EDBT 2026 Demo / reviewers in the wild / expert
Antonio F. Skarmeta
dblp:g/AFGomezSkarmeta · also Antonio F. Skarmeta-Gómez, Antonio Fernandez Gómez-Skarmeta
· DBLP profile ↗
235ranked-venue papers
10as first author
43since 2021 · last 2026
0000-0002-5525-1259ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 62 · 2 first-author · 12 since 2021Artificial intelligence and machine learning · 46 · 5 first-author · 4 since 2021Security and privacy · 30 · 6 since 2021Systems, architecture and hardware · 25 · 1 first-author · 5 since 2021Databases, data management, data science and information retrieval · 20 · 3 first-author · 2 since 2021Software engineering, systems software and programming languages · 18 · 12 since 2021Human-computer interaction and ubiquitous computing · 16Applied, interdisciplinary, general and emerging computing · 14 · 5 since 2021Theory of computation · 2Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Making IBN Tractable by Enhanced Policy Verification: The NIPOV Algorithm
Pedro Martinez-Julia, Ved P. Kafle, Hitoshi Asaeda, Diego R. López, Antonio F. Skarmeta |
NetSoft | 5 |
| 2026 | A Multi-Stakeholder Framework for Secure C-ITS and Experimental Deployment
Ramon Sanchez-Iborra, Maria-Dolores Guerrero-Munuera, Antonio F. Skarmeta, Esteban Egea-López, Felipe Garcia-Vidal, Victoria Beltran, Ramón J. Durán, Juan Carlos Aguado, Noemí Merayo, Ignacio de Miguel |
NetSoft | 3 |
| 2026 | A comprehensive approach for the onboarding, orchestration, and validation of network applicationsabstractThe advent of 5G and Beyond 5G networks has propelled the development of innovative applications and services that harness network programmability, data from management and control interfaces, and the capabilities of network slicing. However, ensuring these applications function as intended and effectively utilize 5G/B5G capabilities remains a challenge, mainly due to their reliance on complex interactions with control plane Network Functions. This work addresses this issue by proposing a novel architecture to enhance the onboarding, orchestration, and validation of 5G/B5G-capable applications and services, while enabling the creation of application-tailored network slices. By integrating DevOps principles into the NFV ecosystem, the proposed architecture automates workflows for deployment, testing, and validation, while adhering to standardized onboarding models and continuous integration practices. Furthermore, we also address the realization of such architecture into a platform that supports extensive testing across multiple dimensions, including 5G readiness, security, performance, scalability, and availability. Besides introducing such a platform, this work also demonstrates its feasibility through the orchestration and validation of an automotive application that manages virtual On-Board Units within a 5G-enabled environment. The obtained results underscore the effectiveness of the proposed architecture, as well as the performance and scalability of the platform that materializes it. By integrating DevOps principles, our work aids in reducing deployment complexity, automating testing and validation, and enhancing the reliability of next-generation Network Applications, therefore accelerating their time-to-market. Rafael Direito, Kostis Trantzas, Jorge Gallego-Madrid, Ana Hermosilla, Diogo Gomes 0001, Christos Tranoris, Rui L. Aguiar, Antonio F. Skarmeta, Spyros G. Denazis |
Comput. Networks | 8 |
| 2026 | Simulation as a Service in Data Spaces: A Digital Twin-based Approach
Luigi Coppolino, Adelaida Parreño-Rodríguez, Alfredo Petruolo, Juan Sánchez-Valverde, Antonio F. Skarmeta |
Data Sci. Eng. | 5 |
| 2026 | Enhancing federated intrusion detection through LLM-Driven alert enrichment and collaborative threat information sharing
Pablo Fernández Saura, Jorge Bernal Bernabé, Antonio F. Skarmeta |
Future Gener. Comput. Syst. | 3 |
| 2026 | Advancing towards a marine digital twin platform: Modeling the mar menor coastal lagoon ecosystem in the south western MediterraneanabstractCoastal marine ecosystems face mounting pressures from anthropogenic activities and climate change, necessitating advanced monitoring and modeling approaches for effective management. This paper pioneers the development of a Marine Digital Twin Platform aimed at modeling the Mar Menor Coastal Lagoon Ecosystem in the Region of Murcia. The platform leverages Artificial Intelligence to emulate complex hydrological and ecological models, facilitating the simulation of what-if scenarios to predict ecosystem responses to various stressors. We integrate diverse datasets from public sources to construct a comprehensive digital representation of the lagoon’s dynamics. The platform’s modular design enables real-time stakeholder engagement and informed decision-making in marine management. Our work contributes to the ongoing discourse on advancing marine science through innovative digital twin technologies. Yu Ye 0005, Aurora González-Vidal, Alejandro Cisterna, Angel Pérez-Ruzafa, Miguel A. Zamora 0001, Antonio F. Skarmeta |
Future Gener. Comput. Syst. | 6 |
| 2026 | Optimizing irrigation in peach trees by predicting trunk water potential using machine learning based on FloraPulse microtensiometersabstractEfficient water management in agriculture is a critical challenge to ensure sustainability, especially in water-constrained regions. Advanced technologies, such as FloraPulse microtensiometers, offer an innovative solution by enabling accurate, real-time monitoring of plant water status by measuring Trunk Water Potential (TWP). This information is essential for assessing water stress and optimising irrigation decisions. This work is the first stage of an overall objective to predict the optimal timing and amount of irrigation. It is important to note that the current models were trained and tested using data from the 2023 season, when all trees were irrigated to 100% of E T c . In this first phase, predictive models are developed that uses advanced Machine Learning (ML) and Deep Learning (DL) techniques to estimate TWP, providing a key tool to anticipate plant water stress as a function of climatic and edaphic variables. According to the initial comparison where ML models (RF, SVR and KNN) and DL model (LSTM) were implemented without using the previous TWP values as input to make the next hour prediction, the LSTM model outperformed the ML models, achieving average R 2 =0.75, MAE=0.19 MPa and CVRMSE=19.22%. Using