Luca Ferretti

dblp:64/8772 · DBLP profile ↗
← Back
26ranked-venue papers
12as first author
10since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 6 · 3 first-author · 2 since 2021Security and privacy · 6 · 4 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 2Computer networks · 2 · 2 first-authorSoftware engineering, systems software and programming languages · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 first-author
YearPublicationVenuePosition
2026 Practical and secure history-independent indexing for queryable-encrypted databases
abstract
Queryable encryption denotes a class of techniques which enable efficient query processing on encrypted databases, but may be affected by severe leakage if associated with improper indexes for achieving sublinear times in single-round query protocols. In this paper, we present an indexing data structure based on skip lists which does not introduce any additional leakage than the order of encrypted records: our index is history-independent, does not leak duplicates, is optimized for external-memory and range queries, and operates with a stateless client, making it well-suited for deployment in real-world databases. Previous works use no indexes or multi-round protocols, possibly with stateful clients, to achieve best security, but affect performance and alter the setting of existing databases, thus limiting deployability. Otherwise, they adopt standard indexes already available within the database at the cost of affecting security guarantees, or design in-memory data structures which do not suit database contexts. We demonstrate the practicality of our index by developing a prototype extension for PostgreSQL and for Order Revealing Encryption, which achieves performance that is comparable to the standard balanced tree implementation for up to 1M records, and acceptable overhead for encrypted data when scaling to 10M records.
Mattia Trabucco, Mauro Andreolini, Luca Ferretti
J. Inf. Secur. Appl.3
2025 Network-efficient authenticated pseudonym-based V2X communications with constant revocation costs
abstract
Standard Vehicle-to-everything (V2X) communications guarantee privacy against tracking by provisioning each vehicle with many conditionally unlinkable pseudonym certificates, which can be linked to each other only with knowledge of a secret information, disclosed by ad-hoc authorities in case of misbehavior for efficient revocation. Certificates are bound to independent keys, but include pseudo-random indexing values which enable such an efficient mechanism at the expense of increasing network overhead of all V2X messages. We propose a novel network-efficient protocol where each vehicle is provisioned with conditionally unlinkable pseudo-random asymmetric key pairs, thus removing the need for linkage values and reducing network overhead while still supporting revocation at constant network costs. Our approach represents a novel application of hierarchical deterministic homomorphic key derivation schemes, which are mostly known for deterministic wallets in the context of blockchains. Compared to standards based on explicit certificates, our approach has lower network overhead, no computational overhead for securing communications, and same cryptographic assumptions. Computational costs for key management operations are higher, but still affordable. We analyze the costs of our proposal both asymptotically and analytically when instantiated with the NIST p-256 elliptic curve recommended by standards.
Mattia Trabucco, Giovanni Gambigliani Zoccoli, Mirco Marchetti, Luca Ferretti
NCA4
2025 That's what you signed for: evaluating user perception about privacy data in infotainment systems
abstract
The growing integration of data-driven technologies in automotive infotainment systems has heightened privacy concerns, yet user awareness remains limited. This study investigates how perceptions of privacy evolve following an intervention designed to raise awareness about data collection practices in these systems. A survey of 932 participants, structured in pre- and post-intervention phases, highlights significant changes in the prioritization of infotainment system features. Through paired statistical analysis and reliability validation, we observe a marked increase in the perceived importance of privacy-related aspects, particularly data precision and collection frequency. Our results underline the potential of targeted interventions to reshape consumer attitudes, emphasizing the need for enhanced transparency in automotive data management practices.
