Antonio Lioy

dblp:39/5082 · DBLP profile ↗
← Back
71ranked-venue papers
10as first author
15since 2021 · last 2026
0000-0002-5669-9338ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 20 · 1 first-author · 8 since 2021Systems, architecture and hardware · 18 · 8 first-author · 1 since 2021Security and privacy · 14 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 13 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 An Approach for Detecting Vulnerable TLS Connections Through Network Monitoring, Intrusion Detection and TLS Testing Tools
Diana Berbecaru, Antonio Lioy
COMPSAC2
2026 An Automatic Large-scale Tool for X.509v3 Certificate Collection and Analysis
Diana Berbecaru, Antonio Lioy, Anuar Elio Magliari
ICC2
2026 Implicit end-point attestation for trusted channel establishment in the keystone TEE
abstract
Nowadays, various contexts and applications include IoT devices. Due to their limited resources and power constraints, these systems are a possible threat vector that adversaries may exploit for cyberattacks. Despite the protection of network communication with Secure Channels, such as TLS and IPsec, the endpoint with which we exchange information may still be compromised. Thus, an adversary may obtain access to sensitive information or send corrupted data without being detected by the other network nodes. Remote Attestation is a possible security control that can detect device misbehaviours, allowing an external entity to verify a platform’s trustworthiness. Attestation reports contain system measures and configuration information to prove the system state. So, the external entity can verify the platform’s authenticity and integrity by comparing the data included in the report with the corresponding expected values. Several solutions addressing this issue are presented in the literature, including Remote Attestation over secure channels. Trusted Channels is the name given to these protocols, as the trustworthiness of the endpoints is a security property guaranteed by the Channel, in addition to the properties of a secure channel. This paper proposes a new certification protocol for IoT devices that merges Remote Attestation with the issuance of a certificate for a key pair generated and stored securely on the platform. This new credential enables the establishment of TLS channels; therefore, the other endpoint obtains information about the node’s trustworthiness. We implemented the protocol within the Keystone framework, which enables a customizable Trusted Execution Environment that provides the Remote Attestation mechanism.
Giacomo Bruno, Silvia Sisinni, Enrico Bravi, Lorenzo Ferro, Flavio Ciravegna, Antonio Lioy
Comput. Networks6
2025 Securing IoT Devices: An Overview
abstract
IoT devices are becoming increasingly popular. However, they are vulnerable to several security attacks because of their resource-constrained nature, making it challenging to protect them with traditional security countermeasures. To cope with the resource limitations of these devices, researchers have proposed ad-hoc versions of classical security controls, such as cryptography and hardware root-of-trust. Lightweight cryptography focuses on developing efficient cryptographic algorithms regarding required memory and processing power. CBOR X. 509 certificates are a lightweight and secure way to represent X. 509 certificates. They are significantly smaller than traditional DERencoded certificates and can be encoded and decoded more efficiently. This makes them well-suited for use in IoT devices, where resources are often limited. Remote Attestation (RA) is a security mechanism that permits a trusted party to verify that a platform behaves as expected. RA techniques are generally not suitable for constrained devices, as they require additional hardware components or extensions. Recently, several proposals have been proposed to provide similar security capabilities to devices with very low computational resources. This can be used to detect and prevent malicious devices from accessing IoT networks. This paper analyses some of these new proposals, technologies, and possible integrations to create secure and efficient IoT systems.
Enrico Bravi, Antonio Lioy
ISCC2
2025 Application Integrity Verification in Confidential Computing Scenario
abstract
The proliferation of cloud computing has transformed the deployment and scalability of applications, enabling organizations to leverage virtualized infrastructures for enhanced flexibility and efficiency. However, this shift has also introduced significant security and privacy challenges, particularly concerning the protection of sensitive data during processing. Confidential Computing has emerged as a paradigm to address these concerns by safeguarding data in use through hardwarebased Trusted Execution Environments (TEEs). TEEs provide isolated environments that ensure the confidentiality and integrity of code and data, even in the presence of potentially compromised host systems. Despite the advancements in TEE technologies, the heterogeneity among implementations poses challenges for developers aiming to create portable and secure applications. Enarx, an open-source project under the Confidential Computing Consortium, addresses this issue by offering a platformagnostic framework that abstracts the complexities of various TEE architectures, facilitating the deployment of applications across different environments. While Enarx ensures the attestation of the underlying hardware and its own components, it currently lacks mechanisms to allow remote attestation of user-developed applications deployed and running within the TEE. This paper proposes an extension to the Enarx framework that incorporates a mechanism that enables application-level remote attestation, guaranteeing the trustworthiness of workloads deployed in TEEs. By integrating a Trust Monitor system into the remote attestation process, our approach enables the validation of application authenticity and integrity, thereby strengthening the overall security posture of Confidential Computing deployments. This advancement is particularly pertinent for sectors requiring stringent data protection measures, such as finance, healthcare, and critical infrastructure.
Enrico Bravi, Silvia Sisinni, Antonio Lioy
ISCC3
2025 Towards Quantum-Resistant Trusted Computing: Architectures for Post-Quantum Integrity Verification Techniques
abstract
Trust is the core building block of secure systems, and it is enforced via methods to guarantee that a specific system is properly configured and works as expected. In this context, a Root of Trust (RoT) establishes a trusted environment, where both data and code are authenticated via a digital signature, which is based on asymmetric cryptography. Unfortunately, this kind of crypto is vulnerable to the threat posed by Quantum Computers (QCs). Firmware, being the earliest layer of trust, faces unique risks due to its longevity and difficult update. Transitioning firmware protection to Post-Quantum Cryptography (PQC) is urgent, since it lowers the risk derived from exposing all computing and network devices to quantum-based attacks. This paper offers an analysis of the most common trust techniques and their roadmap towards a Post-Quantum (PQ) world, by investigating the current status of PQC and the challenges posed by such algorithms in existing Trusted Computing (TC) solutions from an integration perspective. Furthermore, this paper proposes an architecture for PQ TC techniques based on integrity verification, addressing the imperative for immediate adoption of quantum-resistant algorithms.
Grazia D'Onghia, Antonio Lioy
ISCC2
2024 Threat-TLS: A Tool for Threat Identification in Weak, Malicious, or Suspicious TLS Connections
abstract
Various applications running in network-based, mobile, Internet of Things, or embedded systems environments exploit the Transport Layer Security (TLS) protocol to secure communication channels. However, in the last decade, several attacks have been discovered that exploit weaknesses in the protocol specification, the extensions, the cryptographic algorithms, or in the implementation and deployment of TLS-enabled software or libraries. A classical solution to counter TLS attacks on a target is to scan the installed TLS software (via dedicated software or services) and update it with versions that are resistant to attacks. However, an (internal) attacker might even temporarily corrupt the end node so that it becomes vulnerable to TLS attacks. So, the TLS scanning operations should be performed often, wasting resources of the monitored target. We propose a network-based intrusion detection tool named Threat-TLS, aimed to individuate weak, suspicious, or malicious TLS connections in intercepted traffic by looking for TLS patterns that contain features exploited to perform attacks, like old protocol versions, weak algorithms, or extensions. We have tested the proposed tool in a testbed environment by exploiting two famous tools, namely Suricata and Zeek, illustrating its performance in detecting some TLS attacks.
