Jordi Forné

dblp:90/3475 · DBLP profile ↗
← Back
55ranked-venue papers
1as first author
5since 2021 · last 2025
0000-0002-8401-3292ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 23 · 1 first-author · 4 since 2021Computer networks · 12Databases, data management, data science and information retrieval · 11Artificial intelligence and machine learning · 9 · 1 since 2021Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1Theory of computation · 1Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2025 Privacy protection against user profiling through optimal data generalization
abstract
Personalized information systems are information-filtering systems that endeavor to tailor information-exchange functionality to the specific interests of their users. The ability of these systems to profile users based on their search queries at Google, disclosed locations at Twitter or rated movies at Netflix, is on the one hand what enables such intelligent functionality, but on the other, the source of serious privacy concerns. Leveraging on the principle of data minimization, we propose a data-generalization mechanism that aims to protect users’ privacy against non-fully trusted personalized information systems. In our approach, a user may like to disclose personal data to such systems when they feel comfortable. But when they do not, they may wish to replace specific and sensitive data with more general and thus less sensitive data, before sharing this information with the personalized system in question. Generalization therefore may protect user privacy to a certain extent, but clearly at the cost of some information loss. In this work, we model mathematically an optimized version of this mechanism and investigate theoretically some key properties of the privacy-utility trade-off posed by this mechanism. Experimental results on two real-world datasets demonstrate how our approach may contribute to privacy protection and show it can outperform state-of-the-art perturbation techniques like data forgery and suppression by providing higher utility for a same privacy level. On a practical level, the implications of our work are diverse in the field of personalized online services. We emphasize that our mechanism allows each user individually to take charge of their own privacy, without the need to go to third parties or share resources with other users. And on the other hand, it provides privacy designers/engineers with a new data-perturbative mechanism with which to evaluate their systems in the presence of data that is likely to be generalizable according to a certain hierarchy, highlighting spatial generalization, with practical application in popular location based services. Overall, a data-perturbation mechanism for privacy protection against user profiling, which is optimal, deterministic, and local, based on a untrusted model towards third parties.
César Gil, Javier Parra-Arnau, Jordi Forné
Comput. Secur.3
2025 Uncoordinated Syntactic Privacy: A New Composable Metric for Multiple, Independent Data Publishing
abstract
A privacy model is a privacy condition, dependent on a parameter, that guarantees an upper bound on the risk of reidentification disclosure and maybe also on the risk of attribute disclosure by an adversary. A privacy model is composable if the privacy guarantees of the model are preserved, possibly to a limited extent, after repeated independent application of the privacy model. From the opposite perspective, a privacy model is not composable if multiple independent data releases, each of them satisfying the requirements of the privacy model, may result in a privacy breach. Current privacy models are broadly classified into syntactic ones (such as k-anonymity and l-diversity) and semantic ones, which essentially refer to$\varepsilon $-differential privacy (e-DP) and variations thereof. While e-DP and its variants offer strong composability properties, syntactic notions are not composable unless data releases are conducted by a single, centralized data holder that uses specialized notions such as m-invariance and$\tau $-safety. In this work, we propose m-uncoordinated-syntactic-privacy (m-USP), the first syntactic notion with composability properties for the independent publication of nondisjoint data, in other words, without a centralized data holder. Theoretical results are formally proven, and experimental results demonstrate that the risk to individuals does not increase significantly, in contrast to non-composable methods, that are susceptible to attribute disclosure. In most cases, the utility degradation caused by the extra protection is less than 5% and decreases as the value of m increases.
Adrián Tobar Nicolau, Javier Parra-Arnau, Jordi Forné, Vicenç Torra
IEEE Trans. Inf. Forensics Secur.3
2024 On the Necessity of Counterfeits and Deletions for Continuous Data Publishing
Adrián Tobar Nicolau, Javier Parra-Arnau, Jordi Forné
MDAI3
2024 m-Eligibility With Minimum Counterfeits and Deletions for Privacy Protection in Continuous Data Publishing
abstract
Continuous data publishing consists in the republication of updating microdata. The most relevant syntactic notions in continuous data publishing are based on m-invariance. This notion enforces that no user can be distinguished among, at least,m- 1 other users, each with distinct secret data. To achieve m-invariance, the existing methods must first alter the dataset to satisfy a property called m-eligibility. Essentially, a dataset can be made m-invariant if and only if it satisfies the m-eligibility constraint. Although guaranteeing the m-eligibility property is a crucial step, no theoretical study of the best strategies to achieve it has been carried out. This paper performs such a study by giving strategies and demonstrating their optimality under two approaches: insertion of counterfeit tuples and partial publication. The empirical evaluation of our proposal shows a significant reduction on the number of modifications needed to enforce m-eligbility of up to 41% with respect to the literature.
