Alberto Trombetta

dblp:97/2730 · DBLP profile ↗
← Back
38ranked-venue papers
5as first author
6since 2021 · last 2025
0000-0002-2567-9297ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Databases, data management, data science and information retrieval · 13 · 3 first-author · 2 since 2021Security and privacy · 12 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 5 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Systems, architecture and hardware · 2Human-computer interaction and ubiquitous computing · 2Theory of computation · 2 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Databases, data mining, and information retrieval
2 papers
Knowledge graphs · 48% Information retrieval · 48% Data integration and cleaning · 4%
Network and information security
5 papers
Privacy and data protection · 55% Authentication and access control · 29% Cryptographic protocols and secure computation · 16%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
Distributed systems · 50% Cloud and datacenter computing · 50%
Interdisciplinary, comprehensive, and emerging computing
1 paper
Bioinformatics and computational biology · 100%

Topics — the 8 heaviest of 13, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Information retrieval › document retrieval › domain-specific retrieval › biomedical information retrieval
biomedical literature search
0.712023
Graph-based Tool for Exploring PubMed Knowledge Base · ICDE 2023
Privacy and data protection
anonymization
0.332011
Privacy-Preserving Updates to Anonymous and Confidential Databases · IEEE Trans. Dependable Secur. Comput. 2011
Privately Updating Suppression and Generalization based k-Anonymous Databases · ICDE 2008
Private Updates to Anonymous Databases · ICDE 2006
Authentication and access control › trust management
trust negotiation
0.112012
A Flexible Approach to Multisession Trust Negotiations · IEEE Trans. Dependable Secur. Comput. 2012
Privacy and data protection › anonymization
k-anonymity
0.112011
Privacy-Preserving Updates to Anonymous and Confidential Databases · IEEE Trans. Dependable Secur. Comput. 2011
Distributed systems
peer-to-peer systems
0.112010
Group-Based Negotiations in P2P Systems · IEEE Trans. Parallel Distributed Syst. 2010
Cloud and datacenter computing › resource management
resource negotiation
0.112010
Group-Based Negotiations in P2P Systems · IEEE Trans. Parallel Distributed Syst. 2010
Privacy and data protection › anonymization › syntactic anonymization
generalization and suppression
0.112008
Privately Updating Suppression and Generalization based k-Anonymous Databases · ICDE 2008
Data integration and cleaning
schema matching
0.112005
A framework for modeling and evaluating automatic semantic reconciliation · VLDB J. 2005

Methods — techniques the papers use, named apart from their topics

graph-based navigation · 1.3full-text search · 1.3concept extraction · 1.3resource negotiation language · 0.2JXTA · 0.2secure two-party computation · 0.1protocol analysis · 0.1complexity analysis · 0.1secure multiparty computation · 0.1
YearPublicationVenuePosition
2025 Verifiability and Privacy in Federated Learning through Context-Hiding Multi-Key Homomorphic Authenticators
abstract
Federated Learning has rapidly expanded from its original inception to now have a large body of research, several frameworks, and sold in a variety of commercial offerings. Thus, its security and robustness is of significant importance. There are many algorithms that provide robustness in the case of malicious clients. However, the aggregator itself may behave maliciously, for example, by biasing the model or tampering with the weights to weaken the model’s privacy. In this work, we introduce a verifiable federated learning protocol that enables clients to verify the correctness of the aggregator’s computation without compromising the confidentiality of their updates. Our protocol uses a standard secure aggregation technique to protect individual model updates with a linearly homomorphic authenticator scheme that enables efficient, privacy-preserving verification of the aggregated result. Our construction ensures that clients can detect manipulation by the aggregator while maintaining low computational overhead. We demonstrate that our approach scales to large models, enabling verification over large neural networks with millions of parameters.
