EDBT 2026 Demo / reviewers in the wild / expert
Yasuo Okabe
dblp:68/4022
· DBLP profile ↗
57ranked-venue papers
1as first author
23since 2021 · last 2026
0000-0003-0825-2256ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 28 · 1 first-author · 17 since 2021Applied, interdisciplinary, general and emerging computing · 27 · 1 first-author · 16 since 2021Theory of computation · 7Computer networks · 5Security and privacy · 5 · 3 since 2021Systems, architecture and hardware · 3 · 1 since 2021Databases, data management, data science and information retrieval · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Performance Evaluation of EDHOC and COSE Over MQTT in Constrained Iot Environments
Yeahjun Heo, Yasuo Okabe |
COMPSAC | 2 |
| 2026 | Generating Diverse Network Control Policies for Cyber Attack Response Support via Service Dependency Graph Exploration
Shinnosuke Kataoka, Daisuke Kotani, Yasuo Okabe |
COMPSAC | 3 |
| 2026 | Automated Attack Trace Generation: Investigating Coverage and Cleanup Resilience
Masahito Kumazaki, Daisuke Kotani, Yasuo Okabe |
COMPSAC | 3 |
| 2026 | Location-Based Wi-Fi AP Discovery Optimization for Vehicle-to-Infrastructure Communication
Hitoshi Morioka, Yasuo Okabe |
COMPSAC | 3 |
| 2026 | From SAINT to COMPSAC: A Quarter Century of Partnership between IEEE-CS and IPSJ
Yasuo Okabe |
COMPSAC | 1 |
| 2026 | Kubernetes-Based Transparent Orchestration of Heterogeneous IoT Devices Through Peripheral Abstraction with Webassembly
Soichiro Ueda, Ai Nozaki, Daisuke Kotani, Yasuo Okabe |
COMPSAC | 4 |
| 2026 | Security Evaluation of Multi-Slot Slider Captchas Against Deep Learning-Based Attacks
Hanghui Ye, Yasuo Okabe |
COMPSAC | 2 |
| 2025 | Operational Planning of a Home Energy Management System Using Regional Weekly Weather Forecasts to Mitigate Surplus ElectricityabstractPhotovoltaic (PV) systems often generate surplus electricity during daytime when production exceeds demand. To address this, existing studies optimize energy storage and heat-pump (HP) water heater operations but typically focus only on same-day forecasts. This study proposes using regional weekly weather forecasts to enhance PV surplus management. Solar irradiance is estimated via machine learning trained on historical data, using daily and weekly forecasts as inputs. Predicted irradiance informs PV generation forecasts, guiding optimal operational planning for battery storage and HP water heaters through linear programming. Plans are adjusted based on actual generation data. Results indicate that perfectly accurate weekly forecasts could reduce surplus electricity by 16% compared to same-day forecasts. Even with estimated irradiance, integrating next-day forecasts reduces surplus by 0.66% relative to same-day predictions alone. Hiroaki Aoyama, Daisuke Kotani, Yasuo Okabe |
COMPSAC | 3 |
| 2025 | Impact Evaluation of Attacks on Data Flows in Systems With Heterogeneous Redundant ResourcesabstractCyber-physical and IoT systems gather diverse real-world data through systems created by heterogeneous hardware, software resources, and communication technologies, which introduce various threats and countermeasures. Although protecting data transmitted over the system is critical, previous work has not shown how to model these threats and countermeasures to evaluate attack impacts in each threat category. We propose a framework to evaluate the attack impact on data flows in systems with heterogeneous resources by representing the threats existing in each node and the countermeasures applied to data flows in their respective categories. Our framework determines whether a dataflow is compromised or not for each threat category. We define a hierarchical model of resources and vulnerabilities, represent threats and countermeasures by vectors, and develop a metric to quantify attack impacts. To validate the framework, we assess a simple IoT sensor system combining ZigBee and LoRa, demonstrating how it captures protocol and device differences. As a result, our framework flags only threats with realistic attack risks as compromised. Kosei Shimoda, Daisuke Kotani, Yasuo Okabe |
COMPSAC | 3 |
| 2025 | Tiaccoon: Unified Access Control with Multiple Transports in Container NetworksabstractContainer orchestration tools use container overlay networks for communications between containers and enforcement of network access control policies to containers. Use of appropriate transports such as UNIX domain socket and RDMA for communications between containers provide higher throughput and lower latency than TCP/IP, although each transport have limitation on applicable scenarios. However, applications face challenges in flexibly selecting appropriate transports for each connection while container networks consistently apply unified network access control policies. To address this problem, we propose Tiaccoon, achieving unified access control and container communication regardless of transports by replacing the process of socket API. Tiaccoon hooks system calls related to socket API called by applications, applies access control for the connection, creates a socket with the fast transports available for communication with the destination containers, and replace the socket with the created one. Our evaluation shows Tiaccoon achieved throughput, round trip latency, and CPU time equivalent to host networks, which is better than container overlay networks. We also show Tiaccoon satisfies the requirements of container networks and can replace existing container overlay networks for connection-oriented protocols. Hiroya Onoe, Daisuke Kotani, Yasuo Okabe |