Adrián Tobar Nicolau, Javier Parra-Arnau, Jordi Forné, Esteve Pallarès
IEEE Trans. Inf. Forensics Secur.3
2023 SoK: Differentially Private Publication of Trajectory Data
abstract
Trajectory analysis holds many promises, from improvements in traffic management to routing advice or infrastructure development. However, learning users' paths is extremely privacy-invasive. Therefore, there is a necessity to protect trajectories such that we preserve the global properties, useful for analysis, while specific and private information of individuals remains inaccessible. Trajectories, however, are difficult to protect, since they are sequential, highly dimensional, correlated, bound to geophysical restrictions, and easily mapped to semantic points of interest. This paper aims to establish a systematic framework on protective masking and synthetic-generation measures for trajectory databases with syntactic and differentially private (DP) guarantees, including also utility properties, derived from ideas and limitations of existing proposals. To reach this goal, we systematize the utility metrics used throughout the literature, deeply analyze the DP granularity notions, explore and elaborate on the state of the art on privacy-enhancing mechanisms and their problems, and expose the main limitations of DP notions in the context of trajectories.
Àlex Miranda-Pascual, Patricia Guerra-Balboa, Javier Parra-Arnau, Jordi Forné, Thorsten Strufe
Proc. Priv. Enhancing Technol.4
2020 A LINDDUN-Based framework for privacy threat analysis on identification and authentication processes
Antonio Robles-González, Javier Parra-Arnau, Jordi Forné
Comput. Secur.3
2020 The Fast Maximum Distance to Average Vector (F-MDAV): An algorithm for k-anonymous microaggregation in big data
Ana Rodríguez-Hoyos, José Estrada-Jiménez, David Rebollo-Monedero, Ahmad Mohamad Mezher, Javier Parra-Arnau, Jordi Forné
Eng. Appl. Artif. Intell.6
2020 Preserving empirical data utility in k-anonymous microaggregation via linear discriminant analysis
Ana Rodríguez-Hoyos, David Rebollo-Monedero, José Estrada-Jiménez, Jordi Forné, Luis Urquiza-Aguiar
Eng. Appl. Artif. Intell.4
2020 Mathematically optimized, recursive prepartitioning strategies for k-anonymous microaggregation of large-scale datasets
Esteve Pallarès, David Rebollo-Monedero, Ana Rodríguez-Hoyos, José Estrada-Jiménez, Ahmad Mohamad Mezher, Jordi Forné
Expert Syst. Appl.6
2019 On the regulation of personal data distribution in online advertising platforms
José Estrada-Jiménez, Javier Parra-Arnau, Ana Rodríguez-Hoyos, Jordi Forné
Eng. Appl. Artif. Intell.4
2019 Efficient k-anonymous microaggregation of multivariate numerical data via principal component analysis
David Rebollo-Monedero, Ahmad Mohamad Mezher, Xavier Casanova Colomé, Jordi Forné, Miguel Soriano
Inf. Sci.4
2017 Online advertising: Analysis of privacy threats and protection approaches
José Estrada-Jiménez, Javier Parra-Arnau, Ana Rodríguez-Hoyos, Jordi Forné
Comput. Commun.4
2017 p-Probabilistic k-anonymous microaggregation for the anonymization of surveys with uncertain participation
David Rebollo-Monedero, Jordi Forné, Miguel Soriano, Jordi Puiggali
Inf. Sci.2
2017 Shall I post this now? Optimized, delay-based privacy protection in social networks
Javier Parra-Arnau, Félix Gómez Mármol, David Rebollo-Monedero, Jordi Forné
Knowl. Inf. Syst.4
2016 k-Anonymous microaggregation with preservation of statistical dependence
David Rebollo-Monedero, Jordi Forné, Miguel Soriano, Jordi Puiggali
Inf. Sci.2
2014 Optimizing the design parameters of threshold pool mixes for anonymity and delay
David Rebollo-Monedero, Javier Parra-Arnau, Jordi Forné, Claudia Díaz
Comput. Networks3
2014 Measuring the privacy of user profiles in personalized information systems
Javier Parra-Arnau, David Rebollo-Monedero, Jordi Forné
Future Gener. Comput. Syst.3
2014 On collaborative anonymous communications in lossy networks
abstract