Diana Berbecaru, Antonio Lioy
ARES2
2024 Shaping a Quantum-Resistant Future: Strategies for Post-Quantum PKI
abstract
As the quantum computing era approaches, securing classical cryptographic protocols becomes imperative. Public key cryptography is widely used for signature and key exchange but it’s the type of cryptography more threatened by quantum computing. Its application typically requires support via a public-key certificate, which is a signed data structure and must therefore face twice the quantum challenge: for the certified keys and for the signature itself. We present the latest developments in selecting robust Post-Quantum algorithms and investigate their applicability in the Public Key Infrastructure context. Our contribution entails defining requirements for a secure transition to a quantum-resistant Public Key Infrastructure, with a focus on adaptations for the X.509 certificate format. Additionally, we explore transitioning Certificate Revocation List and Online Certificate Status Protocol to support quantum-resistant algorithms. Through comparative analysis, we elucidate the complex transition to a quantum-resistant PKI.
Grazia D'Onghia, Diana Berbecaru, Antonio Lioy
ISCC3
2024 MATCH-IN: Mutual Attestation for Trusted Collaboration in Heterogeneous IoT Networks
abstract
As the Internet of Things (IoT) continues to evolve, ensuring the security and trustworthiness of devices within heterogeneous IoT networks becomes of paramount importance. This paper presents MATCH-IN (Mutual Attestation for Trusted Collaboration in Heterogeneous IoT Networks), a novel approach to establish trusted connections based on mutual attestation between IoT devices that dynamically join a network. Drawing inspiration from the Trusted Computing Group’s "Device Identifier Composition Engine" specification, MATCH-IN introduces a comprehensive scheme for device mutual attestation. The proposed schema enhances the security posture of unstructured IoT networks by enabling devices to mutually attest their identities and configurations, without the need for a centralized verifier for checking the trustworthiness of devices, while these operate in the field. Through a detailed exploration of the DICE specification, this paper provides insights into the integration of MATCH-IN within the context of diverse IoT environments. Our approach aims to foster trusted collaboration among heterogeneous IoT devices, laying the foundation for enhanced security and reliability in the rapidly expanding IoT landscape.
Silvia Sisinni, Diana Berbecaru, Valerio Donnini, Antonio Lioy
ISCC4
2024 Integrity Management in Softwarized Networks
abstract
Nowadays, there is a growing inclination towards network softwarization, wherein functions once handled by specialized hardware are now executed as software components on general-purpose nodes. This can be achieved with Network Function Virtualization (NFV) and Software Defined Networking (SDN), offering advantages such as flexibility and reduced equipment costs. However, these paradigms, reliant on software and operating as a distributed system, introduce security challenges, including threats to software integrity through network or physical manipulation. To address these concerns, Remote Attestation techniques can be employed to enable a party to assess the software and configuration integrity of a network node. In complex network environments, different attestation frameworks may be deployed, depending on the type of hardware and software to be attested. To streamline this process, we present an extended design and implementation of our Trust Monitor architecture, implementing the Trust Manager defined by ETSI for NFV environments. This enhances flexibility by supporting the integration of multiple attestation frameworks based on different technologies. We present also how the Trust Monitor integrates into the IETF RATS architecture and how it interacts with its other elements. Through experimental tests, we demonstrate that the proposed implementation is scalable and effective in attesting both physical and virtual entities, such as Kubernetes pods.
Enrico Bravi, Antonio Lioy, Diana Berbecaru
NOMS2
2024 A novel architecture to virtualise a hardware-bound trusted platform module
abstract
Security and trust are particularly relevant in modern softwarised infrastructures, such as cloud environments, as applications are deployed on platforms owned by third parties, are publicly accessible on the Internet and can share the hardware with other tenants. Traditionally, operating systems and applications have leveraged hardware tamper-proof chips, such as the Trusted Platform Modules (TPMs) to implement security workflows, such as remote attestation, and to protect sensitive data against software attacks. This approach does not easily translate to the cloud environment, wherein the isolation provided by the hypervisor makes it impractical to leverage the hardware root of trust in the virtual domains. Moreover, the scalability needs of the cloud often collide with the scarce hardware resources and inherent limitations of TPMs. For this reason, existing implementations of virtual TPMs (vTPMs) are based on TPM emulators. Although more flexible and scalable, this approach is less secure. In fact, each vTPM is vulnerable to software attacks both at the virtualised and hypervisor levels. In this work, we propose a novel design for vTPMs that provides a binding to an underlying physical TPM; the new design, akin to a virtualisation extension for TPMs, extends the latest TPM 2.0 specification. We minimise the number of required additions to the TPM data structures and commands so that they do not require a new, non-backwards compatible version of the specification. Moreover, we support migration of vTPMs among TPM-equipped hosts, as this is considered a key feature in a highly virtualised environment. Finally, we propose a flexible approach to vTPM object creation that protects vTPM secrets either in hardware or software, depending on the required level of assurance.
Marco de Benedictis, Ludovic Jacquin, Ignazio Pedone, Andrea S. Atzeni, Antonio Lioy
Future Gener. Comput. Syst.5
2023 A Flexible Trust Manager for Remote Attestation in Heterogeneous Critical Infrastructures
abstract
Nowadays, critical infrastructures are managed through paradigms such as cloud/fog/edge computing and Network Function Virtualization (NFV), providing advantages as flexibility, availability, and reduced management costs. These paradigms introduce several advantages but – given their nature of physically distributed systems – leave room for various security threats, such as software integrity attacks. To counter these threats, Trusted Computing and Remote Attestation (RA) techniques can be used, to allow a third party (Verifier) to verify the software and configuration integrity of a platform (Attester). In environments composed of different objects, several RA frameworks (hardware-based, software-based, or hybrid) might need to be deployed, depending on the capabilities of the attested elements. To ease this process, we propose a new design and implementation of our Trust Monitor (TM) architecture, which implements the Trust Manager specified by ETSI for NFV environments, making it more flexible and usable in different contexts. In addition, we define a generic model for performing RA in heterogeneous environments by employing various RA technologies. More specifically, the extended TM allows flexible RA in hybrid infrastructures composed of different objects, i.e., physical nodes, virtual machines, containers, pods, and enclaves. Through tests performed in an experimental testbed, we show that the proposed implementation is scalable and usable in heterogeneous contexts.