Middleware | 3 |
| 2025 | PiCoP: Service Mesh for Sharing Microservices in Multiple Environments Using Protocol-Independent Context PropagationabstractContinuous integration and continuous delivery require many production-like environments in a cluster for testing, staging, debugging, and previewing. In applications built on microservice architecture, sharing common microservices in multiple environments is an effective way to reduce resource consumption. Previous methods extend application layer protocols like HTTP and gRPC to propagate contexts including environment identifiers and to route requests. However, microservices also use other protocols such as MySQL, Redis, Memcached, and AMQP, and extending each protocol requires lots of effort to implement the extensions. This paper proposes PiCoP, a framework to share microservices in multiple environments by propagating contexts and routing requests independently of application layer protocols. PiCoP provides a protocol that propagates contexts by appending them to the front of each TCP byte stream and constructs a service mesh that uses the protocol to route requests. We design the protocol to make it easy to instrument into a system. We demonstrate that PiCoP can reduce resource usage and that it applies to a real-world application, enabling the sharing of microservices in multiple environments using any application layer protocol. Hiroya Onoe, Daisuke Kotani, Yasuo Okabe |
IEEE Trans. Cloud Comput. | 3 |
| 2024 | A Cross-Organizational Identity Proofing System for Seamless Online ID Re-Binding Leveraging Individual Number CardsabstractThis study focuses on the issue of ID management when researchers change their organizational affiliations, aiming at the effective utilization of research data in educational and research organizations. Although research data management systems are being developed at each organization, the continuous use of research data remains an issue for researchers. For example, when a researcher moves from one organization to another, the research data that was previously available to him or her becomes unavailable. In response, there is a need for a system that allows researchers to continue using their research data smoothly even if they move from one organization to another. To solve this problem, the authors propose a cross-organizational identity proofing system that ensures the continuity of IAL2/ AAL2 and completes the ID transfer online. The idea is to use researcher ID numbers, ORCID, and public personal authentication to verify the user's identity when linking the IDs before and after the transfer. To facilitate this, the study performs identity verification using an Individual Number Card (a Japanese governmental system) to enable easy ID linkage between IdPs with high identity confirmation and authentication strength. The implementation has been carried out in the development environment of Orthros, an ID linkage service provided by the National Institute of Informatics (NIl), utilizing the API service of xID Co., which is a solution for linking with the Individual Number Card. This approach is expected to overcome ID management issues associated with researcher transfers and improve the efficiency of research data use. Sayako Shimizu, Hiroyuki Sato 0002, Motonori Nakamura, Hukofumi Suzuki, Yasuo Okabe |
COMPSAC | 5 |
| 2024 | DDoS Attack Information Sharing Among CDNs Interconnected Through CDNIabstractAs CDNs facing DDoS attacks targeting some content every day, CDNI, which is designed to allow multiple CDNs to cooperate each other to distribute content more broadly, will also be targeted if CDNI distributes such content, but for small CDNs owned by ISPs or NSPs in CDNI, it is hard to mitigate large DDoS attacks continuously because of financial limitations. Considering that each CDN in CDNI is operated autonomously in terms of system, security, etc., countermeasures against DDoS attacks should be implemented autonomously in each CDN, so that one of possible countermeasures against DDoS attacks in CDNI is to share information among CDNs to cope with DDoS attacks cooperatively. However, there is no previous research about what an architecture are required or what information should be shared through them to handle DDoS attacks. In this study, we propose a system that handles DDoS attacks through information exchange with leveraging capabilities of CDNI, and we show that, through several use cases of this system, information for requesting CDNI operations and information representing the attacks are essential. Especially, in order for the CDNI to effectively respond to attacks and gain the cooperation of more CDNs, two key types of information are needed: the volume of the attack and information that helps mitigate the attack. Finally, we briefly show an example implementation approach of the architecture and a format for sharing this information by using DOTS. Kazuki Takashima, Daisuke Kotani, Yasuo Okabe |
COMPSAC | 3 |
| 2024 | Putting Authorization Servers on User-Owned Devices in User-Managed Access
Masato Hirai, Daisuke Kotani, Yasuo Okabe |
SEC | 3 |