Francesco Faenza, Dario Stabili, Luca Ferretti, Mirco Marchetti
VTC2025-Fall3
2023 A big data platform exploiting auditable tokenization to promote good practices inside local energy communities
Luca Gagliardelli, Luca Zecchini, Luca Ferretti, Domenico Beneventano, Giovanni Simonini, Sonia Bergamaschi, Mirko Orsini, Luca Magnotta, Emma Mescoli, Andrea Livaldi, Nicola Gessa, Piero De Sabbata, Gianluca D'Agosta, Fabrizio Paolucci, Fabio Moretti
Future Gener. Comput. Syst.3
2022 WebDHT: browser-compatible distributed hash table for decentralized Web applications
abstract
Modern browser technologies allow running highly portable and usable complex applications. However, the inability to access all the operating system features may limit their features or performance when compared to native software in certain scenarios. We investigate the design of peer-to-peer (P2P) networks of interconnected browsers to improve applications interconnecting users, such as videotelephony, messaging and gaming. Although peer-to-peer protocols are well-established in the literature, known designs and implementations cannot be executed on browsers due to constraints of browser environments. We propose WebDHT, a webassembly library for creating P2P networks among browsers which offers topic-based peer-discovery features and integrates usable identity authentication mechanisms. WebDHT implements a variant of the Kademlia protocol based on distributed hash tables (DHT) adapted to support WebRTC protocol. WebDHT requires a native server to be available only for network bootstrap, but leverages existing browsers connected to the DHT to decentralize WebRTC signaling backends. We propose an open-source implementation and two demonstrative applications for users messaging and multimedia streaming, and analyze limitations and future work for designing better browser-compatible P2P networks.
Luca Ferretti
NCA2
2022 Scalable, Confidential and Survivable Software Updates
abstract
Software update systems must guarantee high availability, integrity and security even in presence of cyber attacks. We propose the first survivable software update framework for the secure distribution of confidential updates that is based on a distributed infrastructure with no single points of failure. Previous works guarantee either survivability or confidentiality of software updates but do not ensure both properties. Our proposal is based on an original application of a multi-authority attribute-based encryption scheme in the context of decentralized access control management that avoids single-point-of-vulnerability. We describe the original framework, propose the protocols to implement it, and demonstrate its feasibility through a security and performance evaluation.
Federico Magnanini, Luca Ferretti, Michele Colajanni
IEEE Trans. Parallel Distributed Syst.2
2021 Accountable and privacy-aware flexible car sharing and rental services
abstract
The transportation sector is undergoing rapid changes to reduce pollution and increase life quality in urban areas. One of the most effective approaches is flexible car rental and sharing to reduce traffic congestion and parking space issues. In this paper, we envision a flexible car sharing framework where vehicle owners want to make their vehicles available for flexible rental to other users. The owners delegate the management of their vehicles to intermediate services under certain policies, such as municipalities or authorized services, which manage the due infrastructure and services that can be accessed by users. We investigate the design of an accountable solution that allow vehicles owners, who want to share their vehicles securely under certain usage policies, to control that delegated services and users comply with the policies. While monitoring users behavior, our approach also takes care of users privacy, preventing tracking or profiling procedures by other parties. Existing approaches put high trust assumptions on users and third parties, do not consider users' privacy requirements, or have limitations in terms of flexibility or applicability. We propose an accountable protocol that extends standard delegated authorizations and integrate it with Security Credential Management Systems (SCMS), while considering the requirements and constraints of vehicular networks. We show that the proposed approach represents a practical approach to guarantee accountability in realistic scenarios with acceptable overhead.
