EDBT 2026 Demo / reviewers in the wild / expert
Alberto Trombetta
dblp:97/2730
· DBLP profile ↗
38ranked-venue papers
5as first author
6since 2021 · last 2025
0000-0002-2567-9297ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Databases, data management, data science and information retrieval · 13 · 3 first-author · 2 since 2021Security and privacy · 12 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 5 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Systems, architecture and hardware · 2Human-computer interaction and ubiquitous computing · 2Theory of computation · 2 · 1 first-author
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Databases, data mining, and information retrieval
2 papers |
Knowledge graphs · 48% Information retrieval · 48% Data integration and cleaning · 4% | |
| Network and information security
5 papers |
Privacy and data protection · 55% Authentication and access control · 29% Cryptographic protocols and secure computation · 16% | |
| Computer architecture, parallel and distributed computing, and storage systems
1 paper |
Distributed systems · 50% Cloud and datacenter computing · 50% | |
| Interdisciplinary, comprehensive, and emerging computing
1 paper |
Bioinformatics and computational biology · 100% |
Topics — the 8 heaviest of 13, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Information retrieval › document retrieval › domain-specific retrieval › biomedical information retrieval
biomedical literature search |
0.7 | 1 | 2023 | Graph-based Tool for Exploring PubMed Knowledge Base · ICDE 2023 |
Privacy and data protection
anonymization |
0.3 | 3 | 2011 | Privacy-Preserving Updates to Anonymous and Confidential Databases · IEEE Trans. Dependable Secur. Comput. 2011 Privately Updating Suppression and Generalization based k-Anonymous Databases · ICDE 2008 Private Updates to Anonymous Databases · ICDE 2006 |
Authentication and access control › trust management
trust negotiation |
0.1 | 1 | 2012 | A Flexible Approach to Multisession Trust Negotiations · IEEE Trans. Dependable Secur. Comput. 2012 |
Privacy and data protection › anonymization
k-anonymity |
0.1 | 1 | 2011 | Privacy-Preserving Updates to Anonymous and Confidential Databases · IEEE Trans. Dependable Secur. Comput. 2011 |
Distributed systems
peer-to-peer systems |
0.1 | 1 | 2010 | Group-Based Negotiations in P2P Systems · IEEE Trans. Parallel Distributed Syst. 2010 |
Cloud and datacenter computing › resource management
resource negotiation |
0.1 | 1 | 2010 | Group-Based Negotiations in P2P Systems · IEEE Trans. Parallel Distributed Syst. 2010 |
Privacy and data protection › anonymization › syntactic anonymization
generalization and suppression |
0.1 | 1 | 2008 | Privately Updating Suppression and Generalization based k-Anonymous Databases · ICDE 2008 |
Data integration and cleaning
schema matching |
0.1 | 1 | 2005 | A framework for modeling and evaluating automatic semantic reconciliation · VLDB J. 2005 |
Methods — techniques the papers use, named apart from their topics
graph-based navigation · 1.3full-text search · 1.3concept extraction · 1.3resource negotiation language · 0.2JXTA · 0.2secure two-party computation · 0.1protocol analysis · 0.1complexity analysis · 0.1secure multiparty computation · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Verifiability and Privacy in Federated Learning through Context-Hiding Multi-Key Homomorphic AuthenticatorsabstractFederated Learning has rapidly expanded from its original inception to now have a large body of research, several frameworks, and sold in a variety of commercial offerings. Thus, its security and robustness is of significant importance. There are many algorithms that provide robustness in the case of malicious clients. However, the aggregator itself may behave maliciously, for example, by biasing the model or tampering with the weights to weaken the model’s privacy. In this work, we introduce a verifiable federated learning protocol that enables clients to verify the correctness of the aggregator’s computation without compromising the confidentiality of their updates. Our protocol uses a standard secure aggregation technique to protect individual model updates with a linearly homomorphic authenticator scheme that enables efficient, privacy-preserving verification of the aggregated result. Our construction ensures that clients can detect manipulation by the aggregator while maintaining low computational overhead. We demonstrate that our approach scales to large models, enabling verification over large neural networks with millions of parameters. Simone Bottoni, Giulio Zizzo, Stefano Braghin, Alberto Trombetta |
BDCAT | 4 |