| 2023 | Partial Outsourcing of Malware Dynamic Analysis Without Disclosing File ContentsabstractDynamic analysis is one of the methods to analyze malware. However, if the file to be analyzed contains confidential information, disclosing it to the analyst outside the organization is undesirable. Previous works proposed classifying malware while preserving privacy or outsourcing dynamic analysis, but it is challenging to outsource dynamic analysis without disclosing file contents. The proposed method builds the Local Environment for users and the Remote Environment for analysts outside the organization. We proposed partial outsourcing, which opens a file in the Local Environment, reproduces its behavior in the Remote Environment, and conducts dynamic analysis based on this information. The Local Environment hooks an API call and retrieves information on the function name and arguments. Then, the Local Environment sends the information to the Remote Environment to reproduce file behavior. Our method could reproduce most operations on files and registries but could not reproduce some operations on files. Keisuke Hamajima, Daisuke Kotani, Yasuo Okabe |
COMPSAC | 3 |
| 2023 | A Policy-Based Path Selection Mechanism in QUIC Multipath Extensionabstract2023 IEEE 47th Annual Computers, Software, and Applications Conference (COMPSAC), 26-30 June 2023, Torino, Italy Masahiro Kozuka, Yasuo Okabe |
COMPSAC | 2 |
| 2023 | Efficient Container Image Updating in Low-bandwidth Networks with Delta EncodingabstractContainers are the technology for Linux to isolate execution environments. By distributing a container image, which is a collection of files contained in the container, users can use an execution environment that includes the necessary files and libraries. However, container images are tens to hundreds of megabytes in size and require many network resources to be transferred. Especially in low-bandwidth network environments like edge computing, frequent image updating can be difficult and affect other services’ communication. In this paper, we propose a method to reduce the data size required for image updates using delta encoding. We use delta encoding to reduce data size and finish updating quickly, but generating and applying deltas is a time-consuming operation. Our method proposes DeltaMerging which enables faster delta generation by merging existing deltas, and Di3FS which applies deltas lazily. The proposed method reduces the data size required to update container images from 5 to 40% of that of existing methods. Also, the time required to generate and apply deltas is greatly reduced with DeltaMerging and Di3FS. Furthermore, the performance degradation of the application in the container was almost negligible. Naoki Matsumoto, Daisuke Kotani, Yasuo Okabe |
IC2E | 3 |
| 2023 | Protocol-Independent Context Propagation for Sharing Microservices in Multiple EnvironmentsabstractIn systems designed based on microservice architecture, many production-like environments should be deployed for testing, staging, debugging, and previewing. One way to reduce resource consumption while deploying many environments is to allow sharing of common microservices in multiple environments, and current mechanisms extend application layer protocols like HTTP and gRPC to propagate contexts including environment identifiers and to route requests. However, microservices also use other protocols such as MySQL, Redis, Memcached, and AMQP, and extending each protocol requires lots of effort to implement the extensions. This paper proposes PiCoP, a framework to propagate contexts and route requests independently of application layer protocols. PiCoP consists of a protocol that propagates contexts without interpreting application layer protocols by adding contexts to the front of each TCP byte stream and a proxy that uses the protocol to route requests. We design the protocol to make instrumentation into a system as easy as possible. We showed that PiCoP could reduce resource usage, that the proxy's communication delay is within a practical range, and that it makes sharing microservices in multiple environments with any application layer protocols possible. Hiroya Onoe, Daisuke Kotani, Yasuo Okabe |
IC2E | 3 |
| 2023 | Key Management Based on Ownership of Multiple Authenticators in Public Key Authentication
Koudai Hatakeyama, Daisuke Kotani, Yasuo Okabe |
SEC | 3 |
| 2023 | Visibility of Scan Traffic Trends in Sparsely Populated Darknets
Kodai Mizutani, Daisuke Kotani, Yasuo Okabe |
SecureComm (2) | 3 |
| 2021 | QoS Network Control for Elderly Support ServicesabstractA variety of traffic flows will be generated by various IoT devices in the home in auxiliary services for an aging society. In this study, a network control system was developed to control the Quality of Service (QoS) of its traffic according to the characteristics of devices, services, and users. Assuming a relatively small network environment such as a home network, a mechanism to easily realize QoS through centralized control using SDN and a REST API to specify QoS from applications were designed and implemented. Daisuke Kotani, Taku Tanaka, Yasuo Okabe |
COMPSAC | 3 |
| 2021 | Mutual Secrecy of Attributes and Authorization Policies in Identity FederationabstractIn modern Web services, authentication federation that separates the Identity Provider (IdP), which centrally manages authentication information such as user passwords, from the service provider (SP) is commonly used. Authorization federation in which the IdP further manages user attributes, the IdP provides attribute values to the SP, and the SP decides whether to provide the service, is used as well. However, more information about attribute values is often passed to the SP than is necessary for the authorization decision. If an authorization policy of the SP is logical expression of predicates, the expression needs to be disclosed to the IdP. There also are cases in which it is necessary to keep the authorization policies secret from the IdP and the user. Information that should be concealed may be narrowed down through multiple authorization processes, even if attributes and authorization policies can be kept secret from each other in a single authorization process. In this work, we point out and formulate these problems and provide some protocols to solve them. Satsuki Nishioka, Yasuo Okabe |