the lagged TWP values, the LSTM model showed a significant improvement, with average R 2 =0.98, MAE=0.036MPa, and CVRMSE=4%. In addition, LSTM models with 6, 12 and 24 h prediction horizons were developed, all with R 2 greater than 0.89, MAE less than 0.12 MPa and CVRMSE less than 17%. These results allow the precise prediction of future TWP values and thus offer the design of more accurate and efficient irrigation systems. • Trunk Water Potential (TWP) data were collected using the FloraPulse microtensiometer sensor. • Machine Learning (ML) and Deep Learning (DL) models were used to predict the TWP values. • Comparisons were made between ML (RF, SVR, and KNN) and DL (LSTM) models. • LSTM models of 1, 6, 12, and 24 h prediction horizons were implemented. • Results reveal great potential for TWP prediction and irrigation scheduling. Yu Ye 0005, María Fernanda García Cruz, Ricardo Javier Sendra Lázaro, Miguel A. Zamora 0001, Aurora González-Vidal, Pedro Nortes Tortosa, José Salvador Rubio-Asensio, María Fernanda Ortuño Gallud, Antonio F. Skarmeta |
J. Syst. Archit. | 9 |
| 2026 | Vehicle Localization and Tracking for Urban Toll Collection Using BLE Smartphones and Multibeam Antenna Unit
Alejandro Gil-Martínez, Alejandro Rabadán-Parra, David Cañete-Rebenaque, Antonio F. Skarmeta, José Luis Gómez-Tornero |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2026 | Automating 5G Traffic Generation With Virtual UEs: A Scalable Network Testing Infrastructureabstract5G technology represents a transformative leap in wireless networks, promising advancements in smart cities, autonomous transport, and IoT through high data speeds, reduced latency, and support for numerous devices. However, realizing these benefits requires overcoming significant security challenges, particularly in anomaly detection, as the vast device flow increases the risk of vulnerabilities. While AI is critical for this task, the availability of models for AI-based 5G analysis remains limited. This paper addresses this gap by presenting a scalable research framework for generating realistic 5G traffic across both control and user planes without actual 5G devices. The framework enables non-5G devices, such as mobile phones or PCs, to connect to a real 5G RAN infrastructure via virtual User Equipments (UEs), allowing them to generate client traffic at reduced costs and without physical 5G devices. This innovative approach supports the generation of large amounts of 5G traffic, for subsequent collection and analysis to create various datasets, simulating diverse network behaviours for cybersecurity purposes. By leveraging this virtualized environment, our framework offers a versatile, cost-effective solution for comprehensive 5G data generation in a controlled setting. Results demonstrate that 5G traffic generated by non-5G devices through this framework is suitable for AI modelling and training, advancing research capabilities in anomaly detection and overall network security. Emilio Garcia de La Calera Molina, Anthony Joel Pogo Medina, Alejandro Molina Zarca, Pablo Fernández Saura, Antonio F. Skarmeta |
IEEE Trans. Netw. Serv. Manag. | 5 |
| 2025 | On Automating Security Policies with Contemporary LLMs (Short Paper)abstractThe complexity of modern computing environments and the growing sophistication of cyber threats necessitate a more robust, adaptive, and automated approach to security enforcement. In this paper, we present a framework leveraging large language models (LLMs) for automating attack mitigation policy compliance through an innovative combination of in-context learning and retrieval-augmented generation (RAG). We begin by describing how our system collects and manages both tool and API specifications, storing them in a vector database to enable efficient retrieval of relevant information. We then detail the architectural pipeline that first decomposes high-level mitigation policies into discrete tasks and subsequently translates each task into a set of actionable API calls. Our empirical evaluation, conducted using publicly available CTI policies in STIXv2 format and Windows API documen-tation, demonstrates significant improvements in precision, recall, and Fl-score when employing RAG compared to a non-RAG baseline. Pablo Fernández Saura, K. R. Jayaram, Vatche Isahagian, Jorge Bernal Bernabé, Antonio F. Skarmeta |
SSE | 5 |
| 2025 | Ambiguity Resolution of Two Conformal Leaky-Wave Antennas via Deep LearningabstractAmbiguities in direction-of-arrival (DoA) estimation introduces significant challenges in wireless communication systems, particularly in applications requiring precise localization and sensing. These ambiguities can lead to misinterpretation of signal origins, severely impacting the performance and localization of systems such as Wireless Body Area Networks (WBANs) and Internet of Things (IoT) devices. In this paper, we investigate the ambiguities in an array of two symmetric conformal leaky-wave antenna (LWA) system, which, while offering enhanced field-of-view coverage, introduces complexities in resolving directional ambiguities. To address this issue, we propose a novel ambiguity resolution model based on a Long Short-Term Memory (LSTM) network. Our proposed LSTM-based approach achieves an accuracy of 99.99% in resolving ambiguities in comparison with other state of the art techniques. This advancement not only strengthens the reliability of conformal LWA systems but also lays the foundation for more robust and precise localization in wireless scenarios. Alejandro Gil-Martínez, Jesús Pérez-Valero, Jose Antonio Lopez-Pastor, José Luis Gómez-Tornero, Antonio F. Skarmeta |
IPIN | 5 |
| 2025 | The Resilmesh Architecture: Situation Aware Enabled Cyber Resilience for Dispersed, Heterogenous Cyber SystemsabstractCyber systems (CyS) are becoming more and more complex as they are comprised of several infrastructure layers, heterogeneous technologies and dispersed deployments over wide geographical areas (cloud/edge/endpoint) that facilitates multiple attack entry points (vectors). At the same time, CyS attacks are constantly evolving and have become more complex and sophisticated. To address these issues, the ResilMesh architecture aims to provide critical infrastructure security teams with a greater cyber resilience capability by improving cyber resilience using Cyber Situational Awareness (CSA) based security orchestration and analytics framework. The framework enables organizations to achieve real-time defense, reducing attack surface impact by developing tools to combat complexity, disperse infrastructure, delivering flexible placement of security controls across the CyS infrastructure. The architecture combats Advanced Persistent Threat (APT) sophistication by leveraging advanced AI algorithms and tools for early and ongoing attack detection and prediction and improved situation. This paper presents the Resilmesh architecture, a first PoC implementation, as well as an evaluation of the Resilmesh capabilities to detect and mitigate APTs. Jorge Bernal Bernabé, Martin Husák, Lukás Sadlek, Branka Stojanovic, Michael Somma, Jorgeley Inacio de Oliveira, Ekam Puri Nieto, Pablo Fernández Saura, Antonio F. Skarmeta, Vinh Hoa La |