ABSTRACT Message encryption does not prevent eavesdroppers from unveiling who is communicating with whom, when, or how frequently, a privacy risk wireless networks are particularly vulnerable to. The Crowds protocol, a well‐established anonymous communication system, capitalizes on user collaboration to enforce sender anonymity. This work formulates a mathematical model of a Crowd‐like protocol for anonymous communication in a lossy network, establishes quantifiable metrics of anonymity and quality of service (QoS), and theoretically characterizes the trade‐off between them. The anonymity metric chosen follows the principle of measuring privacy as an attacker's estimation error. By introducing losses, we extend the applicability of the protocol beyond its original proposal. We quantify the intuition that anonymity comes at the expense of both delay and end‐to‐end losses. Aside from introducing losses in our model, another main difference with respect to the traditional Crowds is the focus on networks with stringent QoS requirements, for best effort anonymity, and the consequent elimination of the initial forwarding step. Beyond the mathematical solution, we illustrate a systematic methodology in our analysis of the protocol. This methodology includes a series of formal steps, from the establishment of quantifiable metrics all the way to the theoretical study of the privacy QoS trade‐off. Copyright © 2013 John Wiley & Sons, Ltd.
David Rebollo-Monedero, Jordi Forné, Esteve Pallarès, Javier Parra-Arnau, Carolina Tripp Barba, Luis Urquiza-Aguiar, Mónica Aguilar-Igartua
Secur. Commun. Networks2
2014 Privacy-Preserving Enhanced Collaborative Tagging
abstract
Collaborative tagging is one of the most popular services available online, and it allows end user to loosely classify either online or offline resources based on their feedback, expressed in the form of free-text labels (i.e., tags). Although tags may not be per se sensitive information, the wide use of collaborative tagging services increases the risk of cross referencing, thereby seriously compromising user privacy. In this paper, we make a first contribution toward the development of a privacy-preserving collaborative tagging service, by showing how a specific privacy-enhancing technology, namely tag suppression, can be used to protect end-user privacy. Moreover, we analyze how our approach can affect the effectiveness of a policy-based collaborative tagging system that supports enhanced web access functionalities, like content filtering and discovery, based on preferences specified by end users.
Javier Parra-Arnau, Andrea Perego, Elena Ferrari 0001, Jordi Forné, David Rebollo-Monedero
IEEE Trans. Knowl. Data Eng.4
2013 A modification of the Lloyd algorithm for k-anonymous quantization
David Rebollo-Monedero, Jordi Forné, Esteve Pallarès, Javier Parra-Arnau
Inf. Sci.2
2013 A modification of the k-means method for quasi-unsupervised learning
David Rebollo-Monedero, Marc Solé, Jordi Nin, Jordi Forné
Knowl. Based Syst.4
2012 Optimal tag suppression for privacy protection in the semantic Web
Javier Parra-Arnau, David Rebollo-Monedero, Jordi Forné, Jose L. Muñoz, Oscar Esparza
Data Knowl. Eng.3
2012 Query Profile Obfuscation by Means of Optimal Query Exchange between Users
abstract
We address the problem of query profile obfuscation by means of partial query exchanges between two users, in order for their profiles of interest to appear distorted to the information provider (database, search engine, etc.). We illustrate a methodology to reach mutual privacy gain, that is, a situation where both users increase their own privacy protection through collaboration in query exchange. To this end, our approach starts with a mathematical formulation, involving the modeling of the users' apparent profiles as probability distributions over categories of interest, and the measure of their privacy as the corresponding Shannon entropy. The question of which query categories to exchange translates into finding optimization variables representing exchange policies, for various optimization objectives based on those entropies, possibly under exchange traffic constraints.