Simone Bottoni, Giulio Zizzo, Stefano Braghin, Alberto Trombetta
BDCAT4
2023 Graph-based Tool for Exploring PubMed Knowledge Base
abstract
Studies have shown that data retrieval and visualization tools can help health professionals to improve their understanding and communication with patients, their relationship with stakeholders, and their decision-making process. However, not many efforts have been made in this direction. In this paper, we present a prototype system for the indexing, annotation, and visualization of the PubMed knowledge base to enable the search and retrieval of health-related evidence. The proposed tool builds and keeps updated an enriched graph based on PubMed articles associating them with concepts extracted from the Unified Medical Language System (UMLS) Metathesaurus. Moreover, it allows a full-text search and graph-based navigation and supports an overview of concepts and related publications. The proposed architecture enables scale-up thanks to its containerized nature and parallelization capabilities. The code is open-source under the Apache V2 license.
Simone Bottoni, Alberto Trombetta, Flavio Bertini 0001, Danilo Montesi, Francesca Bonin, Alessandra Pascale, Martin Gleize, Pierpaolo Tommasi
ICDE2
2023 A review of domain ontologies for disability representation
Daniele Spoladore, Marco Sacco, Alberto Trombetta
Expert Syst. Appl.3
2022 Adaptive Replication Strategy in Highly Distributed Data Management Systems
abstract
The performance of the execution of an analytical workload critically impacts the speed at which companies are able to react to market changes. In the era of Big Data, it is imperative that large, complex analytics are executed in a timely manner. In this paper, we propose a method to analyze the data access pattern of analytical workloads on large datasets to identify optimal data partitioning and replication strategies. This, in turn, helps the already existing query optimization components of modern data management systems.
Simone Bottoni, Stefano Braghin, Alberto Trombetta, Srikumar Venugopal
IC2E3
2022 A Semantic-Based Collaborative Ambient-Assisted Working Framework
Turgut Cilsal, Daniele Spoladore, Alberto Trombetta, Marco Sacco
PRO-VE3
2022 Secure Selections on Encrypted Multi-writer Streams
abstract
Performing searches over encrypted data is a very current and active area. Several efficient solutions have been provided for the single-writer scenario in which all sensitive data originate with one party (the Data Owner ) that encrypts and uploads the data to a public repository. Subsequently, the Data Owner accesses the encrypted data through a Query Processor , which has direct access to the public encrypted repository. Motivated by the recent trend in pervasive data collection, we depart from this model and consider a multi-writer scenario in which the data originate with several and mutually untrusted parties, the Data Sources . In this new scenario, the Data Owner provides public parameters so that each Data Source can add encrypted items to the public encrypted stream; moreover, the Data Owner keeps some related secret information needed to generate tokens so that different Query Sources can decrypt different subsets of the encrypted stream, as specified by corresponding access policies. We propose security model for this problem that we call Secure Selective Stream ( SSS ) and give a secure construction for it based on hard problems in Pairing-Based Cryptography. The cryptographic core of our construction is a new primitive, Amortized Orthogonality Encryption , that is crucial for the efficiency of the proposed implementation for SSS .
Angelo Massimo Perillo, Giuseppe Persiano, Alberto Trombetta
ACM Trans. Priv. Secur.3
2020 An ontology-based framework for a Less Invasive Domestic Management System (LIDoMS)
abstract
Research in the fields of the Smart Home and Ambient Assisted Living has increased in the last decade. While some solutions are available to general public, there are still some concerns related to the design of smart solutions and their acceptance, especially when it comes to residents' monitoring and privacy. In this context, this paper introduces an ontology-based smart home framework, LIDoMS, aimed at focusing on inhabitants needs by providing a representation of their health conditions, while offering them customized services. End-users can interact with the system thanks to an adaptive and ubiquitous graphical interface. In this work, the ontological framework underlying LIDoMS is described; the system exploits the knowledge regarding the status of appliances and residents' location within the smart home to infer the activity they are involved in, and to provide customized adaptation of indoor comfort metrics, thus enabling a less invasive monitoring of the inhabitants. Two scenarios describe how different residents can interact with LIDoMS to personalize comfort metrics - pivotal for their health condition. Finally, a framework for the validation of LIDoMS is presented.