NetSoft | 10 |
| 2025 | AI-Driven Self-Healing in Cloud-Native 6G Networks Through Dynamic Server ScalingabstractThe increasing complexity of cloud-native 6 G networks necessitates intelligent resource management to optimize scalability, energy efficiency, and service reliability. This paper presents an AI-driven self-healing mechanism for dynamic server activation within the a cloud-native system. The proposed framework integrates three key frameworks: the Management and Orchestration Framework (MOF) for policy-based network service orchestration, the Cloud Continuum Framework (CCF) for dynamic resource scaling, and the Artificial Intelligence and Machine Learning Framework (AIMLF) for predictive analytics and anomaly detection. By leveraging AI models, the system continuously monitors workload variations, forecasts resource demand, and dynamically scales computing resources, ensuring optimal energy efficiency and SLA compliance. The proposed self-healing workflow enables proactive server activation and deactivation, addressing load bursts and underutilization scenarios. Numerical evaluations, including real-world traffic data analysis, demonstrate that our approach significantly improves power consumption, load balancing, and resource utilization compared to traditional static resource allocation methods. Anastasios E. Giannopoulos, Sotirios T. Spantideas, Panagiotis Trakadas, Jesús Pérez-Valero, Gines Garcia-Aviles, Antonio F. Skarmeta |
NetSoft | 6 |
| 2025 | Real-Time Network Cyber Situational Awareness in B5G NetworksabstractThe dynamic nature of beyond 5G network (B5G) topologies imposes continuous and real-time cyber situational awareness (CSA) to make cognitive security orchestration according to the actual context. In this sense, security orchestration decisions such as virtual network security functions placement or (re)configuration of the system to counter cyberthreats can benefit of these kind of CSA models. Traditional infrastructure and service models for CSA such as CRUSOE capture the security posture, missions, networks and assets, that can be used as baseline for cognitive functions such as cyber asset attack surface management, risk-trust assessment as well as detection and mitigation of cyber-attacks. However, these infrastructure data models and tools have not been adapted to complex B5G domains and do not support real-time processing of 6 G network traffic that, once supported, can boost context awareness and decision making. This paper describes the design, implementation and evaluation of the extension to the CRUSOE infrastructure model to enable the real-time modeling of 6G network flows, thereby increasing cyber security awareness capabilities in 6 G Security Operation Centers (6G-SOC), that ultimately, can help to improve cognitive security management of 6 G networks. The implementation and performance evaluation carried out shows promising results to capture and model in real time the dynamicity of 6G network topologies and traffic. José Antonio Pastor, Martin Husák, Jorge Bernal Bernabé, Antonio F. Skarmeta |
NetSoft | 4 |
| 2025 | Rethinking AI-Powered Service Orchestration: The Case for DecentralizationabstractThe evolution of cloud computing towards a cloud continuum, including cloud, edge, and far-edge resources, is revolutionizing the deployment, management, and orchestration of Network Services (NSs) and applications. Traditional, centralized orchestration approaches are increasingly inadequate for handling the complexity, scale, and dynamic nature of this continuum. In this paper, we present a data-driven approach for AI-powered service orchestration based on the European 6G-CLOUD project. Specifically, we introduce the Decentralized Service Orchestrator (DSO) framework, an AI-powered, decentralized orchestration model that leverages the capabilities of the Artificial Intelligence and Machine Learning Framework (AI/MLF) to enable intelligent, autonomous, and scalable service lifecycle management across heterogeneous environments. Key contributions include the detailed architecture of the DSO, its workflows, and its integration with the Cloud Continuum and with an AI/MLF that manage the AI lifecycle, enabling models provision to the different components. By enabling decentralized AI-driven decision-making, this framework enhances service reliability, scalability, operational efficiency, and innovation acceleration, paving the way for next-generation cloud continuum orchestration. Jesús Pérez-Valero, Gines Garcia-Aviles, Anastasios E. Giannopoulos, Sotirios T. Spantideas, Antonio F. Skarmeta, Slawomir Kuklinski |
NetSoft | 5 |
| 2025 | Ai-Based Meta-Orchestration for Fl-Based Anomaly Detection in B5g NetworksabstractG networks will need to handle Multi-domain, multi-tenant and multi-operator scenarios where the security orchestration of services and network functions will face high complexity of scalability, interoperability and security. In particular, 6G networks will need to manage AI-based network functions to support analytics that can be encapsulated as virtual functions that need to be dynamically orchestrated, configured, deployed, decommissioned, migrated and reconfigured on demand. The distributed nature of these scenarios requires a federated learning FL approach to handle AI-based collaborative learning where FL-agents can be deployed in the continuum of any network segment of the network. This paper proposes an AI-based meta-orchestration approach for multi-domain and multi-tenant 6 G deployments intended to choreograph the FLbased AI functions. The meta-Orchestration encompasses diverse phases, including selection of the orchestration strategy, the orchestration graph building and the selection of best AI-based orchestration algorithm depending on the actual context, thereby maximizing the effectiveness of the allocation of the FL-agents. The implementation and performance evaluation to orchestrate FL agents with diverse AI-based algorithms across the continuum proves our approach to detect anomalies using FL in distributed scenarios. Pablo Fernández Saura, José Manuel Bernabé Murcia, Alejandro Molina Zarca, Jorge Bernal Bernabé, Antonio F. Skarmeta |
