adoption of policies and proposes a policy-based framework for dynamic code mobility management. In addition, the paper explores a reflective-based approach to mobility control and compares policy with reflective-based programming solutions to point out the main differences and lessons learned. Rebecca Montanari, Gianluca Tonti, Cesare Stefanelli |
COMPSAC | 1 |
| 2003 | AGAPE: a Location-aware Group Membership Middleware for Pervasive Computing EnvironmentsabstractThe widespread diffusion of mobile computing along with the integration of telecommunication systems and the Internet enables a scenario where the promise of ubiquitous computing is starting to be realised. This scenario calls for novel services that can be deployed on-demand close to the user and customised to not only client needs, but also to the client current location. In particular, group membership management services should exploit the visibility of client location to organise effective solutions for group communication and interoperation and to promote the design and development of advanced collaborative applications, such as traffic management and e-care ones. The paper describes a middleware for group membership management (AGAPE) that exploits both the visibility of users position and the heterogeneous characteristics of the access terminals to facilitate interoperation in a pervasive computing scenario. Dario Bottazzi, Antonio Corradi, Rebecca Montanari |
ISCC | 3 |
| 2003 | Policy-Driven Binding to Information Resources in Mobility-Enabled Scenarios
Paolo Bellavista, Antonio Corradi, Rebecca Montanari, Cesare Stefanelli |
Mobile Data Management | 3 |
| 2003 | Semantic Web Languages for Policy Representation and Reasoning: A Comparison of KAoS, Rei, and Ponder
Gianluca Tonti, Jeffrey M. Bradshaw, Renia Jeffers, Rebecca Montanari, Niranjan Suri, Andrzej Uszok |
ISWC | 4 |
| 2003 | Context-Aware Middleware for Resource Management in the Wireless InternetabstractThe provisioning of Web services over the wireless Internet introduces novel challenging issues for service design and implementation: from user/terminal mobility during service execution, to wide heterogeneity of portable access devices and unpredictable modifications in accessible resources. In this scenario, there are frequent provision-time changes in the context, defined as the logical set of accessible resources depending on client location, access terminal capabilities, and system/service management policies. The development of context-dependent services requires novel middlewares with full context visibility. We propose a middleware for context-aware resource management, called CARMEN, capable of supporting the automatic reconfiguration of wireless Internet services in response to context changes without any intervention on the service logic. CARMEN determines the context on the basis of metadata, which include declarative management policies and profiles for user preferences, terminal capabilities, and resource characteristics. In addition, CARMEN exploits the mobile agent technology to implement mobile middleware components that follow the provision-time movement of clients to support locally their customized service access. The proposed middleware shows how metadata and mobile agents can favor component reusability and automatic service reconfiguration, by reducing the development/ deployment complexity. Paolo Bellavista, Antonio Corradi, Rebecca Montanari, Cesare Stefanelli |
IEEE Trans. Software Eng. | 3 |
| 2000 | A Flexible Access Control Service for Java Mobile CodeabstractMobile code (MC) technologies provide appealing solutions for the development of Internet applications. For instance, Java technology facilitates dynamic loading of application code from remote servers on to heterogeneous clients distributed all over the Internet. However, executing foreign code that has been loaded from the network raises significant security concerns which limit the diffusion of these technologies. Substantial work has already been done to provide security solutions for protecting both hosting nodes and MC. For example, the Java security architecture evolved from a rigid sandbox model to a more flexible solution where downloaded code can perform any kind of operation, depending on its source location and signature. However, the most widespread security solutions for MC platforms today do not support the sophisticated security policies required in modern inter-organisational environments. This requires expressive languages to specify the policy and flexible mechanisms for policy implementation which cater for code mobility. This paper shows how access control policies for MC-based applications can be specified in a concise and declarative language called Ponder, and how these policies can be implemented within the Java security architecture. Antonio Corradi, Rebecca Montanari, Cesare Stefanelli, Emil C. Lupu, Morris Sloman |
ACSAC | 2 |
| 2000 | A Flexible Management Framework for Certificate Status Validation
Antonio Corradi, Rebecca Montanari, Cesare Stefanelli, Diana Berbecaru, Antonio Lioy, Fabio Maino |
SEC | 2 |
| 1999 | Mobile Agents Protection in the Internet EnvironmentabstractThe Mobile Agent (MA) paradigm seems to be a promising technology for developing applications in open, distributed and heterogeneous environments, such as the Internet. Mobile agents can overcome some of the limits of the traditional client/server model and can easily integrate with the Web to improve application accessibility. Many application areas, such as electronic commerce, mobile computing, network management and information retrieval can benefit from the application of the MA technology. However, a wider diffusion of MA is currently limited by the lack of a comprehensive security framework. Answering to the requirement of protection for both execution sites and mobile agents can boost the acceptance of the MA paradigm in the Internet environment. The paper describes an MA environment, called Secure and Open Mobile Agent (SOMA), that is based on a thorough security model and provides a wide range of tools and mechanisms to build and enforce flexible security policies. In particular, we focus on the problem of how mobile agents can be protected from malicious behavior of execution sites and we propose a distributed multiple-hops integrity protocol for mobile agent protection, fully integrated in SOMA. Antonio Corradi, Rebecca Montanari, Cesare Stefanelli |
COMPSAC | 2 |
| 1999 | Mobile agents and security: protocols for integrity
Antonio Corradi, Marco Cremonini, Rebecca Montanari, Cesare Stefanelli |
DAIS | 3 |
| 1999 | Mobile Agents Integrity for Electronic Commerce Applications
Antonio Corradi, Marco Cremonini, Rebecca Montanari, Cesare Stefanelli |
Inf. Syst. | 3 |