Daniele Spoladore, Marta Mondellini, Marco Sacco, Alberto Trombetta
Intelligent Environments4
2018 An Efficient Cryptography-Based Access Control Using Inner-Product Proxy Re-Encryption Scheme
abstract
Inner-product encryption (IPE) is a well-known functional encryption primitive that allows decryption when the inner-product of the attribute vectors, upon which the encrypted data and the decryption key depend, is equal to zero. Using IPE, it is possible to define fine-grained access policies over encrypted data whose enforcement can be outsourced to the cloud where the data are stored. However, current IPE schemes do not support efficient access policy changes. In this paper, we propose an efficient inner-product proxy re-encryption (E-IPPRE) scheme that provides the proxy server with a transformation key, with which a ciphertext associated with an attribute vector can be transformed to a new ciphertext associated with a different attribute vector, providing a policy update mechanism with a performance suitable for many practical applications. We experimentally assess the efficiency of our protocol and show that it is selective attribute-secure against chosen-plaintext attacks in the standard model under the Asymmetric Decisional Bilinear Diffie-Hellman assumption.
Masoomeh Sepehri, Alberto Trombetta, Maryam Sepehri, Ernesto Damiani
ARES2
2017 Secure and Efficient Data Sharing with Atribute-based Proxy Re-encryption Scheme
abstract
With the ever-growing production of data coming from multiple, scattered, highly dynamical sources (like those found in IoT scenarios), it is compelling to (i) provide a seamless way to outsource the management and sharing of data (as provided by cloud services); (ii) assure an high security and privacy level to such data. As such, objectives (i) and (ii) are not easily reconcilable: for example, the way data is accessed may vary according to access policies of the users and of the cloud providers that share such data. In this paper, we argue that attribute-based proxy re-encryption is a viable solution for providing the flexibility needed in dynamic scenarios like the ones envisioned by large IoT deployments. Towards, this goal we present an efficient attribute-based, proxy re-encryption scheme that can be deployed in such scenarios, along with experimental results that confirm the viability of our approach.
Masoomeh Sepehri, Alberto Trombetta
ARES2
2017 Secure Queries on Encrypted Multi-writer Tables
abstract
Performing searches on encrypted data is a very current and active area. Several efficient solutions have been provided for the single-writer scenario in which all sensitive data originates with one party (the Data Owner) that encrypts it and uploads it to a public repository. Subsequently, the Data Owner (or authorized clients, the Query Sources) perform queries on the encrypted data through a Query Processor which has direct access to the public repository. Motivated by the recent trend in pervasive data, we depart from this model and consider a multi-writer scenario in which data originates with several and mutually untrusted parties. In this new scenario the Data Owner provides public parameters so that each piece of the generated data stream can be put into an encrypted stream; moreover, the Data Owner keeps some related secret information needed to generate tokens so that different subscribers can access different subsets of the encrypted stream in clear. We consider the case in which each piece of the data stream consists of a fixed number of cells, organized in columns, and the data owner can authorize subscribers to access individual data based on the content of the columns. Current public-key functional encryption schemes provide a direct and impractical implementation of this scenario. We thus propose a new public-key primitive, Amortized Orthogonality Encryption or AOE, derived from Inner-Product Encryption, that can be used to encrypt each piece of data stream so that ciphertexts have size proportional to the un-encrypted data; moreover, encryption and decryption take time proportional to the number of columns. Previous schemes would give quadratic complexity. We provide a construction of AOE and prove its selective security under standard assumptions in a bilinear setting with prime order group. Using AOE, we implement all the basic operations in our multi-writer scenario in one round of communication. We demonstrate the feasibility and effectiveness of our proposal by providing an implementation of our scenario in C++.
Angelo Massimo Perillo, Giuseppe Persiano, Alberto Trombetta
EuroS&P3
2014 Discovering non-constant Conditional Functional Dependencies with Built-in Predicates
Antonella Zanzi, Alberto Trombetta
DEXA (1)2
2013 Data Quality Evaluation of Scientific Datasets - A Case Study in a Policy Support Context
abstract
In this work we present the rule-based approach used to evaluate the quality of scientific datasets in a policy support context. The used case study refers to real datasets in a context where low data quality limits the accuracy of the analysis results and, consequently, the significance of the provided policy advice. The applied solution consists in the identification of types of constraints that can be useful as data quality rules and in the development of a software tool to evaluate a dataset on the basis of a set of rules expressed in the XML\nmarkup language. As rule types we selected some types of data constraints and dependencies already proposed in data quality works, but we experimented also the use of order dependencies and existence constraints. The case study was used to develop and test the adopted solution, which is anyway generally applicable to other contexts.