NetSoft | 5 |
| 2025 | Bolstering Up Smart Products Cybersecurity (Re-)Certification with Manufacturer's EvidenceabstractThe innovation brought by smart connected products is transforming many of today's interactions tightly interconnecting physical and digital worlds. Such cyber-physical ecosystems blend data collected in the real world through sensors, with embedded processing, software, and connectivity to reaction (performed autonomously or in concert with the human) in the physical world. Recognizing the widespread adoption of digital elements in many aspects of everyday life along with a ramp up in incidents, recent regulations aim at accelerating on the adoption of good cybersecurity practices. These have the power to protect not only users of individual products but the entire ecosystem and the supply chain throughout all the stages of the lifecycle. A key aspect concerns the cybersecurity certification and how to ensure that the product remains secure once in use or it is re-certified when needed. In the following, we introduce a methodology to support a continuous (re-)certification process by means of evidence already generated by the manufacturer to ensure that product cybersecurity is maintained during operations. Stefano Sebastio, Sreedevi Beena, Sara Nieves Matheu-García, Roland Atoui, Antonio F. Skarmeta |
SMARTCOMP | 5 |
| 2025 | PhenoLinker: Phenotype-gene link prediction and explanation using heterogeneous graph neural networksabstractThe association of a given human phenotype with a genetic variant remains a critical challenge in biomedical research. We present PhenoLinker, a novel graph-based system capable of associating a score to a phenotype-gene relationship by using heterogeneous information networks and a convolutional neural network-based model for graphs, which can provide an explanation for the predictions. Unlike previous approaches, PhenoLinker integrates gene and phenotype attributes, while maintaining explainability through Integrated Gradients. PhenoLinker consistently outperforms existing models in both retrospective and temporal validation tasks. This system can aid in the discovery of new associations and in understanding the consequences of human genetic variation. • PhenoLinker: Advanced Gene-Phenotype Prediction Model: Superior prediction capabilities for gene-phenotype associations • Clear Explanations for Association Predictions: Provides insights into gene-phenotype links • Validated Real-World Impact: Proven reliability in improving genetic diagnoses • Accessible Research Tool: Predictions and visualization openly available, fostering collaboration in gene-phenotype studies Jose L. Mellina Andreu, Luis Bernal, Antonio F. Skarmeta, Mina Ryten, Sara Álvarez, Alejandro Cisterna, Juan A. Botía Blaya |
Artif. Intell. Medicine | 3 |
| 2025 | BASTION: Beyond automated service and security orchestration for next-generation networksabstractThe adoption of 5G technology and beyond introduces advanced capabilities, such as dynamic resource coordination and allocation tailored to specific service and security requirements. To achieve efficient security and network management, service automation and orchestration are essential. This paper presents BASTION, a ZSM-aligned framework for enhanced service and security (meta) orchestration. By leveraging an intent-based, policy-driven approach, it enables the orchestration and enforcement of service and security policies across B5G infrastructures, dynamically adapting to real-time infrastructure conditions. While meta-orchestration capabilities focus on selecting the most suitable orchestration algorithm based on the system’s current status and the received requirements, orchestration capabilities primarily determine what, where, when, and how to enforce services and security policies. Additionally, the modular design and implementation allow for the seamless integration of new security capabilities through plugins, drivers, and managers. This advancement represents a significant step toward building resilient, adaptable, and secure B5G networks capable of meeting the complex demands of modern network environments. The implementation details showcase the full range of capabilities offered by the BASTION framework, highlighting its effectiveness through successful European and national projects. Furthermore, the performance evaluation section provides a comprehensive analysis of orchestration efficiency, breaking down execution times across different phases. In particular, BASTION demonstrates exceptional performance, achieving decision times as low as 1.3 ms and deploying services and security policies, including fully operational dynamic VNFs in less than 30 s, underscoring its ability to deliver fast, scalable, and efficient orchestration in complex environments. José Manuel Bernabé Murcia, Alejandro Molina Zarca, Antonio F. Skarmeta |
Comput. Networks | 3 |
| 2025 | Decentralised Identity Management solution for zero-trust multi-domain Computing Continuum frameworksabstractThe adoption of the Computing Continuum is characterised by the seamless integration of diverse computing environments and devices. In this dynamic landscape, sharing resources across the continuum is becoming a reality and security must move an step forward, specially in terms of authentication and authorisation for such a distributed and heterogeneous environments. The need for robust identity management is paramount and, in this regard, Decentralised Identity Management (DIM) emerges as a promising solution. It leverages decentralised technologies to secure and facilitate identity interactions across the Computing Continuum. Particularly, to enhance security and privacy, it would be desirable to apply the principles of Self-Sovereign Identity (SSI). In this paradigm, users have full ownership and control of their digital identities that empowers individuals to manage and share their identity data on a need-to-know basis. These mechanisms could contribute to improve security