David Rebollo-Monedero, Jordi Forné, Josep Domingo-Ferrer
IEEE Trans. Dependable Secur. Comput.2
2011 An algorithm for k-anonymous microaggregation and clustering inspired by the design of distortion-optimized quantizers
David Rebollo-Monedero, Jordi Forné, Miguel Soriano
Data Knowl. Eng.2
2010 A Privacy-Preserving Architecture for the Semantic Web Based on Tag Suppression
Javier Parra-Arnau, David Rebollo-Monedero, Jordi Forné
TrustBus3
2010 RDSR-V. Reliable Dynamic Source Routing for video-streaming over mobile ad hoc networks
Jose L. Muñoz, Oscar Esparza, Mónica Aguilar-Igartua, Víctor Carrascal Frías, Jordi Forné
Comput. Networks5
2010 Private location-based information retrieval through user collaboration
David Rebollo-Monedero, Jordi Forné, Agusti Solanas, Antoni Martínez-Ballesté
Comput. Commun.2
2010 Pervasive authentication and authorization infrastructures for mobile users
Jordi Forné, M. Francisca Hinarejos, Andrés Marín López, Florina Almenárez, Javier López 0001, José A. Montenegro, Marc Lacoste, Daniel Díaz Sánchez
Comput. Secur.1
2010 PREON: An efficient cascade revocation mechanism for delegation paths
M. Francisca Hinarejos, Jose L. Muñoz, Jordi Forné, Oscar Esparza
Comput. Secur.3
2010 Optimized query forgery for private information retrieval
abstract
We present a mathematical formulation for the optimization of query forgery for private information retrieval, in the sense that the privacy risk is minimized for a given traffic and processing overhead. The privacy risk is measured as an information-theoretic divergence between the user's query distribution and the population's, which includes the entropy of the user's distribution as a special case. We carefully justify and interpret our privacy criterion from diverse perspectives. Our formulation poses a mathematically tractable problem that bears substantial resemblance with rate-distortion theory.
David Rebollo-Monedero, Jordi Forné
IEEE Trans. Inf. Theory2
2010 From t-Closeness-Like Privacy to Postrandomization via Information Theory
abstract
t-Closeness is a privacy model recently defined for data anonymization. A data set is said to satisfy t-closeness if, for each group of records sharing a combination of key attributes, the distance between the distribution of a confidential attribute in the group and the distribution of the attribute in the entire data set is no more than a threshold t. Here, we define a privacy measure in terms of information theory, similar to t-closeness. Then, we use the tools of that theory to show that our privacy measure can be achieved by the postrandomization method (PRAM) for masking in the discrete case, and by a form of noise addition in the general case.
David Rebollo-Monedero, Jordi Forné, Josep Domingo-Ferrer
IEEE Trans. Knowl. Data Eng.2
2008 Efficient Certificate Path Validation and Its Application in Mobile Payment Protocols
abstract
Certification path validation is a complex task that implies high computational cost. In this process is necessary to verify the binding between the owner ofthe certificate and his public key. In SET protocol, the customer and merchant require to verify the certification path of their certificates to trust each other. The customer and merchant carry out several cryptographic operations to complete SET protocol including the authentication process. Because mobile devices are limited in terms of processing and storage capacities, it is relevant to reduce the computational cost required by the cryptographic operations. In this paper, we apply TRUTHC (TrustRelationship Using Two Hash Chains) to reduce thecomputational cost of cryptographic operations carried out by the customer and merchant to complete the certification path validation. In addition, we compare the results using RSA and ECDSA protocols, with a typical PKI.
Rafael Martínez-Peláez, Cristina Satizábal, Francisco Rico-Novella, Jordi Forné
ARES4
2008 Hierarchical Trust Architecture in a Mobile Ad-Hoc Network Using Ant Algorithms
abstract
Trust relationships change frequently in ad-hoc networks, so it is difficult to build certification paths among their nodes. When trust relationships are bidirectional, certification path discovery becomes more difficult because multiple paths can exist between two entities and all the options do not lead to the target entity. On the other hand, certificates can establish relationships of different trust level. In this paper, we propose a protocol that establishes a virtual hierarchy from a peer-to-peer web of trust. This protocol uses swarm intelligence to obtain information about the certification paths and to establish the trustworthiness of each node. Our protocol does not require to issue new certificates among network entities, facilitates the certification path discovery process and the maximum path length can be adapted to the characteristics of users with limited processing and storage capacity.