COMPSAC | 2 |
| 2021 | Analysis of Inter-regional Relationship among Regional Tier-1 ASes in the InternetabstractThe ASes on the Internet are considered to be in a hierarchical structure and are called Tier 1, Tier 2 and Tier 3 from the upper level. ASes ranked at the same Tier are believed to be in an equal relationship (a peering relationship). A subset of Tier 2 is generally regarded as Regional Tier 1 which can obtain almost all route information in a specific region without receiving them from Tier-1 ASes. The scale and the target customers of Regional Tier-1 ASes are different by the region, and such factors may result in an unequal relationship when Regional Tier-1 ASes in two countries are connected. In this paper, we analyze the connection between ASes considered as Regional Tier 1 in two countries, assuming that the target region of Regional Tier 1 is one country. Firstly, we proposed the method to identify the Regional Tier-1 ASes in each country. Next, we examined the relationships between Regional Tier-1 ASes in six countries, the top five countries with the largest number of ASes and Japan, and we confirmed that there were some connections in the transit relationships. We also found that an AS becomes a provider of many foreign Regional Tier-1 ASes, and that an AS peers with small ASes but provides transit to larger ASes in foreign countries. Takuya Urimoto, Daisuke Kotani, Yasuo Okabe |
COMPSAC | 3 |
| 2020 | Improving Attack Detection Performance in NIDS Using GANabstractNowadays, various methods are proposed to build effective anomaly-based Network Intrusion Detection System (NIDS). However, malicious packets are extremely less than normal packets and this class imbalance problem will result in low performance of attack detection. In this study, we have proposed a new hybrid oversampling model using GAN to improve attack detection performance in anomaly-based NIDS. It contains three main steps: feature extraction by Information Gain and PCA, data clustering by DBSCAN and data generation by WGAN-DIV. For performance evaluation, three HTTP only datasets: NSL-KDD-HTTP, UNSW-NB15-HTTP and Kyoto2006-Plus-HTTP are used. Six machine learning methods are utilized as anomaly-based NIDS and SMOTE is also used for comparison. Our model with XGBoost has achieved best F1-score in these three datasets from the results. Daisuke Kotani, Yasuo Okabe |
COMPSAC | 3 |
| 2020 | Centralized Control of Account Migration at Single Sign-On in ShibbolethabstractSingle Sign-On (SSO) is adopted to use multiple services with a single log-in in the Internet. However, when a user tries to change the identity provider (IdP) which is responsible for authenticating of the user, he needs to release the binding between the log-in account on the migration-source IdP and his service account on each service provider (SP), and needs to set a new binding between the account on the migration-destination IdP and the service account on the SP. There is no common migration system to support migration using the SSO function. In this research, we especially focus on Shibboleth's function as an SSO service. And we propose a protocol to migrate accounts of a user on multiple SPs at once using an attribute provider (AP) in SSO environment. Also we implement the mechanism as an open source software using SimpleSAMLphp. Satsuki Nishioka, Yasuo Okabe |
COMPSAC | 2 |
| 2020 | Coflow-Like Online Data Acquisition from Low-Earth-Orbit DatacentersabstractSatellite-based communication technology has gained much attention in the past few years, where satellites play mainly the supplementary roles as relay devices to terrestrial communication networks. Unlike previous work, we treat the low-earth-orbit (LEO) satellites as secure data storage mediums. We focus on data acquisition from a LEO satellite based data storage system (also referred to as the LEO based datacenters), which has been considered as a promising and secure paradigm on data storage. Under the LEO based datacenter architecture, one fundamental challenge is to deal with energy-efficient downloading from space to ground while maintaining the system stability. In this paper, we aim to maximize the amount of data admitted while minimizing the energy consumption, when downloading files from LEO based datacenters to meet user demands. To this end, we first formulate a novel optimization problem and develop an online scheduling framework. We then devise a novel coflow-like “Join the first K-shortest Queues (JKQ)” based job-dispatch strategy, which can significantly lower backlogs of queues residing in LEO satellites, thereby improving the system stability. We also analyze the optimality of the proposed approach and system stability. We finally evaluate the performance of the proposed algorithm through conducting emulator based simulations, based on real-world LEO constellation and user demand traces. The simulation results show that the proposed algorithm can dramatically lower the queue backlogs and achieve high energy efficiency. Huawei Huang, Song Guo 0001, Weifa Liang, Kun Wang 0005, Yasuo Okabe |