Enrico Bravi, Diana Berbecaru, Antonio Lioy
CloudCom3
2023 A Model for Automated Cybersecurity Threat Remediation and Sharing
abstract
This paper presents an approach to the automatic remediation of threats reported by Cyber Threat Intelligence. Remediation strategies, named Recipes, are expressed in a close-to-natural language for easy validation. Thanks to the developed models, they are interpreted, contextualized, and then translated into CACAO Security playbooks, a standard format ready for automatic enforcement, without human intervention. The presented approach also allows sharing of remediation procedures on threat-sharing platforms (e.g. MISP) which improves the overall security posture. The effectiveness of the approach has been tested in the context of two EC-funded projects.
Francesco Settanni, Leonardo Regano, Cataldo Basile, Antonio Lioy
NetSoft4
2022 (POSTER) Using MACsec to protect a Network Functions Virtualisation infrastructure
abstract
IEEE 802.1AE is a standard for Media Access Control security (MACsec), which enables data integrity, authentication, and confidentiality for traffic in a broadcast domain. This protects network communications against attacks at link layer, hence it provides a higher degree of security and flexibility compared to other security protocols, such as IPsec. Softwarised network infrastructures, based on Network Functions Virtualisation (NFV) and Software Defined Networking (SDN), provide higher flexibility than traditional networks. Nonetheless, these networks have a larger attack surface compared to legacy infrastructures based on hardware appliances. In this scenario, communication security is important to ensure that the traffic in a broadcast domain is not intercepted or manipulated. We propose an architecture for centralised management of MACsec-enabled switches in a NFV environment. Moreover, we present a PoC that integrates MACsec in the Open Source MANO NFV framework and we evaluate its performance.
Antonio Lioy, Ignazio Pedone, Silvia Sisinni
ISCC1
2022 A model of capabilities of Network Security Functions
abstract
This paper presents a formal model of the features, named security capabilities, offered by the controls used for enforcing security policies in computer networks. It has been designed to support policy refinement and policy translation and address useful, practical tasks in a vendor-independent manner. The model adopts state-of-the-art design patterns and has been designed to be extensible. The model describes the actions that the controls can perform (e.g. deny packets or encrypt flows), the conditions to select on what to apply the actions, how to compose valid configuration rules from them, and how to build configurations from rules. It proved effective to model filtering controls and iptables.
Cataldo Basile, Daniele Canavese, Leonardo Regano, Ignazio Pedone, Antonio Lioy
NetSoft5
2019 A proposal for trust monitoring in a Network Functions Virtualisation Infrastructure
abstract
Network Functions Virtualisation (NFV) is a novel paradigm for softwarisation of network functions that allows an operator to leverage large scale virtualisation to enhance availability and flexibility of typical network and security services offered to end users. Virtual Network Functions are proposed as an alternative to traditional hardware appliances, with the aim of reducing maintenance and upgrade costs and enhance the provisioning and on-demand placement of network functions. Although promising, this paradigm introduces relevant challenges in the field of security, as the attack surface of a virtualised architecture is larger than a traditional hardware-based network platform. In fact, not only it is affected by both generic threats of virtualisation and networking domains, it also introduces new threats due to the combination of these domains. In this work, we propose the design of a centralized monitoring and reporting solution to assess the trustworthiness of a NFV infrastructure, named Trust Monitor. Moreover, we present an open-source prototype for the proposed solution, which is tailored for the Security-as-a-Service use case and integrated with a reference NFV framework.
Marco de Benedictis, Antonio Lioy
NetSoft2
2019 Integrity verification of Docker containers for a lightweight cloud environment
Marco de Benedictis, Antonio Lioy
Future Gener. Comput. Syst.2
2019 Towards an Efficient Management and Orchestration Framework for Virtual Network Security Functions
abstract
The recent years have witnessed a growth in the number of users connected to computer networks, due mainly to megatrends such as Internet of Things (IoT), Industry 4.0, and Smart Grids. Simultaneously, service providers started offering vertical services related to a specific business case (e.g., automotive, banking, and e-health) requiring more and more scalability and flexibility for the infrastructures and their management. NFV and SDN technologies are a clear way forward to address these challenges even though they are still in their early stages. Security plays a central role in this scenario, mainly because it must follow the rapid evolution of computer networks and the growing number of devices. The main issue is to protect the end-user from the increasing threats, and for this reason, we propose in this paper a security framework compliant to the Security-as-a-Service paradigm. In order to implement this framework, we leverage NFV and SDN technologies, using a user-centered approach. This allows to customize the security service starting from user preferences. Another goal of our work is to highlight the main relevant challenges encountered in the design and implementation of our solution. In particular, we demonstrate how significant is to choose an efficient way to configure the Virtual Network Security Functions in terms of performance. Furthermore, we also address the nontrivial problem of Service Function Chaining in an NFV MANO platform and we show what are the main challenges with respect to this problem.
Ignazio Pedone, Antonio Lioy, Fulvio Valenza
Secur. Commun. Networks2
2019 Providing digital identity and academic attributes through European eID infrastructures: Results achieved, limitations, and future steps
abstract
Summary Electronic identity is getting an increased importance nowadays since relentless digitalization and 24/7 connectivity continue to transform everyday life. To support the recognition of electronic identification cross‐border within the European Union, the European Commission (EC) released the eIDAS Regulation, which became effective on September 2018. To put eIDAS in practice, the EC has supported the definition of the technical specification; it provides a sample implementation; and it coordinates the eIDAS Network composed of eIDAS nodes of various countries. Each eIDAS node has a generic part required for the communication with the other nodes, and a specific part that each country has to modify independently according to its legal, operational, and technical requirements. Although this specific part is very important because it affects the node flexibility and the interaction with the other actors at the national level, it is less known in practice. We describe the adaptation of this specific part in Italy to perform authentication and provision of attributes through the STORK and STORK 2.0 infrastructures (the predecessors of eIDAS), based on our experience in the homonym projects. Significant effort is spent currently to build real services exploiting the eIDAS infrastructure, eg, the eID4U project proposes eIDAS node extension with new attributes required by some common academic services, such as student registration at a foreign university. We describe the support for these new attributes in the eIDAS nodes and the modification of the specific part of the Italian eIDAS node to allow attributes retrieval from different authorities.