Cristina Satizábal, Jordi Forné, Rafael Martínez-Peláez, Francisco Rico-Novella
ARES2
2008 From t-Closeness to PRAM and Noise Addition Via Information Theory
David Rebollo-Monedero, Jordi Forné, Josep Domingo-Ferrer
Privacy in Statistical Databases2
2007 A performance model to Cooperative Itinerant Agents (CIA): a security scheme to IDS
abstract
Intrusion detection systems (IDS) based on autonomous agents are important security tools to protect distributed networks and they can be considered critical systems. For this reason; we have proposed a security scheme to verify the entities' integrity inside the IDS architecture named cooperative itinerant agent (CIA). The proposal includes software watermarking and fingerprinting techniques. Moreover, in this paper we infer a formula to calculate the time consumed by a CIA to perform entities' verification in a determined level of the infrastructure in order to evaluate the agent's scalability. The parameters of this formula are the network's throughput and delay
Rafael Páez, Cristina Satizábal, Jordi Forné
ARES3
2007 Securing Agents against Malicious Host in an Intrusion Detection System
Rafael Páez, Joan Tomàs-Buliart, Jordi Forné, Miguel Soriano
CRITIS3
2007 MAIS: Mobile Agent Integrity System - A Security System to IDS based on Autonomous Agents
Rafael Páez, Joan Tomàs-Buliart, Jordi Forné, Miguel Soriano
SECRYPT3
2007 Building a virtual hierarchy to simplify certification path discovery in mobile ad-hoc networks
Cristina Satizábal, Juan Hernández-Serrano, Jordi Forné, Josep Pegueroles 0001
Comput. Commun.3
2006 PKI Trust Relationships: from a Hybrid Architecture to a Hierarchical Model
abstract
Trust models provide a framework to create and manage trust relationships among the different entities of a public key infrastructure (PKI). These trust relationships are verified through the certification path validation process, which involves: path discovery, signature verification and revocation status checking. When trust relationships are bidirectional, multiple paths can exist between two entities, which increase the runtime of the path discovery process. In addition, validation of long paths can be difficult, especially when storage and processing capacities of the verifier are limited. In this paper, we propose a protocol to establish a hierarchical trust model from a PKI with unidirectional and bidirectional trust relationships. This protocol makes more efficient the path validation process since in a hierarchical model, trust relationships are unidirectional and paths are easy to find. In addition, our protocol allows setting a maximum path length, so it can be adapted to the features of users' terminals.
Cristina Satizábal, Rafael Páez, Jordi Forné
ARES3
2006 PROSEARCH: A Protocol to Simplify Path Discovery in Critical Scenarios
Cristina Satizábal, Rafael Páez, Jordi Forné
CRITIS3
2006 Revocation Scheme for PMI Based Upon the Tracing of Certificates Chains
M. Francisca Hinarejos, Jordi Forné
ICCSA (4)2
2006 Building Hierarchical Public Key Infrastructures in Mobile Ad-Hoc Networks
Cristina Satizábal, Jordi Forné, Juan Hernández-Serrano, Josep Pegueroles 0001
MSN2
2006 Secure brokerage mechanisms for mobile electronic commerce
Oscar Esparza, Jose L. Muñoz, Miguel Soriano, Jordi Forné
Comput. Commun.4
2005 Efficient Certificate Revocation System Implementation: Huffman Merkle Hash Tree (HuffMHT)
Jose L. Muñoz, Jordi Forné, Oscar Esparza, Manel Rey
TrustBus2
2004 Punishing manipulation attacks in mobile agent systems
abstract
Mobile agents are software entities consisting of code, data and state that can migrate autonomously from host to host performing some actions on behalf of a user. Unfortunately, security issues restrict the use of mobile agents, despite the benefits. The protection of mobile agents against the attacks of malicious hosts is considered the most difficult security problem to solve in mobile agent systems. Previously, the mobile agent watermarking approach (MAW) was presented as a new attack detection technique to aid solving the problem of malicious hosts. That approach was based on embedding a fixed watermark into the mobile agent. Some improvements are now introduced to MAW. Instead of a fixed watermark, the origin host embeds a watermark that can change dynamically during execution. In each host, the marked code creates a data container where the watermark is transferred and the results are hidden. When the agent returns home, the origin host verifies the execution integrity by applying a set of integrity rules to the containers. The paper also explains how MAW can be used to punish malicious hosts by using a trusted third party, the host revocation authority.