IEEE Trans. Mob. Comput. | 5 |
| 2019 | Detecting Successful Attacks from IDS Alerts Based On Emulation of Remote ShellcodesabstractServer administrators and security operation center analysts receive alerts from an intrusion detection system and check whether attacks have succeeded. However, it is difficult to handle them quickly because a tremendous number of alerts is generated in a short period of time. We propose a method to identify important alerts that lead to security incidents automatically. The key idea is to determine the success or failure of an attack based on traffic logs and the network behaviors observed during shellcode emulation. We evaluated the proposed method in terms of accuracy and performance and found that it can handle more than 60% of remote shellcodes and cope with practical attack cases. Yo Kanemoto, Kazufumi Aoki, Makoto Iwamura, Jun Miyoshi, Daisuke Kotani, Hiroki Takakura, Yasuo Okabe |
COMPSAC (2) | 7 |
| 2018 | Detecting Emerging Large-Scale Vulnerability Scanning Activities by Correlating Low-Interaction Honeypots with DarknetabstractCyberattacks such as scanning by botnet worms, falsification of web pages, and security breaches happen on the Internet every day. To minimize damage caused by such attacks, early discovery of new attack trends and quick response to incidents are essential since detection delays and slow responses to incidents will cause further damage. Typical methods to detect new large-scale attacks are: (1) analyzing data collected by the darknet, (2) analyzing data collected by honeypots, and (3) summarizing alerts made by intrusion detection systems (IDSs). A darknet is a reachable and unused address space on the Internet, and we can figure out coarse-grained attack trends, such as volume of scans to each TCP/UDP port, by analyzing packets arrived at the darknet. However, darknet traffic usually cannot provide enough payloads to analyze attacks in detail although there are various scans to applications running on one TCP/UDP port, such as Web applications. A honeypot system can intentionally be attacked so that the attack codes and attacker behaviors can be observed after they are attracted to it. A drawback is that honeypots cannot be deployed so large because attackers are very likely to become aware of honeypots whey they are deployed on a network scale like darknet. IDS alerts provide information about attacks, but in recent years attacks the are resistant to be detected by IDS are increasing. In this paper, we present a system that automatically detects new scan activities and estimates the scale of each attack by correlating the data obtained by both low-interaction honeypots and the darknet. A low-interaction honeypot collects payload in TCP stream to find attacks without depending on a specific protocol and classify attack codes in the context of applications. By analyzing the cooccurrence of attacks observed at honeypots and darknet by various features, the system estimates the scale of attacks per each attack. The evaluation result suggests that many attacks can be observed at both honeypots and darknet, so it may be useful to correlate both data by observed time. Ryoh Akiyoshi, Daisuke Kotani, Yasuo Okabe |
COMPSAC (2) | 3 |
| 2018 | Message from the CDS 2018 Workshop OrganizersabstractPresents the introductory welcome message from the conference proceedings. May include the conference officers' congratulations to all involved with the conference event and publication of the proceedings record. Ryozo Kiyohara, Yasuo Okabe, Atsushi Tagami |
COMPSAC (2) | 2 |
| 2018 | A Mixed Integer Programming Solution for Network Optimization Under Tunneling-Based Traffic Engineering SchemesabstractIn order to utilize the network resources efficiently, many traffic engineering schemes have been proposed to distribute the loads on links by controlling traffic routes. Traffic engineering based on tunneling can finely control traffic by setting a route of each flow explicitly. In the tunneling-based traffic engineering scheme, it is not easy to choose the best tunnel node pairs and the best flow allocation to the tunnels. In this paper, we propose a method to calculate an optimal solution in terms of the number of tunnels that can mitigate network congestion or the ratio of each flow on the links in a given network topology. We formulate the problems as mixed integer programming (MIP) and obtain optimal solutions using a high speed MIP solver. We have conducted experiments in the two kinds of problems on two network topologies. We calculate optimal solutions using a MIP solver, and evaluate the calculation time and improvement of network congestion by adding tunnels. Tsubasa Munemitsu, Daisuke Kotani, Yasuo Okabe |
COMPSAC (2) | 3 |
| 2018 | Message from the IWFIT 2018 Workshop OrganizersabstractPresents the introductory welcome message from the conference proceedings. May include the conference officers' congratulations to all involved with the conference event and publication of the proceedings record. Hiroyuki Ohsaki, Yasuo Okabe, Koji Okamura |
COMPSAC (2) | 2 |
| 2018 | Xilara: An XSS Filter Based on HTML Template Restoration
Keitaro Yamazaki, Daisuke Kotani, Yasuo Okabe |
SecureComm (2) | 3 |