Diana Berbecaru, Antonio Lioy, Cesare Cameroni
Softw. Pract. Exp.2
2019 Adding Support for Automatic Enforcement of Security Policies in NFV Networks
abstract
This paper introduces an approach toward the automatic enforcement of security policies in network functions virtualization (NFV) networks and dynamic adaptation to network changes. The approach relies on a refinement model that allows the dynamic transformation of high-level security requirements into configuration settings for the network security functions (NSFs), and optimization models that allow the optimal selection of the NSFs to use. These models are built on a formalization of the NSF capabilities, which serves to unequivocally describe what NSFs are able to do for security policy enforcement purposes. The approach proposed is the first step toward a security policy aware NFV management, orchestration, and resource allocation system-a paradigm shift for the management of virtualized networks-and it requires minor changes to the current NFV architecture. We prove that our approach is feasible, as it has been implemented by extending the OpenMANO framework and validated on several network scenarios. Furthermore, we prove with performance tests that policy refinement scales well enough to support current and future virtualized networks.
Cataldo Basile, Fulvio Valenza, Antonio Lioy, Diego R. López, Antonio Pastor 0001
IEEE/ACM Trans. Netw.3
2017 Remotely Assessing Integrity of Software Applications by Monitoring Invariants: Present Limitations and Future Directions
Alessio Viticchié, Cataldo Basile, Antonio Lioy
CRiSIS3
2017 SHIELD: A novel NFV-based cybersecurity framework
abstract
SHIELD is an EU-funded project, targeting at the design and development of a novel cybersecurity framework, which offers security-as-a-Service in an evolved telco environment. The SHIELD framework leverages NFV (Network Functions Virtualization) and SDN (Software-Defined Networking) for virtualization and dynamic placement of virtualised security appliances in the network (virtual Network Security Functions - vNSFs), Big Data analytics for real-time incident detection and mitigation, as well as attestation techniques for securing both the infrastructure and the services. This papers discusses key use cases and requirements for the SHIELD framework and presents a high-level architectural approach.
Georgios Gardikis, K. Tzoulas, K. Tripolitis, A. Bartzas, Socrates Costicoglou, Antonio Lioy, Bernat Gastón, Carolina Fernandez 0001, Cristian Dávila, Antonis Litke, Antonio Pastor 0001, Jerónimo Núñez, Ludovic Jacquin, Hamza Attak, N. Davri, Georgios Xilouris, M. Kafetzakis, Dimitris Katsianis, Ioannis Neokosmidis, M. Terranova, C. Giustozzi, T. Batista, R. Preto, Eleni Trouva, Y. Angelopoulos, Akis Kourtis
NetSoft6
2017 Towards Optimally Hiding Protected Assets in Software Applications
abstract
Software applications contain valuable assets that, if compromised, can make the security of users at stake and cause huge monetary losses for software developers. Software protections are applied whenever assets' security is at risk as they delay successful attacks. Unfortunately, protections might have recognizable fingerprints that can expose the location of the assets, thus facilitating the attackers' job. This paper presents a novel approach that uses three main methods to hide the protected assets: protection fingerprint replication, enlargement, and shadowing. The best way to hide assets is determined with a Mixed Integer Linear Program, which is automatically built starting from the code structure, the protected assets, and a model that depicts the dependencies among protection and the fingerprints they generate. Additional constraints, such as overhead limits are also supported to ensure the usability of the protected applications. Our implementation, which uses off-the-shelf solvers, showed promising performance and scalability on large applications.
Leonardo Regano, Daniele Canavese, Cataldo Basile, Antonio Lioy
QRS4
2017 Classification and Analysis of Communication Protection Policy Anomalies
abstract
This paper presents a classification of the anomalies that can appear when designing or implementing communication protection policies. Together with the already known intra- and inter-policy anomaly types, we introduce a novel category, the inter-technology anomalies, related to security controls implementing different technologies, both within the same network node and among different network nodes. Through an empirical assessment, we prove the practical significance of detecting this new anomaly class. Furthermore, this paper introduces a formal model, based on first-order logic rules that analyses the network topology and the security controls at each node to identify the detected anomalies and suggest the strategies to resolve them. This formal model has manageable computational complexity and its implementation has shown excellent performance and good scalability.
Fulvio Valenza, Cataldo Basile, Daniele Canavese, Antonio Lioy
IEEE/ACM Trans. Netw.4
2016 On the design, implementation and integration of an Attribute Provider in the Pan-European eID infrastructure
abstract
This paper describes the design and implementation of an Attribute Provider (AP), compatible with the protocol defined in the STORK 2.0 electronic identity European infrastructure that provides cross-border authentication and attribute management in web-based services. Currently, this infrastructure is used as basis in some European countries to implement the recently adopted eIDAS Regulation on electronic identification and trust services for electronic transactions in the internal market. For example, in the e-SENS project the existing nodes of the STORK 2.0 infrastructure are linked to new nodes implementing the eIDAS technical specification, to create a unique interoperability platform. In our work, we considered several key aspects that have been underlined by the National Strategy for Trusted Identities in Cyberspace in USA, e.g. the possibility to incorporate attribute services in identity architectures, the principle of data minimization (provide the minimum set of attributes required so the AP should not overshare as default), and the problem of user consent. We provide also a solution to integrate the proposed AP with an existing database. We believe our work is useful for various identity, attribute and service providers that would connect in the future to the eIDAS interoperability framework.
Diana Berbecaru, Antonio Lioy
ISCC2
2016 Efficient Attribute Management in a Federated Identity Management Infrastructure
abstract
Federated Identity Management technologies are exploited for user authentication in a number of network services but their ease of use and efficient attribute handling are still open issues. We present the STORK 2.0 pan-European infrastructure which supports attribute management, and we propose a data structure, named Attribute Object Identifier (AOI), and its integration into the STORK 2.0 architecture to allow faster access to attributes.
Diana Berbecaru, Antonio Lioy
PDP2
2016 Towards Automatic Risk Analysis and Mitigation of Software Applications
Leonardo Regano, Daniele Canavese, Cataldo Basile, Alessio Viticchié, Antonio Lioy
WISTP5
2015 A novel approach for integrating security policy enforcement with dynamic network virtualization
abstract
Network function virtualization (NFV) is a new networking paradigm that virtualizes single network functions. NFV introduces several advantages compared to classical approaches, such as the dynamic provisioning of functionality or the implementation of scalable and reliable services (e.g., adding a new instance to support demands). NFV also allows the deployment of security controls, like firewalls or VPN gateways, as virtualized network functions. However, currently there is not an automatic way to select the security functions to enable and to configure the selected ones according to a set of user's security requirements. This paper presents a first approach towards the integration of network and security policy management into the NFV framework. By adding to the NFV architecture a new software component, the Policy Manager, we provide NFV with an easy and effective way for users to specify their security requirements and a process that hides all the details of the correct deployment and configuration of security functions. To perform its tasks, the Policy Manager uses policy refinement techniques.