| 2023 | Graph-based Tool for Exploring PubMed Knowledge BaseabstractStudies have shown that data retrieval and visualization tools can help health professionals to improve their understanding and communication with patients, their relationship with stakeholders, and their decision-making process. However, not many efforts have been made in this direction. In this paper, we present a prototype system for the indexing, annotation, and visualization of the PubMed knowledge base to enable the search and retrieval of health-related evidence. The proposed tool builds and keeps updated an enriched graph based on PubMed articles associating them with concepts extracted from the Unified Medical Language System (UMLS) Metathesaurus. Moreover, it allows a full-text search and graph-based navigation and supports an overview of concepts and related publications. The proposed architecture enables scale-up thanks to its containerized nature and parallelization capabilities. The code is open-source under the Apache V2 license. Simone Bottoni, Alberto Trombetta, Flavio Bertini 0001, Danilo Montesi, Francesca Bonin, Alessandra Pascale, Martin Gleize, Pierpaolo Tommasi |
ICDE | 2 |
| 2023 | A review of domain ontologies for disability representation
Daniele Spoladore, Marco Sacco, Alberto Trombetta |
Expert Syst. Appl. | 3 |
| 2022 | Adaptive Replication Strategy in Highly Distributed Data Management SystemsabstractThe performance of the execution of an analytical workload critically impacts the speed at which companies are able to react to market changes. In the era of Big Data, it is imperative that large, complex analytics are executed in a timely manner. In this paper, we propose a method to analyze the data access pattern of analytical workloads on large datasets to identify optimal data partitioning and replication strategies. This, in turn, helps the already existing query optimization components of modern data management systems. Simone Bottoni, Stefano Braghin, Alberto Trombetta, Srikumar Venugopal |
IC2E | 3 |
| 2022 | A Semantic-Based Collaborative Ambient-Assisted Working Framework
Turgut Cilsal, Daniele Spoladore, Alberto Trombetta, Marco Sacco |
PRO-VE | 3 |
| 2022 | Secure Selections on Encrypted Multi-writer StreamsabstractPerforming searches over encrypted data is a very current and active area. Several efficient solutions have been provided for the single-writer scenario in which all sensitive data originate with one party (the Data Owner ) that encrypts and uploads the data to a public repository. Subsequently, the Data Owner accesses the encrypted data through a Query Processor , which has direct access to the public encrypted repository. Motivated by the recent trend in pervasive data collection, we depart from this model and consider a multi-writer scenario in which the data originate with several and mutually untrusted parties, the Data Sources . In this new scenario, the Data Owner provides public parameters so that each Data Source can add encrypted items to the public encrypted stream; moreover, the Data Owner keeps some related secret information needed to generate tokens so that different Query Sources can decrypt different subsets of the encrypted stream, as specified by corresponding access policies. We propose security model for this problem that we call Secure Selective Stream ( SSS ) and give a secure construction for it based on hard problems in Pairing-Based Cryptography. The cryptographic core of our construction is a new primitive, Amortized Orthogonality Encryption , that is crucial for the efficiency of the proposed implementation for SSS . Angelo Massimo Perillo, Giuseppe Persiano, Alberto Trombetta |
ACM Trans. Priv. Secur. | 3 |
| 2020 | An ontology-based framework for a Less Invasive Domestic Management System (LIDoMS)abstractResearch in the fields of the Smart Home and Ambient Assisted Living has increased in the last decade. While some solutions are available to general public, there are still some concerns related to the design of smart solutions and their acceptance, especially when it comes to residents' monitoring and privacy. In this context, this paper introduces an ontology-based smart home framework, LIDoMS, aimed at focusing on inhabitants needs by providing a representation of their health conditions, while offering them customized services. End-users can interact with the system thanks to an adaptive and ubiquitous graphical interface. In this work, the ontological framework underlying LIDoMS is described; the system exploits the knowledge regarding the status of appliances and residents' location within the smart home to infer the activity they are involved in, and to provide customized adaptation of indoor comfort metrics, thus enabling a less invasive monitoring of the inhabitants. Two scenarios describe how different residents can interact with LIDoMS to personalize comfort metrics - pivotal for their health condition. Finally, a framework for the validation of LIDoMS is presented. Daniele Spoladore, Marta Mondellini, Marco Sacco, Alberto Trombetta |
Intelligent Environments | 4 |