Antonella Zanzi, Alberto Trombetta
DATA2
2013 Querying data across different legal domains
abstract
The management of legal domains is gaining great importance in the context of data management. In fact, the geographical distribution of data as implied -- for example -- by cloud-based services requires that the legal restrictions and obligations are to be taken into account whenever data circulates across different legal domains. In this paper, we start to investigate an approach for coping with the complex issues that arise when dealing with data spanning different legal domains. Our approach consists of a conceptual model that takes into account the notion of legal domain (to be paired with the corresponding data) and a reference architecture for implementing our approach in an actual relational DBMS.
Marco Taddeo, Alberto Trombetta, Danilo Montesi, Stefano Pierantozzi
IDEAS2
2013 A Framework for Trust-Based Multidisciplinary Team Recommendation
Lorenzo Bossi, Stefano Braghin, Anwitaman Datta, Alberto Trombetta
UMAP4
2013 Distributed access control policies for spectrum sharing
abstract
ABSTRACT Cognitive radio is a novel wireless communication technology that allows for adaptive configuration of the reception parameters of a terminal, based on the information collected from the environment. Cognitive radio technology can be used in innovative spectrum management approaches such as spectrum sharing, where radio frequency spectral bands can be shared among various users through a dynamic exclusive‐use spectrum access model. Spectrum sharing can be applied to various scenarios in the commercial, public safety and military domain. In some scenarios, spectrum sharing demands a mechanism for expressing and enforcing access control policies for the allocation of resources including spectral bands. The access control polices should state what are the available resources (e.g., transmission/reception bandwidths), what are the users that are allowed to access them and under what conditions. However, because of the intrinsically highly dynamic nature of specific scenarios (e.g., public safety, military), where parties with various levels of authority may suddenly appear, it may be difficult to establish in advance what are the most suitable access control policies. Trust negotiation is a well‐known approach for expressing and enforcing distributed access control policies that depend on two or more parties. In this work, we present a trust negotiation‐based framework that allows for the definition of highly expressive and flexible distributed access control policies for the allocation of spectrum resources. Copyright © 2012 John Wiley & Sons, Ltd.
Gianmarco Baldini, Igor Nai Fovino, Stefano Braghin, Alberto Trombetta
Secur. Commun. Networks4
2012 A Flexible Approach to Multisession Trust Negotiations
abstract
Trust Negotiation has shown to be a successful, policy-driven approach for automated trust establishment, through the release of digital credentials. Current real applications require new flexible approaches to trust negotiations, especially in light of the widespread use of mobile devices. In this paper, we present a multisession dependable approach to trust negotiations. The proposed framework supports voluntary and unpredicted interruptions, enabling the negotiating parties to complete the negotiation despite temporary unavailability of resources. Our protocols address issues related to validity, temporary loss of data, and extended unavailability of one of the two negotiators. A peer is able to suspend an ongoing negotiation and resume it with another (authenticated) peer. Negotiation portions and intermediate states can be safely and privately passed among peers, to guarantee the stability needed to continue suspended negotiations. We present a detailed analysis showing that our protocols have several key properties, including validity, correctness, and minimality. Also, we show how our negotiation protocol can withstand the most significant attacks. As by our complexity analysis, the introduction of the suspension and recovery procedures, and mobile negotiations does not significantly increase the complexity of ordinary negotiations. Our protocols require a constant number of messages whose size linearly depend on the portion of trust negotiation that has been carried before the suspensions.
Anna Cinzia Squicciarini, Elisa Bertino, Alberto Trombetta, Stefano Braghin
IEEE Trans. Dependable Secur. Comput.3
2011 Privacy-Preserving Updates to Anonymous and Confidential Databases
abstract
Suppose Alice owns a k-anonymous database and needs to determine whether her database, when inserted with a tuple owned by Bob, is still k-anonymous. Also, suppose that access to the database is strictly controlled, because for example data are used for certain experiments that need to be maintained confidential. Clearly, allowing Alice to directly read the contents of the tuple breaks the privacy of Bob (e.g., a patient's medical record); on the other hand, the confidentiality of the database managed by Alice is violated once Bob has access to the contents of the database. Thus, the problem is to check whether the database inserted with the tuple is still k-anonymous, without letting Alice and Bob know the contents of the tuple and the database, respectively. In this paper, we propose two protocols solving this problem on suppression-based and generalization-based k-anonymous and confidential databases. The protocols rely on well-known cryptographic assumptions, and we provide theoretical analyses to proof their soundness and experimental results to illustrate their efficiency.