| 2017 | Identifying link layer home network topologies using HTIPabstractIn this article, we propose a method to identify the link layer home network topology, motivated by applications to cost reduction of support centers. If the topology of home networks can be identified automatically and efficiently, it is easier for operators of support centers to identify fault points. We use MAC address forwarding tables (AFTs) which can be collected from network devices via HTIP (ITU-T G.9973, Home network Topology Identifying Protocol). There are a couple of existing methods for identifying a network topology using AFTs, but they are insufficient for our purpose; they are not applicable to some specific network topologies that are typical in home networks. Our method proposed in this paper can handle such topologies. Furthermore, our method is faster because, for detecting a leaf node at each round, the existing methods use a result of set inclusion operations, while our method only needs to check the sizes of sets, which is much less costly. We also give experimental evaluations to show the advantages of our method. Yoshiyuki Mihara, Shuichi Miyazaki, Yasuo Okabe, Tetsuya Yamaguchi, Manabu Okamoto |
CCNC | 3 |
| 2017 | A Threshold-Based Authentication System Which Provides Attributes Using Secret SharingabstractIn identity federation, each service provider verifies the identity of a user based on authentication performed by an authentication server called an Identity Provider (IdP). When the IdP suffers from a trouble such that an unauthorized person has cracked into the IdP or the IdP is unreachable due to a network problem, all services in the federation may be stopped by the single trouble. Simple replication of servers for the IdP might cause privacy concern because plain attribute values of registered users are copied to multiple servers, including servers that may not necessarily be trusted. In order to maintain the function as an IdP even under such troubles, we propose a system in which servers of the IdP are distributed and cooperate using threshold-based authentication and secret sharing. Even when some of IdPs are not available, the proposed system can provide authentication and authorization to all services in the federation by performing authentication procedure with the rest IdPs. Since attribute values are distributed to IdPs using secret sharing, an attacker cannot know the attribute values even if he successfully usurps administrator-level privilege of an IdP. We also design and implement the proposed system. We measure the execution time and verify that the computation time is sufficiently small. Furthermore, we show that our system is robust with respect to both fault tolerance and security. Tomohiro Ito, Daisuke Kotani, Yasuo Okabe |
COMPSAC (2) | 3 |
| 2017 | A Collusion-Resilient Hybrid P2P Framework for Massively Multiplayer Online GamesabstractMassively Multiplayer Online Games (MMOG), on which many users play simultaneously in a large scale virtual space on the Internet, have long been popular services. Most of MMOGs work based on Client / Server (C/S) model. Although C/S model is easy to manage games, it lacks scalability since the capacity of storages and the performance of servers that needs to be maintained by administrators increases in proportion to the number of users. In order to solve the problem of scalability, it is expected that development of a P2P-based MMOGs framework takes the place of the conventional C/S model.P2P MMOGs has a disadvantage that cheats are easily performed compared to the C/S model. There are various studies to prevent cheats on P2P models, but research on frameworks considering the possibility of collusion cheats has been rarely done so far.In this paper, we propose a collusion-resilient hybrid P2P framework for MMORPG. We first analyze the features of RPG and we clarify the requirements. We investigate cheats which may be caused in a P2P framework and we categorize cheats into three. Then, we consider about the influences and detectability of them. In order to prevent the three types of cheats, it is necessary to calculate data concealed from users on the process of events. Therefore, we suppose that there are “scramble” that encrypt data in order to conceal what the data means and that we can calculate the scrambled data without decryption. We have devised a method using secret sharing based on Chinese Remainder Theorem that has almost all properties for scramble, and discuss its use in the hybrid P2P framework. We have compared the proposed framework to conventional frameworks and a framework with ideal “scramble,” with respect to the resistance against cheats. Kazuma Matsumoto, Yasuo Okabe |
COMPSAC (2) | 2 |
| 2017 | Competitive buffer management for multi-queue switches in QoS networks using packet buffering algorithms
Koji M. Kobayashi, Shuichi Miyazaki, Yasuo Okabe |
Theor. Comput. Sci. | 3 |
| 2016 | User Identification of Pseudonyms without Identity Information Exposure in Access FederationsabstractThe concept and design of access federations have been widely accepted and their world-wide deployment is in progress. In an access federation, control of user information (personal identification information) is a key issue in its operation in terms privacy. Pseudonym is proposed and implemented as a solution to this problem. We consider a case where the requirement of privacy protection by using pseudonyms and that of user identification for service providing conflict with each other. In this paper, we propose a “counting server” for identification of different pseudonyms or social identities. SPs can use this identification information to provide special services such as student discount and limit of use. We also show an implementation of this scheme on Shibboleth/SAML platforms. Related protocols are designed, another SAML engine are provided on SP, and counting server is provided. Furthermore, we analyze this scheme, and proves the security properties. Yasuo Okabe, Motonori Nakamura |