| 2018 | An Efficient Cryptography-Based Access Control Using Inner-Product Proxy Re-Encryption SchemeabstractInner-product encryption (IPE) is a well-known functional encryption primitive that allows decryption when the inner-product of the attribute vectors, upon which the encrypted data and the decryption key depend, is equal to zero. Using IPE, it is possible to define fine-grained access policies over encrypted data whose enforcement can be outsourced to the cloud where the data are stored. However, current IPE schemes do not support efficient access policy changes. In this paper, we propose an efficient inner-product proxy re-encryption (E-IPPRE) scheme that provides the proxy server with a transformation key, with which a ciphertext associated with an attribute vector can be transformed to a new ciphertext associated with a different attribute vector, providing a policy update mechanism with a performance suitable for many practical applications. We experimentally assess the efficiency of our protocol and show that it is selective attribute-secure against chosen-plaintext attacks in the standard model under the Asymmetric Decisional Bilinear Diffie-Hellman assumption. Masoomeh Sepehri, Alberto Trombetta, Maryam Sepehri, Ernesto Damiani |
ARES | 2 |
| 2017 | Secure and Efficient Data Sharing with Atribute-based Proxy Re-encryption SchemeabstractWith the ever-growing production of data coming from multiple, scattered, highly dynamical sources (like those found in IoT scenarios), it is compelling to (i) provide a seamless way to outsource the management and sharing of data (as provided by cloud services); (ii) assure an high security and privacy level to such data. As such, objectives (i) and (ii) are not easily reconcilable: for example, the way data is accessed may vary according to access policies of the users and of the cloud providers that share such data. In this paper, we argue that attribute-based proxy re-encryption is a viable solution for providing the flexibility needed in dynamic scenarios like the ones envisioned by large IoT deployments. Towards, this goal we present an efficient attribute-based, proxy re-encryption scheme that can be deployed in such scenarios, along with experimental results that confirm the viability of our approach. Masoomeh Sepehri, Alberto Trombetta |
ARES | 2 |
| 2017 | Secure Queries on Encrypted Multi-writer TablesabstractPerforming searches on encrypted data is a very current and active area. Several efficient solutions have been provided for the single-writer scenario in which all sensitive data originates with one party (the Data Owner) that encrypts it and uploads it to a public repository. Subsequently, the Data Owner (or authorized clients, the Query Sources) perform queries on the encrypted data through a Query Processor which has direct access to the public repository. Motivated by the recent trend in pervasive data, we depart from this model and consider a multi-writer scenario in which data originates with several and mutually untrusted parties. In this new scenario the Data Owner provides public parameters so that each piece of the generated data stream can be put into an encrypted stream; moreover, the Data Owner keeps some related secret information needed to generate tokens so that different subscribers can access different subsets of the encrypted stream in clear. We consider the case in which each piece of the data stream consists of a fixed number of cells, organized in columns, and the data owner can authorize subscribers to access individual data based on the content of the columns. Current public-key functional encryption schemes provide a direct and impractical implementation of this scenario. We thus propose a new public-key primitive, Amortized Orthogonality Encryption or AOE, derived from Inner-Product Encryption, that can be used to encrypt each piece of data stream so that ciphertexts have size proportional to the un-encrypted data; moreover, encryption and decryption take time proportional to the number of columns. Previous schemes would give quadratic complexity. We provide a construction of AOE and prove its selective security under standard assumptions in a bilinear setting with prime order group. Using AOE, we implement all the basic operations in our multi-writer scenario in one round of communication. We demonstrate the feasibility and effectiveness of our proposal by providing an implementation of our scenario in C++. Angelo Massimo Perillo, Giuseppe Persiano, Alberto Trombetta |
EuroS&P | 3 |
| 2014 | Discovering non-constant Conditional Functional Dependencies with Built-in Predicates
Antonella Zanzi, Alberto Trombetta |
DEXA (1) | 2 |
| 2013 | Data Quality Evaluation of Scientific Datasets - A Case Study in a Policy Support ContextabstractIn this work we present the rule-based approach used to evaluate the quality of scientific datasets in a policy support context. The used case study refers to real datasets in a context where low data quality limits the accuracy of the analysis results and, consequently, the significance of the provided policy advice. The applied solution consists in the identification of types of constraints that can be useful as data quality rules and in the development of a software tool to evaluate a dataset on the basis of a set of rules expressed in the XML\nmarkup language. As rule types we selected some types of data constraints and dependencies already proposed in data quality works, but we experimented also the use of order dependencies and existence constraints. The case study was used to develop and test the adopted solution, which is anyway generally applicable to other contexts. Antonella Zanzi, Alberto Trombetta |