Oscar Esparza, Miguel Soriano, Jose L. Muñoz, Jordi Forné
GLOBECOM4
2004 Reducing the Communication Overhead of an Offline Revocation Dictionary
Jose L. Muñoz, Jordi Forné, Oscar Esparza, Josep Pegueroles 0001, Esteve Pallarès
TrustBus2
2003 Using OCSP to Secure Certificate-Using Transactions in M-commerce
Jose L. Muñoz, Jordi Forné, Oscar Esparza, Miguel Soriano
ACNS2
2003 Mobile Agent Watermarking and Fingerprinting: Tracing Malicious Hosts
Oscar Esparza, Marcel Fernandez, Miguel Soriano, Jose L. Muñoz, Jordi Forné
DEXA5
2003 Protocols for Malicious Host Revocation
Oscar Esparza, Miguel Soriano, Jose L. Muñoz, Jordi Forné
ICICS4
2003 Host Revocation Authority: A Way of Protecting Mobile Agents from Malicious Hosts
Oscar Esparza, Miguel Soriano, Jose L. Muñoz, Jordi Forné
ICWE4
2003 A protocol for detecting malicious hosts based on limiting the execution time of mobile agents
abstract
Mobile agents are software entities consisting of code and data that can migrate autonomously from host to host executing their code. Despite its benefits, security issues strongly restrict the use of code mobility. The protection of mobile agents against the attacks of malicious hosts is considered the most difficult security problem to solve in mobile agent systems. In O. Esparza et al. [2003] the authors introduced the idea of limiting the execution time in the hosts. Malicious hosts need time to analyze and modify an agent in order to take some profit. Controlling the execution time in the hosts permits detecting manipulation attacks performed by malicious hosts during the agents' execution. This paper presents a protocol for detecting malicious hosts based on the idea of execution time limiting.
Oscar Esparza, Miguel Soriano, Jose L. Muñoz, Jordi Forné
ISCC4
2003 Implementation of an Efficient Authenticated Dictionary for Certificate Revocation
abstract
Public key cryptography is widely used to provide the security services necessary to develop WEB applications. The PKI is the infrastructure that supports the public key cryptography and the revocation of certificate implies one of its major costs. The authors have developed a revocation system based on the data structures proposed by Naor and Nissim in their authenticated dictionary (AD). Our implementation is called ADMHT and in this paper we address some open issues that are necessary to implement such a system.
Jose L. Muñoz, Jordi Forné, Oscar Esparza, Miguel Soriano
ISCC2
1993 A Particular Solution to Provide Secure Communications in an Ethernet Environment
abstract
In this paper we describe the adopted and implemented solution to provide secure communications over the extended area Ethernet network of the Polytechnic University of Catalonia (U.P.C.). The developed solution is not adapted to the current standards about security on local networks (IEEE-802.10, ISO 7498-2, etc.). This solution is based on the construction of a set of ciphering devices (CRYPTONETS), whose function is similar to the one carried out by a classic bridge, but incorporating ciphering facilities. Moreover, there is a Supervision and Administration Center (SAC), which takes care of the key renewal and System Management. The cryptographic algorithms used are the D.E.S. for the Ethernet frames ciphering, and the R.S.A., for key-management.
Miguel Soriano, Jordi Forné, Francisco Recacha, José Luis Melús-Moreno
CCS2
1993 Implementation of a security system in a local area network environment
abstract
The development and the implementation of a security system in a local area network environment are presented. This system is based on an extended Ethernet network, but the methodology used is transferable to different kinds of LCNs and even metropolitan area networks (MANs), with some easy modifications. The adopted solution fulfills all the requirements that must fulfill any security protocol since: it provides cryptographic security services, it is an independent algorithm, it supports transparent operations for protected systems, it does not interfere with the operation of unprotected systems, it provides protocol support of key management independent of data security, and it provides optimal communication with unprotected systems. It also offers advantages such as flexibility, simplicity, low cost, and mobility.
Miguel Soriano, Jordi Forné, José Luis Melús-Moreno, Francisco Recacha
LCN2
1993 Secure Data Transmission in Extended Ethernet Environments
abstract
An extended Ethernet LAN is built by connecting several Ethernet segments by means of suitable devices (repeaters, bridges, etc.). A common way to make this interconnection is through a main segment, called the backbone, that joins each of the departments (or, perhaps, building floors) within the owner premises. In this kind of network, data transmission in the backbone is very sensitive to either eavesdropping or manipulation. The implementation of a cryptographic system that protects transmission (providing for both confidentiality and integrity of transmitted data) in this kind of network is addressed. The operation of the proposed system and the specific troubles encountered in implementing it in the local network of the Polytechnic University of Catalonia are presented. An analysis of the functionality of the ciphering bridges is provided and their implementation is studied in detail. Finally, the more relevant results and conclusions are given.>
Francisco Recacha, José Luis Melús-Moreno, X. Simón, Miguel Soriano, Jordi Forné
IEEE J. Sel. Areas Commun.5