Cataldo Basile, Antonio Lioy, Christian Pitscheider, Fulvio Valenza, Marco Vallini
NetSoft2
2015 Offloading personal security applications to a secure and trusted network node
abstract
The current device-centric protection model against security threats has serious limitations from the final user perspective, among the other the necessity to keep each device updated with the latest security updates and the necessity to replicate all the security polices across all devices. In our model, the protection is decoupled from the users terminals and it is provided through a Trusted Virtual Domain (TVD) instantiated in future edge routers. Each TVD provides unified and homogeneous security for a single user, irrespective of the terminal employed. This paper shows a first prototype implementing this concept through a network element, called Network Edge Device, capable of running the proposed virtualized architecture and making extensive use of SDN technologies, with the aim at providing a uniform security level for the final user.
Roberto Bonafiglia, Francesco Ciaccia, Antonio Lioy, Mario Nemirovsky, Fulvio Risso
NetSoft3
2015 A Formal Model of Policy Reconciliation
abstract
This paper proposes a novel approach to perform the reconciliation of security policies by means of user-defined reconciliation strategies. The proposed policy reconciliation model allows several degree of freedom when specifying reconciliation strategies, which can be based not only on rule actions, like most of the works in literature, but also on other rule data (e.g., the conditions) and other external data (e.g., rule priorities, policy priorities). Additionally, it can be applied to reconcile policies at runtime and off-line, that is, it allows the generation of a reconciled policy. Moreover, the reconciliation process generates a detailed report on all the decision taken. Given its expressiveness, the approach can be also applied to simplify the policy specification process. The model has been validated against a practical example, the definition of the application layer filtering policy in a corporate scenario, and its performance has been tested with synthetic policies. Both validation and performance analysis gave encouraging results.
Cataldo Basile, Antonio Lioy, Christian Pitscheider, Shilong Zhao
PDP2
2015 Exploiting the European Union trusted service status list for certificate validation in STORK: design, implementation, and lessons learnt
abstract
Summary Since December 2009, the European Union Trusted Service Status Lists (TSLs) have been specified and adopted across European Union countries in order to enable the verification of digital signatures with legal values. This paper deals with the exploitation of TSLs in real digital services, other than electronic signatures, that is for certificate validation service. In particular, we used such lists in the service provided by the pan‐European Secure identTities acRoss boRders linKed identity management infrastructure in order to validate X.509 public key certificates. In addition, we propose an XML data structure to be used in conjunction with a TSL, in the form of a Trust Service Association (TrSA) file, to hold trust relationships between different services in a TSL. The TrSA file in conjunction with the TSLs may be used directly by the service providers or users to validate certificates. For the generation of the TSLs, we propose also a tool for automatic generation of the TSLs, named TSLGenerator. Copyright © 2014 John Wiley & Sons, Ltd.
Diana Berbecaru, Antonio Lioy
Softw. Pract. Exp.2
2015 Analysis of Application-Layer Filtering Policies With Application to HTTP
abstract
Application firewalls are increasingly used to inspect upper-layer protocols (as HTTP) that are the target or vehicle of several attacks and are not properly addressed by network firewalls. Like other security controls, application firewalls need to be carefully configured, as errors have a significant impact on service security and availability. However, currently no technique is available to analyze their configuration for correctness and consistency. This paper extends a previous model for analysis of packet filters to the policy anomaly analysis in application firewalls. Both rule-pair and multirule anomalies are detected, hence reducing the likelihood of conflicting and suboptimal configurations. The expressiveness of this model has been successfully tested against the features of Squid, a popular Web caching proxy offering various access control capabilities. The tool implementing this model has been tested on various scenarios and exhibits good performance.
Cataldo Basile, Antonio Lioy
IEEE/ACM Trans. Netw.2
2014 Inter-technology Conflict Analysis for Communication Protection Policies
Cataldo Basile, Daniele Canavese, Antonio Lioy, Fulvio Valenza
CRiSIS3
2014 Practical Assessment of Biba Integrity for TCG-Enabled Platforms
abstract
Checking the integrity of an application is necessary to determine if the latter will behave as expected. The method defined by the Trusted Computing Group consists in evaluating the fingerprints of the hardware and software components of a platform required for the proper functioning of the application to be assessed. However, this only ensures that a process was working correctly at load-time but not for the whole life-cycle. Policy-Reduced Integrity Measurement Architecture (PRIMA) addresses this problem by enforcing a security policy that denies information flows from potentially malicious processes to an application target of the evaluation and its dependencies (required by CW-Lite, an evolution of the Biba integrity model). Given the difficulty of deploying PRIMA, as platform administrators have to tune their security policies to satisfy the CW-Lite requirements, we propose Enhanced IMA, an extended version of the Integrity Measurement Architecture (IMA) that, unlike PRIMA, works almost out of the box and just reports information flows instead of enforcing them. In addition, we introduce a model to evaluate the information reported by Enhanced IMA with existing techniques.
Roberto Sassu, Gianluca Ramunno, Antonio Lioy
TrustCom3
2013 Privacy-by-design cloud computing through decentralization and real life trust
abstract
Existing Cloud services suffer from several weaknesses regarding privacy and security [1]. A preliminary analysis shows that they are subject to a number of vulnerabilities ranging from insecure interfaces to insecure Hypervisors [2]. Starting from these vulnerabilities as the first step of a broader research activity, we came up with a new approach that is very promising in re-visiting security and privacy problems in Cloud based systems.
Leucio Antonio Cutillo, Antonio Lioy
P2P2
2013 Improved Reachability Analysis for Security Management
abstract
Network reachability analysis evaluates the actual connectivity of an IT infrastructure. It can be performed by active network probing or examining a formal model of a target IT infrastructure. The latter approach is preferable as it does not interfere with the normal network behaviour and can be easily used during development and change management phases. In this paper we propose a novel modelling approach based on a geometric representation of device configurations (i.e. the policies) which allows the computation of the reachability analysis using the concept of equivalent firewall. An equivalent firewall is a fictitious device, ideally connected directly to the communication endpoints, that summarizes the network behaviour between them. Our model supports routing, filtering and address translation devices in a computationally effective way. In fact, the experimental results show that the computation of equivalent firewalls is performed in a negligible time and that then the reachability queries are answered in few seconds.