DATA | 2 |
| 2013 | Querying data across different legal domainsabstractThe management of legal domains is gaining great importance in the context of data management. In fact, the geographical distribution of data as implied -- for example -- by cloud-based services requires that the legal restrictions and obligations are to be taken into account whenever data circulates across different legal domains. In this paper, we start to investigate an approach for coping with the complex issues that arise when dealing with data spanning different legal domains. Our approach consists of a conceptual model that takes into account the notion of legal domain (to be paired with the corresponding data) and a reference architecture for implementing our approach in an actual relational DBMS. Marco Taddeo, Alberto Trombetta, Danilo Montesi, Stefano Pierantozzi |
IDEAS | 2 |
| 2013 | A Framework for Trust-Based Multidisciplinary Team Recommendation
Lorenzo Bossi, Stefano Braghin, Anwitaman Datta, Alberto Trombetta |
UMAP | 4 |
| 2013 | Distributed access control policies for spectrum sharingabstractABSTRACT Cognitive radio is a novel wireless communication technology that allows for adaptive configuration of the reception parameters of a terminal, based on the information collected from the environment. Cognitive radio technology can be used in innovative spectrum management approaches such as spectrum sharing, where radio frequency spectral bands can be shared among various users through a dynamic exclusive‐use spectrum access model. Spectrum sharing can be applied to various scenarios in the commercial, public safety and military domain. In some scenarios, spectrum sharing demands a mechanism for expressing and enforcing access control policies for the allocation of resources including spectral bands. The access control polices should state what are the available resources (e.g., transmission/reception bandwidths), what are the users that are allowed to access them and under what conditions. However, because of the intrinsically highly dynamic nature of specific scenarios (e.g., public safety, military), where parties with various levels of authority may suddenly appear, it may be difficult to establish in advance what are the most suitable access control policies. Trust negotiation is a well‐known approach for expressing and enforcing distributed access control policies that depend on two or more parties. In this work, we present a trust negotiation‐based framework that allows for the definition of highly expressive and flexible distributed access control policies for the allocation of spectrum resources. Copyright © 2012 John Wiley & Sons, Ltd. Gianmarco Baldini, Igor Nai Fovino, Stefano Braghin, Alberto Trombetta |
Secur. Commun. Networks | 4 |
| 2012 | A Flexible Approach to Multisession Trust NegotiationsabstractTrust Negotiation has shown to be a successful, policy-driven approach for automated trust establishment, through the release of digital credentials. Current real applications require new flexible approaches to trust negotiations, especially in light of the widespread use of mobile devices. In this paper, we present a multisession dependable approach to trust negotiations. The proposed framework supports voluntary and unpredicted interruptions, enabling the negotiating parties to complete the negotiation despite temporary unavailability of resources. Our protocols address issues related to validity, temporary loss of data, and extended unavailability of one of the two negotiators. A peer is able to suspend an ongoing negotiation and resume it with another (authenticated) peer. Negotiation portions and intermediate states can be safely and privately passed among peers, to guarantee the stability needed to continue suspended negotiations. We present a detailed analysis showing that our protocols have several key properties, including validity, correctness, and minimality. Also, we show how our negotiation protocol can withstand the most significant attacks. As by our complexity analysis, the introduction of the suspension and recovery procedures, and mobile negotiations does not significantly increase the complexity of ordinary negotiations. Our protocols require a constant number of messages whose size linearly depend on the portion of trust negotiation that has been carried before the suspensions. Anna Cinzia Squicciarini, Elisa Bertino, Alberto Trombetta, Stefano Braghin |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2011 | Privacy-Preserving Updates to Anonymous and Confidential DatabasesabstractSuppose Alice owns a k-anonymous database and needs to determine whether her database, when inserted with a tuple owned by Bob, is still k-anonymous. Also, suppose that access to the database is strictly