Francesco Pollicino, Luca Ferretti, Dario Stabili, Mirco Marchetti
NCA2
2021 Survivable zero trust for cloud computing environments
Luca Ferretti, Federico Magnanini, Mauro Andreolini, Michele Colajanni
Comput. Secur.1
2021 Verifiable and auditable authorizations for smart industries and industrial Internet-of-Things
Luca Ferretti, Francesco Longo 0001, Giovanni Merlino, Michele Colajanni, Antonio Puliafito, Nachiket Tapas
J. Inf. Secur. Appl.1
2021 OpenABM-Covid19 - An agent-based model for non-pharmaceutical interventions against COVID-19 including contact tracing
abstract
SARS-CoV-2 has spread across the world, causing high mortality and unprecedented restrictions on social and economic activity. Policymakers are assessing how best to navigate through the ongoing epidemic, with computational models being used to predict the spread of infection and assess the impact of public health measures. Here, we present OpenABM-Covid19: an agent-based simulation of the epidemic including detailed age-stratification and realistic social networks. By default the model is parameterised to UK demographics and calibrated to the UK epidemic, however, it can easily be re-parameterised for other countries. OpenABM-Covid19 can evaluate non-pharmaceutical interventions, including both manual and digital contact tracing, and vaccination programmes. It can simulate a population of 1 million people in seconds per day, allowing parameter sweeps and formal statistical model-based inference. The code is open-source and has been developed by teams both inside and outside academia, with an emphasis on formal testing, documentation, modularity and transparency. A key feature of OpenABM-Covid19 are its Python and R interfaces, which has allowed scientists and policymakers to simulate dynamic packages of interventions and help compare options to suppress the COVID-19 epidemic.
Robert Hinch, William J. M. Probert, Anel Nurtay, Michelle Kendall, Chris Wymant, Katrina A. Lythgoe, Ana Bulas Cruz, Lele Zhao, Andrea Stewart, Luca Ferretti, Daniel Montero, James Warren, Nicole Mather, Matthew Abueg, Neo Wu, Olivier Legat, Katie Bentley, Thomas Mead, Kelvin Van-Vuuren, Dylan Feldner-Busztin, Tommaso Ristori, Anthony Finkelstein, David G. Bonsall, Lucie Abeler-Dörner, Christophe Fraser
PLoS Comput. Biol.11
2020 An experimental analysis of ECQV implicit certificates performance in VANETs
abstract
Emerging Cooperative Intelligent Transportation Systems (C-ITS) enable improved driving experience and safety guarantees, but require secure Vehicular Ad-hoc NETworks (VANETs) that must comply to strict performance constraints. Specialized standards have been defined to these aims, such as the IEEE 1609.2 that uses network-efficient cryptographic protocols to reduce communication latencies. The reduced latencies are achieved through a combination of the Elliptic Curve Qu-Vantstone (ECQV) implicit certificate scheme and the Elliptic Curve Digital Signature Algorithm (ECDSA), to guarantee data integrity and authenticity. However, literature lacks implementations and evaluations for vehicular systems. In this paper, we consider the IEEE 1609.2 standard for secure VANETs and investigate the feasibility of ECQV and ECDSA schemes when deployed in C-ITSs. We propose a prototype implementation of the standard ECQV scheme to evaluate its performance on automotive-grade hardware. To the best of our knowledge, this is the first open implementation of the scheme for constrained devices that are characterized by low computational power and low memory. We evaluate its performance against C-ITS communication latency constraints and show that, although even highly constrained devices can support the standard, complying with stricter requirements demands for higher computational resources.
Francesco Pollicino, Dario Stabili, Luca Ferretti, Mirco Marchetti
VTC Fall3
2019 Efficient License Management Based on Smart Contracts Between Software Vendors and Service Providers
abstract
In a fully interconnected world where even network-related services are becoming more dependent on software, the management of license agreements is critical for the business of any software vendor and communication provider. Building, managing and protecting the infrastructure to handle software license validation and scalability for the provider and, on the other hand, assessing the correct use of the software licenses for the vendor can become an expensive part of the relationship costs. We propose a novel approach for decentralized software licensing that leverages blockchain and smart contracts as fundamental enabling technologies. Our proposal guarantees a secure and inexpensive system with no central point of failure that can regulate the relations among untrusted parties. We describe the main design choices and present a prototype experimentation that demonstrates the benefits of the proposal in the context of virtualized network infrastructures.