properties during continuum resource management operations. In this context, this paper presents the design, workflows and implementation of a solution that provides authentication/authorisation features to distributed zero-trust based infrastructures across the continuum, enhancing security in resource sharing and resource acquisition stages. To this aim, the solution relies on key aspects like decentralisation, interoperability, trust management and privacy-enhancing capabilities. The decentralisation leverages distributed ledger technologies, such as blockchain, to establish a decentralised identity ecosystem. The solution prioritises interoperability, enabling nodes to seamlessly access and share their identities across different domains and environments. Trustworthiness is at the core of DIM, and privacy is also considered, incorporating privacy-preserving techniques that individuals to selectively disclose identity attributes while safeguarding sensitive information. The implementation includes different operations for allowing continuum frameworks to be enhanced with decentralised authentication and authorisation features. The performance has been evaluated measuring the impact for the adoption of the solution. The most expensive task, the self-identity generation, takes only a few seconds (in our deployment) and it is only executed once. Authorisation tasks operate in the millisecond range, which is a totally invaluable time if incorporated into resource acquisition processes in frameworks such as Liqo, used in the scope of FLUIDOS project. José Manuel Bernabé Murcia, Eduardo Cánovas, Jesús García Rodríguez, Alejandro Molina Zarca, Antonio F. Skarmeta |
Future Gener. Comput. Syst. | 5 |
| 2024 | EMPYREAN: Trustworthy, Cognitive and AI-driven Collaborative Associations of IoT Devices and Edge Resources for Data ProcessingabstractThe EU-funded EMPYREAN project (empyrean-horizon.eu) aims to establish a hyper-distributed computing paradigm, leveraging collaborative, heterogeneous IoT devices and federated resources. EMPYREAN focuses on developing technologies for efficient AI workload processing, secure distributed edge storage and cloud-native application development. It will offer open and standardised APIs and use open-source platforms. EMPYREAN's capabilities will be demonstrated through three use cases: advanced manufacturing, smart agriculture, and warehouse automation. Aristotelis Kretsis, Panagiotis C. Kokkinos, Emmanouel A. Varvarigos, Dimitris Syrivelis, Paraskevas Bakopoulos, Márton Sipos, Marcell Fehér, Daniel Enrique Lucani, José Manuel Bernabé Murcia, Antonio F. Skarmeta, Ivan Paez, Luca Cominardi, Michael Mercier, Pedro Velho, Yiannis Georgiou 0002, Charalampos Mainas, Anastassios Nanos, Javier Martin, Aitor Fernández Gómez, Roberto Gonzalez, Panos Ilias, Theodoros Chalazas, Keshav Chintamani |
HPDC | 10 |
| 2024 | Building the Cloud Continuum with REARabstractThe computing continuum combines computational resources and services from edge to cloud, promising enhanced efficiency and resilience with respect to the traditional siloed-based approach. This study presents the REAR (Resource Advertisement and Reservation) protocol, which tackles the complexities of managing resources within this continuum. REAR establishes standardized interfaces to enable interoperability, enhances resource allocation efficiency, and maintains security measures for workload execution. The paper details the protocol’s design, key components, operational workflows, and potential uses, contributing to the optimization of resource use across the computing continuum. Stefano Galantino, Elisa Albanese, Nasir Asadov, Stefano Braghin, Francesco Cappa, Andrea Colli-Vignarelli, Amjad Yousef Majid, Eduard Marin, Jacopo Marino, Lorenzo Moro, Liubov Nedoshivina, Fulvio Risso, Domenico Siracusa, Antonio F. Skarmeta, Luca Zuanazzi |
NetSoft | 14 |
| 2024 | Network slicing as 6G security mechanism to mitigate cyber-attacks: the RIGOUROUS approachabstractWith the emergence of 6G, novel approaches are demanded to identify and address cyber-security, trust and privacy risks threatening the softwarised and virtualised networks and computing infrastructure, and next-generation services. One of the main innovations beyond State-of-the-Art envisioned is to deliver End-to-End Multi-domain Multi-tenant 6G Network Slicing capabilities over Zero-touch Security Network Management.This paper introduces a novel security enabler deployed in the data plane where network slicing is explored as a security mitigation mechanism. In this way, legitimate traffic can be isolated from harmful traffic and the attacker will have near zero vulnerability surface to compromise the implemented security measures. The proposed solution is centred on Network Self-Protection (NSP) based on the Open Virtual Switch (OVS) platform, to which significant extensions have been undertaken to support Network Slicing capabilities in multi-tenant multi-domain beyond 5G networks.Preliminary experiments show promising results in terms of overhead introduced in the data plane (in the order of microseconds) and high scalability when deploying up to 2048 network slices. The proposed software network slicing enabler is a suitable candidate for coping with network traffic with different levels of nested encapsulation associated with this kind of virtualised infrastructures. Antonio Matencio-Escolar, Jorge Bernal Bernabé, José M. Alcaraz Calero, Qi Wang 0001, Antonio F. Skarmeta |
NetSoft | 5 |
| 2024 | Machine learning-powered traffic processing in commodity hardware with eBPFabstractNetwork softwarization is paving the way for the design and development of Next-Generation Networks (NGNs), which are demanding profound improvements to existing communication infrastructures. Two of the fundamental pillars of NGNs are flexibility and intelligence to create elastic network functions capable of managing complex communication systems in an efficient and cost-effective way. In this sense, the extended Berkeley Packet Filter (eBPF) is a state-of-the-art solution that enables low-latency traffic processing within the Linux kernel in commodity hardware. When combined with Machine Learning (ML) algorithms, it becomes a promising enabler to perform smart monitoring and networking tasks at any required place of the fog-edge-cloud continuum. In this work, we present a solution that leverages eBPF to integrate ML-based intelligence with fast packet processing within the Linux kernel, enabling the execution of complex computational tasks in a flexible way, saving resources and reducing processing latencies. A real implementation and a series of experiments have been carried out in an Internet of Things (IoT) scenario to evaluate the performance of the solution to detect attacks in a 6LowPAN system. The performance of the in-kernel implementation shows a considerable reduction in the execution time (-97%) and CPU usage (-6%) of a Multi-Layer Perceptron (MLP) model in comparison with a user space development approach; thus positioning our proposal as a promising solution to embed ML-powered fast packet processing within the Linux kernel. Jorge Gallego-Madrid, Irene Bru-Santa, Álvaro Ruiz-Ródenas, Ramon Sanchez-Iborra, Antonio F. Skarmeta |