controlled, because for example data are used for certain experiments that need to be maintained confidential. Clearly, allowing Alice to directly read the contents of the tuple breaks the privacy of Bob (e.g., a patient's medical record); on the other hand, the confidentiality of the database managed by Alice is violated once Bob has access to the contents of the database. Thus, the problem is to check whether the database inserted with the tuple is still k-anonymous, without letting Alice and Bob know the contents of the tuple and the database, respectively. In this paper, we propose two protocols solving this problem on suppression-based and generalization-based k-anonymous and confidential databases. The protocols rely on well-known cryptographic assumptions, and we provide theoretical analyses to proof their soundness and experimental results to illustrate their efficiency. Alberto Trombetta, Wei Jiang 0026, Elisa Bertino, Lorenzo Bossi |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2011 | A Multidimensional Critical State Analysis for Detecting Intrusions in SCADA SystemsabstractA relatively new trend in Critical Infrastructures (e.g., power plants, nuclear plants, energy grids, etc.) is the massive migration from the classic model of isolated systems, to a system-of-systems model, where these infrastructures are intensifying their interconnections through Information and Communications Technology (ICT) means. The ICT core of these industrial installations is known as Supervisory Control And Data Acquisition Systems (SCADA). Traditional ICT security countermeasures (e.g., classic firewalls, anti-viruses and IDSs) fail in providing a complete protection to these systems since their needs are different from those of traditional ICT. This paper presents an innovative approach to Intrusion Detection in SCADA systems based on the concept of Critical State Analysis and State Proximity. The theoretical framework is supported by tests conducted with an Intrusion Detection System prototype implementing the proposed detection approach. Andrea Carcano, Alessio Coletta, Michele Guglielmi, Marcelo Masera, Igor Nai Fovino, Alberto Trombetta |
IEEE Trans. Ind. Informatics | 6 |
| 2010 | Adaptive and Distributed Access Control in Cognitive Radio NetworksabstractCognitive Radio (CR) is a novel wireless technology communication that allows for adaptive configuration of the reception parameters of a terminal, based on the information collected from the environment. CR techniques may be applied to the resolution of emergency crisis to improve the spectrum utilization and the resilience of the wireless networks used by public safety organizations. Typically, such scenarios demand a mechanism for expressing and enforcing access control policies: that is, for stating what are the available resources (e.g. transmission/reception bandwidths), what are the parties that are allowed to access them and under what conditions. However, due to the intrinsically highly dynamic nature of such settings - in which unknown parties may suddenly appear and force a change in the configuration of other parties - it is extremely difficult to establish in advance what are the most suitable access control policies. Trust negotiation is a well-known approach for expressing and enforcing distributed access control policies which depend on two or more (initially mutually untrusting) parties. Such policies are determined on the fly by all the involved parties and do not require a centralized authority. In this work we present a trust negotiation-based framework which allows for the definition of highly expressive and flexible distributed access control policies and their efficient enforcement in cognitive radio networks. Gianmarco Baldini, Stefano Braghin, Igor Nai Fovino, Alberto Trombetta |
AINA | 4 |
| 2010 | Modbus/DNP3 State-Based Intrusion Detection SystemabstractThe security of Industrial Critical Infrastructures is become a prominent problem with the advent of modern ICT technologies used to improve the performances and the features of the SCADA systems. In this paper we present an innovative approach to the design of Intrusion Detection Systems. The aim is to be able to detect complex attacks to SCADA systems, by monitoring its state evolution. By complex attack, we mean attacks composed of a set of commands that, while licit when considered in isolation on a single-packet basis, can disrupt the correct behavior of the system when executed in particular operating states. The proposed IDS detects these complex attacks thanks to an internal representation of the controlled SCADA system. We also present the corresponding rule language powerful enough to express the system's critical states. Furthermore, we present a prototype of the proposed IDS, able to monitor systems using the ModBus and DNP3 communication protocols. Igor Nai Fovino, Andrea Carcano, Thibault De Lacheze Murel, Alberto Trombetta, Marcelo Masera |
AINA | 4 |