Cataldo Basile, Daniele Canavese, Antonio Lioy, Christian Pitscheider
PDP3
2013 Towards Privacy-by-Design Peer-to-Peer Cloud Computing
Leucio Antonio Cutillo, Antonio Lioy
TrustBus2
2013 FcgiOCSP: a scalable OCSP-based certificate validation system exploiting the FastCGI interface
abstract
SUMMARY Certificate validation, one of the most important and complex tasks in Public Key Infrastructures, is still a challenging topic nowadays because of the scalability and complexity issues related to this process. Validation of an X.509 certificate requires checking its revocation status, either by consulting the so‐called Certificate Revocation Lists or by contacting a specific server via the Online Certificate Status Protocol (OCSP). Because more and more entities extensively need to validate the certificates used for various purposes (such as digital signature, server authentication, and secure e‐mail), the OCSP servers become overloaded. Thus, an increasing effort is currently dedicated to the creation and management of scalable certificate validation architectures. In this work, we discuss scalability challenges in OCSP‐based certificate validation, and we propose a method to evaluate the OCSP server performance in stress conditions. Next, we experimentally measure the performance, expressed in terms of response time and throughput, of some open‐source OCSP implementations. Finally, we propose and evaluate our own scalable OCSP‐based certificate validation system, named FcgiOCSP, as it exploits the FastCGI interface. Experimental results demonstrate the high performance of FcgiOCSP with respect to other OCSP implementations evaluated in this work. Copyright © 2012 John Wiley & Sons, Ltd.
Diana Berbecaru, Matteo Maria Casalino, Antonio Lioy
Softw. Pract. Exp.3
2012 Network-Level Access Control Policy Analysis and Transformation
abstract
Network-level access control policies are often specified by various people (network, application, and security administrators), and this may result in conflicts or suboptimal policies. We have defined a new formal model for policy representation that is independent of the actual enforcement elements, along with a procedure that allows the easy identification and removal of inconsistencies and anomalies. Additionally, the policy can be translated to the model used by the target access control element to prepare it for actual deployment. In particular, we show that every policy can be translated into one that uses the “First Matching Rule” resolution strategy. Our policy model and optimization procedure have been implemented in a tool that experimentally demonstrates its applicability to real-life cases.
Cataldo Basile, Alberto Cappadonia, Antonio Lioy
IEEE/ACM Trans. Netw.3
2011 Exploiting Proxy-Based Federated Identity Management in Wireless Roaming Access
Diana Berbecaru, Antonio Lioy, Marco Domenico Aime
TrustBus2
2011 On the Performance of Secure Vehicular Communication Systems
abstract
Vehicular communication (VC) systems are being developed primarily to enhance transportation safety and efficiency. Vehicle-to-vehicle communication, in particular, frequent cooperative awareness messages or safety beacons, has been considered over the past years as a main approach. Meanwhile, the need to provide security and to safeguard users' privacy is well understood, and security architectures for VC systems have been proposed. Although technical approaches to secure VC have several commonalities and a consensus has formed, there are critical questions that have remained largely unanswered: Are the proposed security and privacy schemes practical? Can the secured VC systems support the VC-enabled applications as effectively as unsecured VC would? How should security be designed so that its integration into a VC system has a limited effect on the system's performance? In this paper, we provide answers to these questions, investigating the joint effect of a set of system parameters and components. We consider the state-of-the-art approach in secure VC, and we evaluate analytically and through simulations the interdependencies among components and system characteristics. Overall, we identify key design choices for the deployment of efficient, effective, and secure VC systems.
Giorgio Calandriello, Panagiotis Papadimitratos, Jean-Pierre Hubaux, Antonio Lioy
IEEE Trans. Dependable Secur. Comput.4
2011 Automatic (Re)Configuration of IT Systems for Dependability
abstract
This paper proposes an approach for automatic, service-driven configuration of networked IT systems focused on achieving a specific set of dependability properties. An automatic process starts from a service-level model to generate dependable configurations for the managed IT infrastructure. The process uses an ontology to model the services and their dependability requirements, the IT infrastructure, the available dependability mechanisms, and their configuration. Configurations are computed by model transformation rules which implement various dependability strategies with different degrees of requirements' satisfaction. Alternative configurations are generated to allow reconfiguring the system taking into account incidents or other operational conditions. A sample system hosting services based on web technologies is used as a proof-of-concept to illustrate application and extent of our approach.
Marco Domenico Aime, Antonio Lioy, Paolo Carlo Pomi
IEEE Trans. Serv. Comput.2
2010 Towards a Network-Independent Policy Specification
abstract
A very ambitious objective in the field of policy-based systems is the provision of an intuitive and transparent way for policy specification, refinement and enforcement. This is one of the key enabling technologies for a simplified security management of complex networked environments. Currently, security policies are enforced by configuring the end devices by means of low-level device-specific parameters manually derived from high level specifications. This process, defined as policy translation, is still performed without a holistic view of the overall security requirements. This paper presents the Network Contextualization Tool (NCTool), a software supporting administrators in performing network dependent activities when configuring security enabled devices. The tool provides a great advantage in the management of complex networks. In fact, it simplifies the network administration tasks and reduces effort and responsibilities for the administrators, thus decreasing the risk of mistaken configurations.
Cataldo Basile, Antonio Lioy, Marco Vallini
PDP2
2010 The ForwardDiffSig Scheme for Multicast Authentication
abstract
This paper describes ForwardDiffSig, an efficient scheme for multicast authentication with forward security. This scheme provides source authentication, data integrity, and non-repudiation since it is based on the use of asymmetric cryptography. At the same time, it offers also protection against key exposure as it exploits OptiSum, our optimized implementation of the ISum forward-secure signature scheme. A tradeoff exists in the used keys: Short keys provide speed at the signer, whereas long keys are preferable for long-term non-repudiation. Performance has been evaluated with a custom packet simulator and shows that, by grouping the packets, ForwardDiffSig is efficient in terms of speed even for long keys at the price of a significant signature overhead. Therefore, ForwardDiffSig is fast, exhibits low delay, and provides non-repudiation and protection against key exposure, but has a nonnegligible impact in applications with strict energy or bandwidth constraints.
Diana Berbecaru, Luca Albertalli, Antonio Lioy
IEEE/ACM Trans. Netw.3
2009 MagicNET: Security System for Development, Validation and Adoption of Mobile Agents
abstract
Current research in the area of mobile agents' security mainly deals with protection and security for agents and agents' runtime platforms. Mobile agent systems usually do not provide an extensive security methodology for the entire agent's life cycle, from agent's creation to its deployment and execution. In this paper we propose a comprehensive secure system for deployment of mobile agents. The system provides methodology that spans a number of phases in agent's lifetime: it starts from agent creation and ends with agent's execution. It addresses classification, validation, publishing, discovery, adoption, authentication and authorization of agents. Our system is based on secure web services and uses RBAC XACML policies and SAML protocol.