Comput. Networks | 5 |
| 2024 | Beyond selective disclosure: Extending distributed p-ABC implementations by commit-and-prove techniquesabstractThe increasing user awareness and regulatory framework (e.g., GDPR, eIDAS2) have contributed to considering data minimization and privacy-by-design as central guiding principles for new systems. Among others, this has led to a paradigm shift towards Self-Sovereign Identity solutions to put the user in full control over their data. Despite the promising landscape, privacy-preserving Attribute-Based Credentials (p-ABC) have not been widely adopted, mainly due to the lack of secure, flexible and efficient implementations that cover the basic and advanced needs in p-ABC systems. In this work, we tackle this gap by developing an improved zero-knowledge showing protocol of a distributed p-ABC scheme based on Pointcheval-Sanders Multi-Signatures to allow for modular extensions through commit-and-prove techniques. We use it to implement a flexible p-ABC system with decentralized issuance that, apart from the basic notions of p-ABCs, covers range proofs, pseudonyms, inspection and revocation. Lastly, we thoroughly evaluate the performance of the system under different testbed conditions, showing a significant efficiency improvement over previous implementations. Jesús García Rodríguez, Stephan Krenn, Jorge Bernal Bernabé, Antonio F. Skarmeta |
Comput. Networks | 4 |
| 2024 | A Convolutional Neural Network approach for image-based anomaly detection in smart agricultureabstractThe recent technological advances and their applications to agriculture provide leverage for the new paradigm of smart agriculture. Remote sensing applications can help optimize resources, making agriculture more ecological, increasing productivity and helping farmers to anticipate events that could not otherwise be avoided. Considering that losses caused by anomalies such as diseases, weeds and pests account for 20-40 % of overall agricultural productivity, a successful research effort in this area would be a breakthrough for agriculture. In this paper, we propose a methodology with which to discover and classify anomalies in images of crops, taken from a wide range of distances, using different Convolutional Neural Network architectures. This methodology also deals with several difficulties that usually appear in this kind of problems, such as class imbalance, the insufficient and small variety of images, overtraining or lack of models generalisation. We have implemented four convolutional neural network architectures in a high-performance computing environment, and propose a methodology based on data augmentation with the addition of Gaussian noise to the images to solve the above problems. Our approach was tested using two well-established open datasets that are unalike: DeepWeeds, which provides a classification of 8 weed species native to Australia using images that were taken at a distance of 1 m, and Agriculture-Vision, which classifies 6 types of crop anomalies using multispectral satellite imagery. Our methodology attained accuracies of 98 % and 95.3% respectively, improving the state-of-the-art by several points. In order to ease reproducibility and model selection, we have provided a comparison in terms of computational time and other metrics, thus enabling the choice between architectures to be made according to the resources available. The complete code is available in an open repository in order to encourage reproducibility and promote scientific advances in sustainable agriculture. José Mendoza-Bernal, Aurora González-Vidal, Antonio F. Skarmeta |
Expert Syst. Appl. | 3 |
| 2023 | DJM-CYBER: A Joint Master in Advanced CybersecurityabstractVarious publicly available studies show that millions of cybersecurity experts are missing worldwide. One possible way to tackle the workforce gap is with tailored higher education programmes. The goal of this paper is to present the relevant projects and frameworks of the European Union which can guide the development of novel cybersecurity education offerings. We describe the most relevant and freely available tools and test them in the development of a joint Master study programme to be offered by a consortium of five European universities. We show that these tools allow educators and study programme developers to map their outputs to the European Cybersecurity Framework developed by the ENISA and other similar frameworks. We complete our work with a detailed analysis of a joint cybersecurity master programme consisting of four innovative and distinctly different tracks. Yianna Danidou, Sara Ricci, Antonio F. Skarmeta, Jiri Hosek, Stefano Zanero, Imre Lendak |
ARES | 3 |
| 2023 | An inclusive Lifecycle Approach for IoT Devices Trust and Identity ManagementabstractERATOSTHENES is an EC, co-funded, research project strongly considering modern security challenges in the domain of Internet of Things in mind of their huge penetration into our day to day lives. There are a series of recent challenges that recently have been converted into obstacles or risk points that could block the secure operation of IoT networks in all day to day activities, from home to office, to leisure and security. These include examples such as the highly increased number of connected devices (at all network levels) that are on top forming inhomogeneous networks and systems of systems. Different vendor characteristics further increase the attack surface that is expected to further rise in the upcoming years. Such, highly critical, characteristics, dramatically increase the needs for confidentiality access control, user and things’ privacy, devices’ trustworthiness and compliance that