| 2010 | Combining access control and trust negotiations in an On-line Social NetworkabstractProtection of On-line Social Networks (OSNs) resources has become a primary need since today OSNs are the hugest repository of personal information on the Web. This has resulted in the definition of some access control models tailored to the protection of OSN resources. One of the key parameter on w Stefano Braghin, Elena Ferrari 0001, Alberto Trombetta |
CollaborateCom | 3 |
| 2010 | State-Based Firewall for Industrial Protocols with Critical-State Prediction Monitor
Igor Nai Fovino, Andrea Carcano, Alessio Coletta, Michele Guglielmi, Marcelo Masera, Alberto Trombetta |
CRITIS | 6 |
| 2010 | Privacy-aware role-based access controlabstractIn this article, we introduce a comprehensive framework supporting a privacy-aware access control mechanism, that is, a mechanism tailored to enforce access control to data containing personally identifiable information and, as such, privacy sensitive. The key component of the framework is a family of models (P-RBAC) that extend the well-known RBAC model in order to provide full support for expressing highly complex privacy-related policies, taking into account features like purposes and obligations. We formally define the notion of privacy-aware permissions and the notion of conflicting permission assignments in P-RBAC, together with efficient conflict-checking algorithms. The framework also includes a flexible authoring tool, based on the use of the SPARCLE system, supporting the high-level specification of P-RBAC permissions. SPARCLE supports the use of natural language for authoring policies and is able to automatically generate P-RBAC permissions from these natural language specifications. In the article, we also report performance evaluation results and contrast our approach with other relevant access control and privacy policy frameworks such as P3P, EPAL, and XACML. Qun Ni, Elisa Bertino, Jorge Lobo 0001, Carolyn Brodie, Clare-Marie Karat, John Karat, Alberto Trombetta |
ACM Trans. Inf. Syst. Secur. | 7 |
| 2010 | Group-Based Negotiations in P2P SystemsabstractIn P2P systems, groups are typically formed to share resources and/or to carry on joint tasks. In distributed environments formed by a large number of peers conventional authentication techniques are inadequate for the group joining process, and more advanced ones are needed. Complex transactions among peers may require more elaborate interactions based on what peers can do or possess instead of peers' identity. In this work, we propose a novel peer group joining protocol. We introduce a highly expressive resource negotiation language, able to support the specification of a large variety of conditions applying to single peers or groups of peers. Moreover, we define protocols to test such resource availability customized to the level of assurance required by the peers. Our approach has been tested and evaluated on an extension of the JXTA P2P platform. Our results show the robustness of our approach in detecting malicious peers, detected both during the negotiation and during the peer group lifetime. Regardless of the peer group cardinality and interaction frequency, the peers always detect possible free riders within a small time frame. Anna Cinzia Squicciarini, Federica Paci, Elisa Bertino, Alberto Trombetta, Stefano Braghin |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2009 | State-Based Network Intrusion Detection Systems for SCADA Protocols: A Proof of Concept
Andrea Carcano, Igor Nai Fovino, Marcelo Masera, Alberto Trombetta |
CRITIS | 4 |
| 2008 | Scada Malware, a Proof of Concept
Andrea Carcano, Igor Nai Fovino, Marcelo Masera, Alberto Trombetta |
CRITIS | 4 |
| 2008 | Privately Updating Suppression and Generalization based k-Anonymous DatabasesabstractAlice, owner of a k-anonymous database, needs to determine whether her database, when inserted with a tuple owned by Bob, is still k-anonymous. Suppose that Bob is not allowed to access to the database because of data confidentiality and that Alice is not allowed to read Bob's tuple due to Bob's privacy concern. Under these assumptions, this paper proposes two protocols to check whether the database inserted with a tuple is still k-anonymous, without letting Alice and Bob know the contents of the tuple and the database respectively. Alberto Trombetta, Wei Jiang 0026, Elisa Bertino, Lorenzo Bossi |
ICDE | 1 |
| 2007 | Supporting Robust and Secure Interactions in Open Domains through Recovery of Trust NegotiationsabstractTrust negotiation supports authentication and access control across multiple security domains by allowing parties to use non-forgeable digital credentials to establish trust. By their nature trust negotiation systems are used in environments that are not always reliable. In particular, it is important not only to protect negotiations against malicious attacks, but also against failures and crashes of the parties or of the communication means. To address the problem of failures and crashes, we propose an efficient and secure recovery mechanism. The mechanism includes two recovery protocols, one for each of the two main negotiation phases. In fact, because of the requirements that both services and credentials have to be protected on the basis of the associated disclosure policies, most approaches distinguish between a phase of disclosure policy evaluation from a phase devoted to actual credentials exchange. We prove that the protocols, besides being efficient, are secure with respect to integrity, and confidentiality and are idempotent. To the best of our knowledge, this is the first effort for achieving robustness and fault tolerance of trust negotiation systems. Anna Cinzia Squicciarini, Alberto Trombetta, Elisa Bertino |