Muhammad Awais Shibli, Sead Muftic, Alessandro Giambruno, Antonio Lioy
NSS4
2009 A unified and flexible solution for integrating CRL and OCSP into PKI applications
abstract
Abstract Public key certificates (PKCs) are used nowadays in several security protocols and applications, so as to secure data exchange via transport layer security channels, or to protect data at the application level by means of digital signatures. However, many security applications often fail to manage properly the PKCs, in particular when checking their validity status. These failures are partly due to the lack of experience (or training) of the users who configure these applications or protocols, and partly due to the scarce support offered by some common cryptographic libraries to the application developers. This paper describes the design and implementation of a light middleware dealing with certificate validation in a unified way. Our middleware exploits on one side the libraries that have already been defined or implemented for certificate validation, and it constructs a thin layer, which provides flexibility and security features to the upper layer applications. In our current approach, this layer boasts an integrated approach to support various certificate revocation mechanisms, it protects the applications from some common security attacks, and offers several configuration and performance options to the programmers and to the end users. We describe the architecture of this approach as well as its practical implementation in the form of a library based on the famous OpenSSL security library, and that can be easily integrated with other certificate‐aware security applications. Copyright © 2009 John Wiley & Sons, Ltd.
Diana Berbecaru, Amarkumar Desai, Antonio Lioy
Softw. Pract. Exp.3
2006 A Wireless Distributed Intrusion Detection System and a New Attack Model
abstract
Denial-of-Service attacks, and jamming in particular, are a threat to wireless networks because they are at the same time easy to mount and difficult to detect and stop. We propose a distributed intrusion detection system in which each node monitors the traffic flow on the network and collects relevant statistics about it. By combining each node’s view we are able to tell if (and which type of) an attack happened or if the channel is just saturated. However, this system opens the possibility for misuse. We discuss the impact of the misuse on the system and the best strategies for each actor.
Marco Domenico Aime, Giorgio Calandriello, Antonio Lioy
ISCC3
2005 The Wireless Opaque Channel to Contrast Information Leakage
abstract
Widespread adoption of wireless devices has considerably enlarged the domain of user applications, but consequently specific issues related to a secure use of these devices arise, in particular when user privacy may be at stake. This work aims at assuring an adequate degree of privacy when using pervasive wireless devices, by means of a modified flooding routing algorithm and known anonymity techniques, which however have not yet been applied to wireless scenarios. The level of privacy reached is evaluated by traffic matrices and experimental tests.
Marco Domenico Aime, Andrea S. Atzeni, Antonio Lioy
WOWMOM3
2005 Incremental Trust: Building Trust from Past Experience
abstract
Emerging ubiquitous computing leverages the need for automated trust management models. We take a domestic network of both fixed and mobile nodes as our reference scenario and investigate how nodes can build trust exclusively based on their past experience. In a home network, trust propagation can be superfluous, while direct evaluation of peers' behaviour during repeated interactions has a key role. We present experimental results on the use of statistics for automated trust building and outline numerous issues that should be analysed further.
Marco Domenico Aime, Antonio Lioy
WOWMOM2
2002 Security aspects in standard certificate revocation mechanisms: a case study for OCSP
abstract
One of the highly sensitive problems that need careful consideration when employing public-key technology in IT systems is the validation of the digital certificates used. In particular, one of the steps that must be performed is checking the revocation status of the certificate. With real-time revocation checking, a PKI-enabled system that needs to validate a certificate executes an on-line transaction with a specialized server - designated by a certification authority to provide signed responses containing certificate status information. At the end of the transaction, an indication of the current revocation status of the certificate is returned. This paper presents the implementation of a system providing online certificate status service to end entities and proposes a simple OCSP (on-line certificate status protocol) client API which can be easily integrated into PKI-aware applications with the aim of performing on-line revocation-checking. Finally, the implementation's performance was measured and the acquired results are presented and analyzed.
Diana Berbecaru, Antonio Lioy, Marius Marian
ISCC2
2001 On the Complexity of Public-Key Certificate Validation
Diana Berbecaru, Antonio Lioy, Marius Marian
ISC2
2001 Synthesis of power-managed sequential components based oncomputational kernel extraction
abstract
This paper introduces a power optimization paradigm for sequential components based on the concept of computational kernel, a highly simplified logic block whose behavior mimics the steady-state behavior of the original specification. We present a flexible framework that supports a number of algorithmic options for carrying out kernel extraction. We first describe an exact symbolic procedure that is applicable to components for which only a functional specification (i.e., the state transition graph) is available. Due to its computational complexity, this procedure is mainly of theoretical interest and it is not usable for large circuits. We then propose two approximate algorithms that can be adopted in practical situations. The first one is simulation-based and it is suitable to cases where input data streams representing typical operation of the component are available. The second approach performs kernel extraction by iteratively refining a structural representation of the component obtained through synthesis. The impact of the power optimization paradigm based on kernel extraction is demonstrated by the results of extensive experimentation carried out on a number of benchmarks of different characteristics and nature.
Luca Benini, Giovanni De Micheli, Antonio Lioy, Enrico Macii, Giuseppe Odasso, Massimo Poncino
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.3
2000 A Flexible Management Framework for Certificate Status Validation
Antonio Corradi, Rebecca Montanari, Cesare Stefanelli, Diana Berbecaru, Antonio Lioy, Fabio Maino
SEC5
2000 Security issues in control, management and routing protocols
Madalina Baltatu, Antonio Lioy, Fabio Maino, Daniele Mazzocchi
Comput. Networks2
1999 Automatic Synthesis of Large Telescopic Units Based on Near-Minimum Timed Supersetting
abstract
In high-performance systems, variable-latency units are often employed to improve the average throughput when the worst-case delay exceeds the cycle time. Traditionally, units of this type have been hand-designed. In this paper, we propose a technique for the automatic synthesis of variable-latency units that is applicable to large data-path modules. We define and study an optimization problem, timed supersetting, whose solution is at the kernel of the procedure for automatic generation of variable-latency units. We contribute a new algorithm for solving timed supersetting in the most difficult case, that is, when the timing behavior of the circuit is expressed through an accurate delay model. The proposed solution overcomes the computational limitations of previous approaches and its robustness is experimentally demonstrated by obtaining high-throughput, variable-latency implementations for all the largest circuits in the Iscas '85 and Iscas '89 benchmark suites, as well as for some realistic, high-performance arithmetic units.
Luca Benini, Giovanni De Micheli, Antonio Lioy, Enrico Macii, Giuseppe Odasso, Massimo Poncino
IEEE Trans. Computers3
1998 Computational Kernels and their Application to Sequential Power Optimization
abstract
We introduce a new sequential optimization paradigm based on the extraction of computational kernels, i.e., logic blocks whose behavior mimics the steady-state behavior of the original circuit. We present a procedure for the automatic extraction of such kernels directly from the gate-level description of the design. The advantage of this solution with respect to extraction algorithms based on STG analysis is that it can be applied to large circuits, since it does not require to manipulate the STG specification.