Federico Magnanini, Luca Ferretti, Michele Colajanni
NCA2
2019 Fog-based Secure Communications for Low-power IoT Devices
abstract
Designing secure, scalable, and resilient IoT networks is a challenging task because of resource-constrained devices and no guarantees of reliable network connectivity. Fog computing improves the resiliency of IoT, but its security model assumes that fog nodes are fully trusted. We relax this latter constraint by proposing a solution that guarantees confidentiality of messages exchanged through semi-honest fog nodes thanks to a lightweight proxy re-encryption scheme. We demonstrate the feasibility of the solution by applying it to IoT networks of low-power devices through experiments on microcontrollers and ARM-based architectures.
Luca Ferretti, Mirco Marchetti, Michele Colajanni
ACM Trans. Internet Techn.1
2018 Analyses of Secure Automotive Communication Protocols and Their Impact on Vehicles Life-Cycle
abstract
Modern vehicles are complex cyber physical systems where communication protocols designed for physically isolated networks are now employed to connect Internet-enabled devices. This unforeseen increase in connectivity creates novel attack surfaces, and exposes safety-critical functions of the vehicle to cyber attacks. As standard security solutions are not applicable to vehicles due to resource constraints and compatibility issues, research is proposing tailored approaches to cope with existing systems and to design next generations vehicles. In this paper we focus on solutions based on cryptographic protocols to protect in-vehicle communications and prevent unauthorized manipulation of the vehicle behaviors. Existing proposals consider vehicles as monolithic systems and evaluate performance and costs of the proposed solutions without considering the complex life-cycle of automotive components and the multifaceted automotive ecosystem that includes a large number of actors. The main contribution of this paper is a study of the impact of security solutions by considering vehicles life-cycle. We model existing proposals and highlight their impacts on vehicles production and maintenance operations by taking into consideration interactions among multiple players. Finally, we give insights on the requirements of architectures for secure intra-vehicular protocols.
Dario Stabili, Luca Ferretti, Mirco Marchetti
SMARTCOMP2
2018 A symmetric cryptographic scheme for data integrity verification in cloud databases
Luca Ferretti, Mirco Marchetti, Mauro Andreolini, Michele Colajanni
Inf. Sci.1
2017 Verifiable Delegated Authorization for User-Centric Architectures and an OAuth2 Implementation
abstract
Delegated authorization protocols have become wide-spread to implement Web applications and services, where some popular providers managing people identity information and personal data allow their users to delegate third party Web services to access their data. In this paper, we analyze the risks related to untrusted providers not behaving correctly, and we solve this problem by proposing the first verifiable delegated authorization protocol that allows third party services to verify the correctness of users data returned by the provider. The contribution of the paper is twofold: we show how delegated authorization can be cryptographically enforced through authenticated data structures protocols, we extend the standard OAuth2 protocol by supporting efficient and verifiable delegated authorization including database updates and privileges revocation.
Luca Ferretti, Mirco Marchetti, Michele Colajanni
COMPSAC (2)1
2016 Implementation of Verified Set Operation Protocols Based on Bilinear Accumulators
Luca Ferretti, Michele Colajanni, Mirco Marchetti
CANS1
2016 Guaranteeing Correctness of Bulk Operations in Outsourced Databases
Luca Ferretti, Michele Colajanni, Mirco Marchetti
DBSec1
2015 Enforcing Correct Behavior without Trust in Cloud Key-Value Databases
abstract
Traditional computation outsourcing and modern cloud computing are affected by a common risk of distrust between service requestor and service provider. We propose a novel protocol, named Probus, that offers guarantees of correct behavior to both parts without assuming any trust relationship between them in the context of cloud-based key-value databases. Probus allows a service requestor to have evidence of cloud provider misbehavior on its data, and a cloud provider to defend itself from false accusations by demonstrating the correctness of its operations. Accusation and defense proofs are based on cryptographic mechanisms that can be verified by a third party. Probus improves the state-of-the-art by introducing novel solutions that allow for efficient verification of data security properties and by limiting the overhead required to provide its security guarantees. Thanks to Probus it is possible to check the correctness of all the results generated by a cloud service, thus improving weaker integrity assurance based on probabilistic verifications that are adopted by related work.