require lifecycle considerations. The ERATOSTHENES project orchestrates a novel distributed, automated, auditable, yet privacy-respectful, Trust and Identity Management Framework and Reference Architecture with the ultimate scope to dynamically and holistically manage IoT devices in a lifecycle approach, strengthening trust, identities, and resilience in the entire IoT ecosystem while supporting the enforcement of the NIS directive, GDPR and Cybersecurity Act. This publication describes the ERATOSTHENES technical concept and reference architecture as well as design considerations, architecture characteristics, connectivity and interoperability. Konstantinos Loupos, Harris Niavis, Fotis Michalopoulos, George Misiakoulis, Antonio F. Skarmeta, Jesús Garcia, Angel Palomares, Rustem Dautov, Francesca Giampaolo, Rosella Mancilla, Francesca Costantino, Dimitri Van Landuyt, Sam Michiels, Stefan More, Christos Xenakis, Michail Bampatsikos, Ilias Politis, Konstantinos Krilakis, Sokratis Vavilis |
ARES | 5 |
| 2023 | ELECTRON: An Architectural Framework for Securing the Smart Electrical Grid with Federated Detection, Dynamic Risk Assessment and Self-HealingabstractThe electrical grid has significantly evolved over the years, thus creating a smart paradigm, which is well known as the smart electrical grid. However, this evolution creates critical cybersecurity risks due to the vulnerable nature of the industrial systems and the involvement of new technologies. Therefore, in this paper, the ELECTRON architecture is presented as an integrated platform to detect, mitigate and prevent potential cyberthreats timely. ELECTRON combines both cybersecurity and energy defence mechanisms in a collaborative way. The key aspects of ELECTRON are (a) dynamic risk assessment, (b) asset certification, (c) federated intrusion detection and correlation, (d) Software Defined Networking (SDN) mitigation, (e) proactive islanding and (f) cybersecurity training and certification. Panagiotis I. Radoglou-Grammatikis, Thanasis Liatifis, Christos Dalamagkas, Alexios Lekidis, Konstantinos Voulgaridis, Thomas Lagkas, Nikolaos Fotos, Sofia-Anna Menesidou, Thomas Krousarlis, Pedro Ruzafa Alcazar, Juan Francisco Martinez, Antonio F. Skarmeta, Alberto Molinuevo Martín, Iñaki Angulo, Jesus Villalobos Nieto, Hristo Koshutanski, Rodrigo Diaz Rodriguez, Ilias Siniosoglou, Orestis Mavropoulos, Konstantinos Kyranou, Theocharis Saoulidis, Allon Adir, Ramy Masalha, Emanuele Bellini 0001, Nicholas Kolokotronis, Stavros Shiaeles, Jose Garcia Franquelo, George Lalas, Andreas Zalonis, Antonis Voulgaridis, Angelina D. Bintoudi, Konstantinos Votis, David Pampliega, Panagiotis G. Sarigiannidis |
ARES | 12 |
| 2023 | By-default Security Orchestration on distributed Edge/Cloud Computing FrameworkabstractNext generation networks and the strength of the distributed computing paradigm (edge/cloud) are transforming how services are provisioned, mainly when solutions focus on collaboration and aggregation of resources provided by different entities or organisations, that becomes essential to satisfy the most demanding computation and storage service requirements. However, it also entails challenges such as infrastructure and technologies heterogeneity, which directly impacts infrastructure management and especially security, that usually tends to be relegated to a second place. This paper provides a by-default security orchestrator approach to mitigate the above mentioned challenges in distributed edge/cloud computing frameworks. We use an Intent-based/policy-based orchestration paradigm for dealing with heterogeneity, allowing users to request service deployments securely without requiring knowledge about the underlying distributed infrastructure. By-default security orchestration will decide how to provide the requested services, ensuring that they are compliant with the security requirements provided by the user and the ones gathered by the system, locally and from reliable external sources1. We provide design and use-cases based workflows for managing by-default security orchestration in proactive and reactive ways. In the future, it is expected to perform the implementation and validation of the proposed approach inside the scope of the FLUIDOS EU project.1https://www.cisa.gov/known-exploited-vulnerabilities-catalog José Manuel Bernabé Murcia, José Francisco Pérez Zarca, Alejandro Molina Zarca, Antonio F. Skarmeta |
NetSoft | 4 |
| 2023 | European 5G Security in the Wild: Reality versus Expectationsabstract5G cellular systems are slowly being deployed worldwide delivering the promised unprecedented levels of throughput and latency to hundreds of millions of users. At such scale security is crucial, and consequently, the 5G standard includes a new series of features to improve the security of its predecessors (i.e., 3G and 4G). In this work, we evaluate the actual deployment in practice of the promised 5G security features by analysing current commercial 5G networks from several European operators. By collecting 5G signalling traffic in the wild in several cities in Spain, we i) fact-check which 5G security enhancements are actually implemented in current deployments, ii) provide a rich overview of the implementation status of each 5G security feature in a wide range of 5G commercial networks in Europe and compare it with previous results in China, iii) analyse the implications of optional features not being deployed, and iv) discuss on the still remaining 4G-inherited vulnerabilities. Our results show that in European 5G commercial networks, the deployment of the 5G security features is still on the works. This is well aligned with results previously reported from China [16] and keeps these networks vulnerable to some 4G attacks, during their migration period from 4G to 5G. Oscar Lasierra, Gines Garcia-Aviles, Esteban Municio, Antonio F. Skarmeta, Xavier Pérez Costa |
WISEC | 4 |