Luca Benini, Giovanni De Micheli, Antonio Lioy, Enrico Macii, Giuseppe Odasso, Massimo Poncino
DAC3
1998 Timed Supersetting and the Synthesis of Telescopic Units
abstract
In high-performance systems, variable-latency units are often employed to improve the average throughput when the worst-case delay exceeds the cycle time. Although such units have traditionally been hand-designed, recent results have shown that variable-latency units can be automatically generated. Unfortunately, the existing synthesis procedure has limited applicability due to its computational complexity. In this work, we define and study an optimization problem, timed supersetting, whose solution is at the kernel of the procedure for automatic generation of variable-latency units. We contribute a new algorithm for solving timed supersetting in the most difficult case, that is, when the timing behaviour of the circuits is expressed through an accurate delay model. The proposed solution overcomes the complexity limitation of previous approaches, and its robustness is experimentally demonstrated by obtaining high-throughput, variable-latency implementations for all the largest circuits in the Iscas'85 and Iscas'89 benchmark suites.
Luca Benini, Giovanni De Micheli, Antonio Lioy, Enrico Macii, Giuseppe Odasso, Massimo Poncino
Great Lakes Symposium on VLSI3
1997 Accurate Entropy Calculation for Large Logic Circuits Based on Output Clustering
abstract
Entropy-based estimation is a promising approach to the problem of predicting the power dissipated by a digital system for which an architectural description is available. For achieving good performance of the power estimation tool, an accurate computation of the input and output entropies of the Boolean functions implemented by the circuit is essential. For small designs, the calculation can be carried out exactly, thanks to the compact representation and ease of manipulation of Boolean and pseudo-Boolean functions provided by BDD-like data structures. For large circuits, on the other hand, resorting to approximate computations is mandatory. Techniques to determine an upper bound on the exact entropy values have been developed in the recent past. Unfortunately, the results provided by such techniques are, in some ceases, not satisfactory; in other words, the assumptions made to simplify the calculation-total absence of correlation among the output signals of a circuit are in many cases too strong to guarantee a reasonable lightness of the approximate entropy values to the exact ones. In this paper, we propose a method to determine the entropy of large logic circuits with a level of accuracy which is far beyond the one provided by existing approaches. We partition the set of output signals according to the information about the functional correlations that may exist among such signals, and we compute the approximate entropy values after performing output clustering. Experimental results, obtained on a large collection of benchmarks, are very promising.
Antonio Lioy, Enrico Macii, Massimo Poncino, Massimo Rossello
Great Lakes Symposium on VLSI1
1997 Secure document management and distribution in an open network environment
Antonio Lioy, Fabio Maino, Marco Mezzalama
ICICS1
1997 Non-intrusive authentication
Daniel Alberto Galliano, Antonio Lioy, Fabio Maino
SEC2
1993 On the Resetability of Synchronous Sequential Circuits
Antonio Lioy, Massimo Poncino
ISCAS1
1993 A study of the resetability of synchronous sequential circuits
Antonio Lioy, Massimo Poncino
Microprocess. Microprogramming1
1993 On the Equivalence of Fanout-Point Faults
abstract
Test-equivalent faults are commonly used in test generation and fault simulation to reduce the number of explicitly addressed faults. At the gate level, practical equivalence rules are confined to faults on the input and output terminals of Boolean gates and those related to fanout-free wires. It is shown that under some conditions equivalence may also be stated between faults on a fanout stem and its branches. A modification of the standard fault folding algorithm is proposed, which leads to reducing the number of target faults and occasionally identifying logic redundancies. Application to real designs shows that the added computational complexity is negligible, while for some classes of CMOS circuits hard-to-simulate faults are eliminated and hence their fault simulation time is drastically reduced.>
Antonio Lioy
IEEE Trans. Computers1
1992 A quadratic programming approach to estimating the testability and coverage distributions of a VLSI circuit
Hassan A. Farhat, Steven G. From, Antonio Lioy
Microprocess. Microprogramming3
1991 An algebraic approach to test generation for sequential circuits
abstract
The authors describe an algebraic algorithm for automatic test pattern generation for sequential circuits. Three innovative concepts have been introduced in order to reduce the computational time required for pattern generation. These are: firstly, circuit partitioning in fanout-free regions; then, computation of observability and excitability functions for state propagation and justification; and finally, assignment of an observability and an excitability order to each node of the decision tree, for fast test pattern detection of each fault.>
Antonio Lioy, Enrico Macii, Angelo Raffaele Meo, Matteo Sonza Reorda
Great Lakes Symposium on VLSI1
1991 A hierarchical multi-level test generation system
abstract
The authors describe a multi-level ATPG system which handles circuits consisting of 'switch' transistors, Boolean gates, and open-output gates (i.e., tristate, open-collector, open-emitter). Both combinational and synchronous sequential circuits are supported, with provision for full-scan, partial-scan, and non-scan design. The most remarkable features of the system are an unified approach to test generation (suitable to compiled-code implementation) and automatic extraction of hierarchy.>
Antonio Lioy, Massimo Poncino
Great Lakes Symposium on VLSI1
1991 Looking for Functional Fault Equivalence
abstract
Recognition of test equivalent faults is usually applied to reduce the number of target faults for test generation and fault simulation. Also fault diagnosis benefits from this knowledge as it allows fast dropping of undistinguishable faults. Equivalent faults are generally identified by mean of a structural analysis of the circuit. Functionally equivalent faults are not considered as their identification is computationally too expensive for real circuits. This paper presents new theorems about functional fault equivalence and dominance. They provide a constructive basis upon which a functional fault collapsing algorithm is built. Application to a set of benchmark circuits establish that identification of functionally equivalent faults is feasible, and that their number may be a not negligible fraction of the faults in a circuit. Results apply both to combinational and synchronous sequential circuits.
Antonio Lioy
ITC1
1990 Assessing the diagnostic power of test pattern sets
Paolo Camurati, Antonio Lioy, Paolo Prinetto, Matteo Sonza Reorda
Microprocessing and Microprogramming2
1989 A multilevel hardware description language
Silvano Gai, Antonio Lioy
Microprocess. Microprogramming2
1988 Adaptative backtrace and dynamic partitioning enhance ATPG
abstract
Two improvements to existing automatic-test-pattern-generation (ATPG) algorithms are proposed. First, an adaptive technique has been introduced to solve internal conflicts in the backtrace phase of previous algorithms. This has proved useful in reducing the number of backtracks, allowing tests to be generated faster and more redundancies to be identified. In addition, to cope with the large size of present VLSI circuits, the author has also proposed to dynamically identify useless regions, which can be dropped from consideration. This way it has been possible to considerably speed up the overall test generation tasks. An ATPG system based on these ideas has been developed and it has proved effective in generating test for large circuits.>
Antonio Lioy
ICCD1
1986 VLSI implementation of linear feedback shift registers for microprocessor applications
Silvano Gai, Antonio Lioy, Fabio Neri
Microprocessing and Microprogramming2