Andrea Andreoli, Luca Ferretti, Mirco Marchetti, Michele Colajanni
CSCloud2
2014 Efficient detection of unauthorized data modification in cloud databases
abstract
Cloud services represent an unprecedented opportunity, but their adoption is hindered by confidentiality and integrity issues related to the risks of outsourcing private data to cloud providers. This paper focuses on integrity and proposes an innovative solution that allows cloud tenants to detect unauthorized modifications to outsourced data while minimizing storage and network overheads. Our approach is based on encrypted Bloom filters, and is designed to allow efficient integrity verification for databases stored in the cloud. We assess the effectiveness of the proposal as well as its performance improvements with respect to existing solutions by evaluating storage and network costs.
Luca Ferretti, Fabio Pierazzi, Michele Colajanni, Mirco Marchetti, Marcello Missiroli
ISCC1
2014 Performance and Cost Evaluation of an Adaptive Encryption Architecture for Cloud Databases
abstract
The cloud database as a service is a novel paradigm that can support several Internet-based applications, but its adoption requires the solution of information confidentiality problems. We propose a novel architecture for adaptive encryption of public cloud databases that offers an interesting alternative to the tradeoff between the required data confidentiality level and the flexibility of the cloud database structures at design time. We demonstrate the feasibility and performance of the proposed solution through a software prototype. Moreover, we propose an original cost model that is oriented to the evaluation of cloud database services in plain and encrypted instances and that takes into account the variability of cloud prices and tenant workloads during a medium-term period.
Luca Ferretti, Fabio Pierazzi, Michele Colajanni, Mirco Marchetti
IEEE Trans. Cloud Comput.1
2014 Scalable Architecture for Multi-User Encrypted SQL Operations on Cloud Database Services
abstract
The success of the cloud database paradigm is strictly related to strong guarantees in terms of service availability, scalability and security, but also of data confidentiality. Any cloud provider assures the security and availability of its platform, while the implementation of scalable solutions to guarantee confidentiality of the information stored in cloud databases is an open problem left to the tenant. Existing solutions address some preliminary issues through SQL operations on encrypted data. We propose the first complete architecture that combines data encryption, key management, authentication and authorization solutions, and that addresses the issues related to typical threat scenarios for cloud database services. Formal models describe the proposed solutions for enforcing access control and for guaranteeing confidentiality of data and metadata. Experimental evaluations based on standard benchmarks and real Internet scenarios show that the proposed architecture satisfies also scalability and performance requirements.
Luca Ferretti, Fabio Pierazzi, Michele Colajanni, Mirco Marchetti
IEEE Trans. Cloud Comput.1
2014 Distributed, Concurrent, and Independent Access to Encrypted Cloud Databases
abstract
Placing critical data in the hands of a cloud provider should come with the guarantee of security and availability for data at rest, in motion, and in use. Several alternatives exist for storage services, while data confidentiality solutions for the database as a service paradigm are still immature. We propose a novel architecture that integrates cloud database services with data confidentiality and the possibility of executing concurrent operations on encrypted data. This is the first solution supporting geographically distributed clients to connect directly to an encrypted cloud database, and to execute concurrent and independent operations including those modifying the database structure. The proposed architecture has the further advantage of eliminating intermediate proxies that limit the elasticity, availability, and scalability properties that are intrinsic in cloud-based solutions. The efficacy of the proposed architecture is evaluated through theoretical analyses and extensive experimental results based on a prototype implementation subject to the TPC-C standard benchmark for different numbers of clients and network latencies.