Alberto Trombetta, Wei Jiang 0026, Elisa Bertino, Lorenzo Bossi
IEEE Trans. Dependable Secur. Comput.1
2011 A Multidimensional Critical State Analysis for Detecting Intrusions in SCADA Systems
abstract
A relatively new trend in Critical Infrastructures (e.g., power plants, nuclear plants, energy grids, etc.) is the massive migration from the classic model of isolated systems, to a system-of-systems model, where these infrastructures are intensifying their interconnections through Information and Communications Technology (ICT) means. The ICT core of these industrial installations is known as Supervisory Control And Data Acquisition Systems (SCADA). Traditional ICT security countermeasures (e.g., classic firewalls, anti-viruses and IDSs) fail in providing a complete protection to these systems since their needs are different from those of traditional ICT. This paper presents an innovative approach to Intrusion Detection in SCADA systems based on the concept of Critical State Analysis and State Proximity. The theoretical framework is supported by tests conducted with an Intrusion Detection System prototype implementing the proposed detection approach.
Andrea Carcano, Alessio Coletta, Michele Guglielmi, Marcelo Masera, Igor Nai Fovino, Alberto Trombetta
IEEE Trans. Ind. Informatics6
2010 Adaptive and Distributed Access Control in Cognitive Radio Networks
abstract
Cognitive Radio (CR) is a novel wireless technology communication that allows for adaptive configuration of the reception parameters of a terminal, based on the information collected from the environment. CR techniques may be applied to the resolution of emergency crisis to improve the spectrum utilization and the resilience of the wireless networks used by public safety organizations. Typically, such scenarios demand a mechanism for expressing and enforcing access control policies: that is, for stating what are the available resources (e.g. transmission/reception bandwidths), what are the parties that are allowed to access them and under what conditions. However, due to the intrinsically highly dynamic nature of such settings - in which unknown parties may suddenly appear and force a change in the configuration of other parties - it is extremely difficult to establish in advance what are the most suitable access control policies. Trust negotiation is a well-known approach for expressing and enforcing distributed access control policies which depend on two or more (initially mutually untrusting) parties. Such policies are determined on the fly by all the involved parties and do not require a centralized authority. In this work we present a trust negotiation-based framework which allows for the definition of highly expressive and flexible distributed access control policies and their efficient enforcement in cognitive radio networks.
Gianmarco Baldini, Stefano Braghin, Igor Nai Fovino, Alberto Trombetta
AINA4
2010 Modbus/DNP3 State-Based Intrusion Detection System
abstract
The security of Industrial Critical Infrastructures is become a prominent problem with the advent of modern ICT technologies used to improve the performances and the features of the SCADA systems. In this paper we present an innovative approach to the design of Intrusion Detection Systems. The aim is to be able to detect complex attacks to SCADA systems, by monitoring its state evolution. By complex attack, we mean attacks composed of a set of commands that, while licit when considered in isolation on a single-packet basis, can disrupt the correct behavior of the system when executed in particular operating states. The proposed IDS detects these complex attacks thanks to an internal representation of the controlled SCADA system. We also present the corresponding rule language powerful enough to express the system's critical states. Furthermore, we present a prototype of the proposed IDS, able to monitor systems using the ModBus and DNP3 communication protocols.