ICDCS | 2 |
| 2007 | Privacy-aware role based access controlabstractPrivacy has been acknowledged to be a critical requirement for many business (and non-business) environments. Therefore, the definition of an expressive and easy-to-use privacy related access control model, based on which privacy policies can be specified, is crucial. In this work we introduce a family of models (P-RBAC) that extend the well known RBAC model in order to provide full support for expressing highly complex privacy-related policies, taking into account features like purposes and obligations. We also compare our work with access control and privacy policy frameworks such as P3P, EPAL, and XACML. Qun Ni, Alberto Trombetta, Elisa Bertino, Jorge Lobo 0001 |
SACMAT | 2 |
| 2006 | Private Updates to Anonymous DatabasesabstractSuppose that Alice, owner of a k-anonymous database, needs to determine whether her database, when adjoined with a tuple owned by Bob, is still k-anonymous. Suppose moreover that access to the database is strictly controlled, because for example data are used for experiments that need to be maintained confidential. Clearly, allowing Alice to directly read the contents of the tuple breaks the privacy of Bob; on the other hand, the confidentiality of the database managed by Alice is violated once Bob has access to the contents of the database. Thus the problem is to check whether the database adjoined with the tuple is still k-anonymous, without letting Alice and Bob know the contents of, respectively, the tuple and the database. In this paper, we propose two protocols solving this problem. Alberto Trombetta, Elisa Bertino |
ICDE | 1 |
| 2006 | Equivalences and optimizations in an expressive XSLT subset
Alberto Trombetta, Danilo Montesi |
Acta Informatica | 1 |
| 2005 | A framework for modeling and evaluating automatic semantic reconciliation
Avigdor Gal, Ateret Anaby-Tavor, Alberto Trombetta, Danilo Montesi |
VLDB J. | 3 |
| 2004 | Equivalences and Optimizations in an Expressive XSLT Fragment
Alberto Trombetta, Danilo Montesi |
IDEAS | 1 |
| 2003 | A Model for Schema Integration in Heterogeneous DatabasesabstractSchema integration is the process by which schemata from heterogeneous databases are conceptually integrated into a single cohesive schema. In this work we propose a modeling framework for schema integration, capturing the inherent uncertainty accompanying the integration process. The model utilizes a fuzzy framework to express a confidence measure, associated with the outcome of a schema integration process. In this paper we provide a systematic analysis of the process properties and establish a criterion for evaluating the quality of matching algorithms, which map attributes among heterogeneous schemata. Avigdor Gal, Alberto Trombetta, Ateret Anaby-Tavor, Danilo Montesi |
IDEAS | 2 |
| 2003 | A similarity based relational algebra for Web and multimedia data
Danilo Montesi, Alberto Trombetta, Peter A. Dearnley |
Inf. Process. Manag. | 2 |
| 2002 | Workflow Architecture for Interactive Video Management Systems
Elisa Bertino, Alberto Trombetta, Danilo Montesi |
Distributed Parallel Databases | 2 |
| 2000 | Fuzzy and Presentation Algebras for Web and Multimedia DataabstractWeb and multimedia data are becoming very important. A fundamental characteristic of these data is imprecision. Query languages for web and multimedia data must express imprecision in features matching, similarity queries and user preferences. In addition specific operators need to be introduced to organize the answers in a user friendly style. The aim of this work is to provide a formal framework in which to formulate very powerful queries and presentations of the answers. To this end, a fuzzy algebra and a presentation algebra are introduced. The fuzzy algebra extends the classical relational algebra over fuzzy relations. Both algebras allow user preferences in the form of weights to be attached to predicates and operators. The effect of this weights is to alter the classic behaviour of query expressions to better suite user requirements. In addition, optimization issues are presented in the form of algebraic manipulation of expressions thus leading to a set of equivalence and containment rules. Elisa Bertino, Danilo Montesi, Alberto Trombetta |
IDEAS | 3 |
| 1997 | Optimal Comparison Strategies in Ulam's Searching Game with Two Errors
Daniele Mundici, Alberto Trombetta |
Theor. Comput. Sci. | 2 |