Luca Ferretti, Michele Colajanni, Mirco Marchetti
IEEE Trans. Parallel Distributed Syst.1
2013 Access Control Enforcement on Query-Aware Encrypted Cloud Databases
abstract
The diffusion of cloud database services requires a lot of efforts to improve confidentiality of data stored in external infrastructures. We propose a novel scheme that integrates data encryption with users access control mechanisms. It can be used to guarantee confidentiality of data with respect to a public cloud infrastructure, and to minimize the risks of internal data leakage even in the worst case of a legitimate user colluding with some cloud provider personnel. The correctness and feasibility of the proposal is demonstrated through formal models, while the integration in a cloud-based architecture is left to future work.
Luca Ferretti, Michele Colajanni, Mirco Marchetti
CloudCom (2)1
2012 SNP calling by sequencing pooled samples
abstract
BACKGROUND: Performing high throughput sequencing on samples pooled from different individuals is a strategy to characterize genetic variability at a small fraction of the cost required for individual sequencing. In certain circumstances some variability estimators have even lower variance than those obtained with individual sequencing. SNP calling and estimating the frequency of the minor allele from pooled samples, though, is a subtle exercise for at least three reasons. First, sequencing errors may have a much larger relevance than in individual SNP calling: while their impact in individual sequencing can be reduced by setting a restriction on a minimum number of reads per allele, this would have a strong and undesired effect in pools because it is unlikely that alleles at low frequency in the pool will be read many times. Second, the prior allele frequency for heterozygous sites in individuals is usually 0.5 (assuming one is not analyzing sequences coming from, e.g. cancer tissues), but this is not true in pools: in fact, under the standard neutral model, singletons (i.e. alleles of minimum frequency) are the most common class of variants because P(f) ∝ 1/f and they occur more often as the sample size increases. Third, an allele appearing only once in the reads from a pool does not necessarily correspond to a singleton in the set of individuals making up the pool, and vice versa, there can be more than one read - or, more likely, none - from a true singleton. RESULTS: To improve upon existing theory and software packages, we have developed a Bayesian approach for minor allele frequency (MAF) computation and SNP calling in pools (and implemented it in a program called snape): the approach takes into account sequencing errors and allows users to choose different priors. We also set up a pipeline which can simulate the coalescence process giving rise to the SNPs, the pooling procedure and the sequencing. We used it to compare the performance of snape to that of other packages. CONCLUSIONS: We present a software which helps in calling SNPs in pooled samples: it has good power while retaining a low false discovery rate (FDR). The method also provides the posterior probability that a SNP is segregating and the full posterior distribution of f for every SNP. In order to test the behaviour of our software, we generated (through simulated coalescence) artificial genomes and computed the effect of a pooled sequencing protocol, followed by SNP calling. In this setting, snape has better power and False Discovery Rate (FDR) than the comparable packages samtools, PoPoolation, Varscan : for N = 50 chromosomes, snape has power ≈ 35%and FDR ≈ 2.5%. snape is available at http://code.google.com/p/snape-pooled/ (source code and precompiled binaries).
Emanuele Raineri, Luca Ferretti, Anna Esteve-Codina, Bruno Nevado, Simon Heath, Miguel Pérez-Enciso
BMC Bioinform.2
1994 An Arm Exoskeleton System for Teleoperation and Virtual Environments Applications
abstract
The control of exploratory and manipulative procedures in teleoperation and virtual environments requires the availability of adequate advanced interfaces capable not only of recording the movements of the human hands and arms, but also of replicating sensations of contact and collisions. In this paper the problem of replicating external forces acting against the remote/virtual arm is addressed. The design of an arm exoskeleton system developed in the authors' laboratory is presented. The exoskeleton consists of a 7 DOF actuated and sensorized mechanical structure wrapping up completely the human arm and directly supported by the shoulders and the trunk of the human operator. Emphasis is given to the implemented control procedures and to the description of the transputer-based control architecture.>
Massimo Bergamasco, Benedetto Allotta, L. Bosio, Luca Ferretti, Gianluca Parrini, G. M. Prisco, Fabio Salsedo, G. Sartini
ICRA4