COMPSAC | 2 |
| 2015 | Approximability of Two Variants of Multiple Knapsack Problems
Shuichi Miyazaki, Naoyuki Morimoto, Yasuo Okabe |
CIAC | 3 |
| 2014 | A packet-in message filtering mechanism for protection of control plane in openflow networksabstractProtecting control planes in networking hardware from high rate packets is a critical issue for networks under operation. One common approach for conventional networking hardware is to offload expensive functions onto hard-wired offload engines as ASICs. OpenFlow networks are expected to provide greater network control flexibility by an open interface to the packet-forwarding plane and by centralized controllers. In OpenFlow networks, the approach for conventional networking hardware alone is inadequate because it restricts a certain amount of flexibility that OpenFlow is expected to provide. Therefore, we need a generic control plane protection mechanism in OpenFlow switches as a last resort. In this paper, we propose a mechanism to filter out Packet-In messages without dropping important ones for network control. Our proposed mechanism works simply. Switches record the values of packet header fields before sending Packet-In messages, which are specified by the controllers in advance, and filter out packets that have the same values as the recorded ones. We implemented and evaluated the proposed mechanism on a prototype software switch, concluding that it dramatically reduces CPU loads in the switches and passes important Packet-In messages for network control. Daisuke Kotani, Yasuo Okabe |
ANCS | 2 |
| 2013 | Design and Implementation of a Functional Extension Framework for Authn & Authz Federation Infrastructure Using Web Browser Add-onabstractGakuNin is a federation for constructing an academic authn & authz infrastructure by using single sign-on (SSO) technology in Japan and it consists of academic eresource providers and consumers, e.g. Universities, Electric Journal Publishers and so on. The expansion of SSO target systems causes several issues in its infrastructure. In this paper, we focus on the issues, (1) rapidly increasing the importance of the user credential at the identity provider, (2) its phishing risk at service providers and (3) the difficulty of choosing own identity provider from the large number of federated providers. We propose a framework to solve the problems using web browser add-on. We have implemented a prototype of the framework. We also discuss the issues in the current implementation. Toyokazu Akiyama, Takeshi Nishimura, Kazutsuna Yamaji, Motonori Nakamura, Yasuo Okabe |
AINA | 5 |
| 2013 | Design of Cooperative Load Distribution for Addressing Flash Crowds Using P2P File Sharing NetworkabstractThe flash crowd is a network phenomenon where a network or host suddenly receives a lot of traffic. It is a serious problem for web servers because it causes the websites temporarily unavailable. However, conventional load distribution methods could not address this problem effectively by reason of that it needs a reliable projection for a peak of loads. Preparing enough infrastructures for addressing flash crowds, it is especially difficult for the administrators such as persons, not-for-profit organizations, and SOHO business operators. In many cases, these websites are not protected from flash crowds. In this paper, we propose a load distribution method for addressing flash crowds effectively by cooperating with other web servers and exchanging data in a P2P file sharing network. In our approach, web servers lent their idle resources each other, and increase the number of replicas automatically according to high demand by using P2P file sharing networks. Hiroki Okamoto, Ryosuke Matsumoto, Yasuo Okabe |
COMPSAC | 3 |
| 2013 | Toward a more practical unsupervised anomaly detection system
Hiroki Takakura, Yasuo Okabe, Koji Nakao |
Inf. Sci. | 3 |
| 2011 | Quality-aware energy routing toward on-demand home energy networking: (Position paper)abstractAn on-demand electric power supply architecture in home based on quality-aware routing is proposed. In the architecture power sources and powered devices send quality parameters by which they supply or consume electric power. The network itself chooses best matching of a source and a device, and makes reservation of a path by RSVP-based QoS routing mechanism. In this paper the basic concepts and the overview of the proposed architecture is described. Kazumi Sakai, Yasuo Okabe |
CCNC | 2 |
| 2011 | Power routing switches toward energy-on-demand home networkingabstractAn on-demand electric power supply architecture in home based on quality-aware routing is proposed. In the architecture power sources and powered devices send quality parameters by which they supply or consume electric power. The network itself chooses best matching of a source and a device, and makes reservation of a path. In this demonstration on-demand multi sources energy routing and snatching other devices' energy considering precedence on the proposed architecture with implemented routing switches are shown. Tomoki Shibata, Kazumi Sakai, Yasuo Okabe |
CCNC | 3 |