Igor Nai Fovino, Andrea Carcano, Thibault De Lacheze Murel, Alberto Trombetta, Marcelo Masera
AINA4
2010 Combining access control and trust negotiations in an On-line Social Network
abstract
Protection of On-line Social Networks (OSNs) resources has become a primary need since today OSNs are the hugest repository of personal information on the Web. This has resulted in the definition of some access control models tailored to the protection of OSN resources. One of the key parameter on w
Stefano Braghin, Elena Ferrari 0001, Alberto Trombetta
CollaborateCom3
2010 State-Based Firewall for Industrial Protocols with Critical-State Prediction Monitor
Igor Nai Fovino, Andrea Carcano, Alessio Coletta, Michele Guglielmi, Marcelo Masera, Alberto Trombetta
CRITIS6
2010 Privacy-aware role-based access control
abstract
In this article, we introduce a comprehensive framework supporting a privacy-aware access control mechanism, that is, a mechanism tailored to enforce access control to data containing personally identifiable information and, as such, privacy sensitive. The key component of the framework is a family of models (P-RBAC) that extend the well-known RBAC model in order to provide full support for expressing highly complex privacy-related policies, taking into account features like purposes and obligations. We formally define the notion of privacy-aware permissions and the notion of conflicting permission assignments in P-RBAC, together with efficient conflict-checking algorithms. The framework also includes a flexible authoring tool, based on the use of the SPARCLE system, supporting the high-level specification of P-RBAC permissions. SPARCLE supports the use of natural language for authoring policies and is able to automatically generate P-RBAC permissions from these natural language specifications. In the article, we also report performance evaluation results and contrast our approach with other relevant access control and privacy policy frameworks such as P3P, EPAL, and XACML.
Qun Ni, Elisa Bertino, Jorge Lobo 0001, Carolyn Brodie, Clare-Marie Karat, John Karat, Alberto Trombetta
ACM Trans. Inf. Syst. Secur.7
2010 Group-Based Negotiations in P2P Systems
abstract
In P2P systems, groups are typically formed to share resources and/or to carry on joint tasks. In distributed environments formed by a large number of peers conventional authentication techniques are inadequate for the group joining process, and more advanced ones are needed. Complex transactions among peers may require more elaborate interactions based on what peers can do or possess instead of peers' identity. In this work, we propose a novel peer group joining protocol. We introduce a highly expressive resource negotiation language, able to support the specification of a large variety of conditions applying to single peers or groups of peers. Moreover, we define protocols to test such resource availability customized to the level of assurance required by the peers. Our approach has been tested and evaluated on an extension of the JXTA P2P platform. Our results show the robustness of our approach in detecting malicious peers, detected both during the negotiation and during the peer group lifetime. Regardless of the peer group cardinality and interaction frequency, the peers always detect possible free riders within a small time frame.
Anna Cinzia Squicciarini, Federica Paci, Elisa Bertino, Alberto Trombetta, Stefano Braghin
IEEE Trans. Parallel Distributed Syst.4
2009 State-Based Network Intrusion Detection Systems for SCADA Protocols: A Proof of Concept
Andrea Carcano, Igor Nai Fovino, Marcelo Masera, Alberto Trombetta
CRITIS4
2008 Scada Malware, a Proof of Concept
Andrea Carcano, Igor Nai Fovino, Marcelo Masera, Alberto Trombetta
CRITIS4
2008 Privately Updating Suppression and Generalization based k-Anonymous Databases
abstract
Alice, owner of a k-anonymous database, needs to determine whether her database, when inserted with a tuple owned by Bob, is still k-anonymous. Suppose that Bob is not allowed to access to the database because of data confidentiality and that Alice is not allowed to read Bob's tuple due to Bob's privacy concern. Under these assumptions, this paper proposes two protocols to check whether the database inserted with a tuple is still k-anonymous, without letting Alice and Bob know the contents of the tuple and the database respectively.
Alberto Trombetta, Wei Jiang 0026, Elisa Bertino, Lorenzo Bossi
ICDE1
2007 Supporting Robust and Secure Interactions in Open Domains through Recovery of Trust Negotiations
abstract
Trust negotiation supports authentication and access control across multiple security domains by allowing parties to use non-forgeable digital credentials to establish trust. By their nature trust negotiation systems are used in environments that are not always reliable. In particular, it is important not only to protect negotiations against malicious attacks, but also against failures and crashes of the parties or of the communication means. To address the problem of failures and crashes, we propose an efficient and secure recovery mechanism. The mechanism includes two recovery protocols, one for each of the two main negotiation phases. In fact, because of the requirements that both services and credentials have to be protected on the basis of the associated disclosure policies, most approaches distinguish between a phase of disclosure policy evaluation from a phase devoted to actual credentials exchange. We prove that the protocols, besides being efficient, are secure with respect to integrity, and confidentiality and are idempotent. To the best of our knowledge, this is the first effort for achieving robustness and fault tolerance of trust negotiation systems.
Anna Cinzia Squicciarini, Alberto Trombetta, Elisa Bertino
ICDCS2
2007 Privacy-aware role based access control
abstract
Privacy has been acknowledged to be a critical requirement for many business (and non-business) environments. Therefore, the definition of an expressive and easy-to-use privacy related access control model, based on which privacy policies can be specified, is crucial. In this work we introduce a family of models (P-RBAC) that extend the well known RBAC model in order to provide full support for expressing highly complex privacy-related policies, taking into account features like purposes and obligations. We also compare our work with access control and privacy policy frameworks such as P3P, EPAL, and XACML.
Qun Ni, Alberto Trombetta, Elisa Bertino, Jorge Lobo 0001
SACMAT2
2006 Private Updates to Anonymous Databases
abstract
Suppose that Alice, owner of a k-anonymous database, needs to determine whether her database, when adjoined with a tuple owned by Bob, is still k-anonymous. Suppose moreover that access to the database is strictly controlled, because for example data are used for experiments that need to be maintained confidential. Clearly, allowing Alice to directly read the contents of the tuple breaks the privacy of Bob; on the other hand, the confidentiality of the database managed by Alice is violated once Bob has access to the contents of the database. Thus the problem is to check whether the database adjoined with the tuple is still k-anonymous, without letting Alice and Bob know the contents of, respectively, the tuple and the database. In this paper, we propose two protocols solving this problem.
Alberto Trombetta, Elisa Bertino
ICDE1
2006 Equivalences and optimizations in an expressive XSLT subset
Alberto Trombetta, Danilo Montesi
Acta Informatica1
2005 A framework for modeling and evaluating automatic semantic reconciliation
Avigdor Gal, Ateret Anaby-Tavor, Alberto Trombetta, Danilo Montesi
VLDB J.3
2004 Equivalences and Optimizations in an Expressive XSLT Fragment
Alberto Trombetta, Danilo Montesi
IDEAS1
2003 A Model for Schema Integration in Heterogeneous Databases
abstract
Schema integration is the process by which schemata from heterogeneous databases are conceptually integrated into a single cohesive schema. In this work we propose a modeling framework for schema integration, capturing the inherent uncertainty accompanying the integration process. The model utilizes a fuzzy framework to express a confidence measure, associated with the outcome of a schema integration process. In this paper we provide a systematic analysis of the process properties and establish a criterion for evaluating the quality of matching algorithms, which map attributes among heterogeneous schemata.
Avigdor Gal, Alberto Trombetta, Ateret Anaby-Tavor, Danilo Montesi
IDEAS2
2003 A similarity based relational algebra for Web and multimedia data
Danilo Montesi, Alberto Trombetta, Peter A. Dearnley
Inf. Process. Manag.2
2002 Workflow Architecture for Interactive Video Management Systems
Elisa Bertino, Alberto Trombetta, Danilo Montesi
Distributed Parallel Databases2
2000 Fuzzy and Presentation Algebras for Web and Multimedia Data
abstract
Web and multimedia data are becoming very important. A fundamental characteristic of these data is imprecision. Query languages for web and multimedia data must express imprecision in features matching, similarity queries and user preferences. In addition specific operators need to be introduced to organize the answers in a user friendly style. The aim of this work is to provide a formal framework in which to formulate very powerful queries and presentations of the answers. To this end, a fuzzy algebra and a presentation algebra are introduced. The fuzzy algebra extends the classical relational algebra over fuzzy relations. Both algebras allow user preferences in the form of weights to be attached to predicates and operators. The effect of this weights is to alter the classic behaviour of query expressions to better suite user requirements. In addition, optimization issues are presented in the form of algebraic manipulation of expressions thus leading to a set of equivalence and containment rules.
Elisa Bertino, Danilo Montesi, Alberto Trombetta
IDEAS3
1997 Optimal Comparison Strategies in Ulam's Searching Game with Two Errors
Daniele Mundici, Alberto Trombetta
Theor. Comput. Sci.2