| 2010 | A Web-Based Privacy-Secure Content Trading System for Small Content Providers Using Semi-Blind Digital WatermarkingabstractA privacy-secure content trading system based on semi-blind fingerprinting is presented. Semi-blind fingerprinting provides privacy-secure content trading as secure as blind fingerprinting at feasible processing cost with sufficient robustness. This system assures a fair trading for both a content provider and a purchaser which is effective for a market where a number of small or not so reliable content providers deal with purchasers. We have been aiming at providing a useful tool for the market by overcoming the following defects. In the basic models of conventional fingerprinting, the user's security could be guaranteed only under the premise that a content provider was perfectly trustworthy. Such premise makes a system unpractical. To overcome this defect, various scheme of blind fingerprinting have been proposed in which cryptography technique is used in order to protect user's privacy. However, these are not practical due to heavy computation cost and insufficient robustness of watermark against manipulations. The semi-blind fingerprinting fulfills the need for both feasibility and robustness by altering encryption with image decomposition that blinds up an image to be unrecognizable. Image decomposition and a customized embedding algorithm are implemented to a web-based system, whose perceptual condition of decomposed images and robustness of watermark is evaluated. Mitsuo Okada, Yasuo Okabe, Tetsutaro Uehara |
CCNC | 2 |
| 2009 | Semi-blind Fingerprinting Utilizing Ordinary Existing Watermarking Techniques
Mitsuo Okada, Yasuo Okabe, Tetsutaro Uehara |
IWDW | 2 |
| 2009 | Competitive buffer management for multi-queue switches in qos networks using packet buffering algorithmsabstractThe online buffer management problem formulates the problem of queuing policies of network switches supporting QoS (Quality of Service) guarantee. We focus on multi-queue switches in QoS networks proposed by Azar et al. They introduced so-called "the relaxed model". Also, they showed that if the competitive ratio of the single-queue model is at most c, and if the competitive ratio of the relaxed model is at most c2, then the competitive ratio of the multi-queue switch model is cc2. They proved that c2d2, and obtained upper bounds on the competitive ratios for several multi-queue switch models. Koji M. Kobayashi, Shuichi Miyazaki, Yasuo Okabe |
SPAA | 3 |
| 2007 | A Robust Feature Normalization Scheme and an Optimized Clustering Method for Anomaly-Based Intrusion Detection System
Hiroki Takakura, Yasuo Okabe, Yongjin Kwon |
DASFAA | 3 |
| 2007 | A tight bound on online buffer management for two-port shared-memory switchesabstractThe online buffer management problem formulates the problem of queueing policies of network switches supporting QoS (Quality of Service) guarantee. For this problem, several models are considered. In this paper, we focus on shared memory switches with preemption. We prove that the competitive ratio of the Longest Queue Drop (LQD) policy is 4M-43M-2 in the case of N=2, where N is the number of output ports in a switch and M is the size of the buffer. This matches the lower bound given by Hahne, Kesselman and Mansour. Also, in the case of arbitrary N, we improve the competitive ratio of LQD from 2 to 2-1M minK=1, 2, ..., N{⌊MK⌋ + K - 1. Koji M. Kobayashi, Shuichi Miyazaki, Yasuo Okabe |
SPAA | 3 |
| 2005 | Single backup table schemes for shortest-path routing
Hiro Ito, Kazuo Iwama, Yasuo Okabe, Takuya Yoshihiro |
Theor. Comput. Sci. | 3 |
| 2004 | Management of parallel UBR flows over TCP in congested ATM networks
Ahmed Ishtiaq, Yasuo Okabe, Masanori Kanazawa |
Comput. Commun. | 2 |
| 2003 | Improving Performance of SCTP over Broadband High Latency NetworksabstractStream control transmission protocol (SCTP) is newly emerged protocol, which combined good qualities of TCP and UDP. It is a reliable message oriented protocol providing multistreaming and multihoming as well. The congestion control scheme of SCTP is more or less similar to that of TCP with the exception of the fast recovery algorithm. The performance of SCTP over the Internet and satellite links is improved as compared with TCP. However, the congestion control scheme of SCTP over high latency broadband networks needs further refinement in case of multiple packet losses on a link. We propose a new congestion control for SCTP and proved that performance of SCTP has significantly improved. Ishtiaq Ahmed, Yasuo Okabe, Kanazawa Masanori |
LCN | 2 |
| 2003 | Polynomial-Time Computable Backup Tables for Shortest-Path Routing
Hiro Ito, Kazuo Iwama, Yasuo Okabe, Takuya Yoshihiro |
SIROCCO | 3 |
| 2003 | Avoiding Routing Loops on the Internet
Hiro Ito, Kazuo Iwama, Yasuo Okabe, Takuya Yoshihiro |
Theory Comput. Syst. | 3 |
| 2002 | Interference among Multiple TCP Flows over Congested ATM LinksabstractIn this paper we describe the throughput performance of Linux TCP over multiple UBR flows in the presence of a high priority traffic class like CBR. We then propose a modified congestion control algorithm for TCP to improve its throughput over ATM networks in particular. The experimental results are provided to claim that our proposed algorithm is dynamically sensitive to the congestion in the network and adjusts the sender rate more accurately. At the same time the fairness and synchronization is thoroughly better between contending TCP flows. Ahmed Ishtiaq, Yasuo Okabe, Masanori Kanazawa |
LCN | 2 |
| 2002 | Avoiding Routing Loops on the Internet
Hiro Ito, Kazuo Iwama, Yasuo Okabe, Takuya Yoshihiro |
SIROCCO | 3 |
| 2001 | Separating Oblivious and Non-oblivious BPs
Kazuo Iwama, Yasuo Okabe, Toshiro Takase |
COCOON | 2 |