| 2023 | A multi-layer guided reinforcement learning-based tasks offloading in edge computingabstractThe breakthrough in Machine Learning (ML) techniques and the popularity of the Internet of Things (IoT) has increased interest in applying Artificial Intelligence (AI) techniques to the new paradigm of Edge Computing. One of the challenges in edge computing architectures is the optimal distribution of the generated tasks between the devices in each layer (i.e., cloud-fog-edge). In this paper, we propose to use Reinforcement Learning (RL) to solve the Task Assignment Problem (TAP) at the edge layer and then we propose a novel multi-layer extension of RL (ML-RL) techniques that allows edge agents to query an upper-level agent with more knowledge to improve the performance in complex and uncertain situations. We first formulate the task assignment process considering the trade-off between energy consumption and execution time. We then present a greedy solution as a baseline and implement our multi-layer RL proposal in the PureEdgeSim simulator. Finally several simulations of each algorithm are evaluated with different numbers of devices to verify scalability. The simulation results show that reinforcement learning solutions outperformed the heuristic-based solutions and our multi-layer approach can significantly improve performance in high device density scenarios. Alberto Robles Enciso, Antonio F. Skarmeta |
Comput. Networks | 2 |
| 2023 | A privacy-preserving attribute-based framework for IoT identity lifecycle managementabstractThe Internet of Things (IoT) has brought a new era of interconnected devices and seamless data exchange. As the IoT ecosystem continues to expand, there is an increasing need for effective identity management mechanisms, specifically for authorization processes and access control. The pervasiveness of such devices demands that desirable solutions tackle not only security properties but also privacy aspects like granular control over which identity data is shared in authentication/authorization processes, covering aspects like bootstrapping, enrolment, and service provision. In this context, it is natural to turn to privacy-enhancing technologies, like (privacy-preserving) Attribute-Based Credentials (p-ABC), for achieving both high security and privacy guarantees. Nonetheless, these technical tools need to be accompanied by a comprehensive approach that deals with the particularities of IoT scenarios and covers the full lifetime of the device. In this work, we propose the use of a p-ABC scheme with support for distributed issuance (dp-ABC) as a keystone for privacy-preserving attribute-based authentication and authorization in IoT scenarios. We integrate said cryptographic scheme with W3C’s Verifiable Credentials standard, evaluating its impact to gauge its feasibility. The integration facilitates adoption and, particularly, allows the solution to transparently coexist with simpler techniques in heterogeneous scenarios that demand them. Moreover, we define and analyse a generic and comprehensive framework for identity management that identifies challenges throughout the device’s lifetime to achieve IoT privacy-preserving identity management following self-sovereign principles. We show how the various aspects identified in the framework are tackled in a concrete instantiation as part of the H2020 project ERATOSTHENES. Jesús García Rodríguez, Antonio F. Skarmeta |
Comput. Networks | 2 |
| 2023 | Intrusion Detection Based on Privacy-Preserving Federated Learning for the Industrial IoTabstractFederated learning (FL) has attracted significant interest given its prominent advantages and applicability in many scenarios. However, it has been demonstrated that sharing updated gradients/weights during the training process can lead to privacy concerns. In the context of the Internet of Things (IoT), this can be exacerbated due to intrusion detection systems (IDSs), which are intended to detect security attacks by analyzing the devices’ network traffic. Our work provides a comprehensive evaluation of differential privacy techniques, which are applied during the training of an FL-enabled IDS for industrial IoT. Unlike previous approaches, we deal with nonindependent and identically distributed data over the recent ToN_IoT dataset, and compare the accuracy obtained considering different privacy requirements and aggregation functions, namely FedAvg and the recently proposed Fed+. According to our evaluation, the use of Fed+ in our setting provides similar results even when noise is included in the federated training process. Pedro Ruzafa Alcazar, Pablo Fernández Saura, Enrique Mármol Campos, Aurora González-Vidal, José Luis Hernández-Ramos, Jorge Bernal Bernabé, Antonio F. Skarmeta |
IEEE Trans. Ind. Informatics | 7 |
| 2022 | Dynamic Risk Assessment and Certification in the Power Grid: A Collaborative ApproachabstractThe digitisation of the typical electrical grid introduces valuable services, such as pervasive control, remote monitoring and self-healing. However, despite the benefits, cybersecurity and privacy issues can result in devastating effects or even fatal accidents, given the interdependence between the energy sector and other critical infrastructures. Large-scale cyber attacks, such as Indostroyer and DragonFly have already demonstrated the weaknesses of the current electrical grid with disastrous consequences. Based on the aforementioned remarks, both academia and industry have already designed various cybersecurity standards, such as IEC 62351. However, dynamic risk assessment and certification remain crucial aspects, given the sensitive nature of the electrical grid. On the one hand, dynamic risk assessment intends to re-compute the risk value of the affected assets and their relationships in a dynamic manner based on the relevant security events and alarms. On the other hand, based on the certification process, new approach for the dynamic management of the security need to be defined in order to provide adaptive reaction to new threats. This paper presents a combined approach, showing how both aspects can be applied in a collaborative manner in the smart electrical grid. Thanasis Liatifis, Pedro Ruzafa Alcazar, Panagiotis I. Radoglou-Grammatikis, Dimitrios Papamartzivanos, Sofia-Anna Menesidou, Thomas Krousarlis, Alberto Molinuevo Martín, Iñaki Angulo, Antonios Sarigiannidis, Thomas Lagkas, Vasileios Argyriou, Antonio F. Skarmeta, Panagiotis G. Sarigiannidis |
NetSoft | 12 |
| 2022 | Automatic, verifiable and optimized policy-based security enforcement for SDN-aware IoT networks
Daniele Bringhenti, Jalolliddin Yusupov, Alejandro Molina Zarca, Fulvio Valenza, Riccardo Sisto, Jorge Bernal Bernabé, Antonio F. Skarmeta |
Comput. Networks | 7 |
| 2022 | Evaluating Federated Learning for intrusion detection in Internet of Things: Review and challengesabstractThe application of Machine Learning (ML) techniques to the well-known intrusion detection systems (IDS) is key to cope with increasingly sophisticated cybersecurity attacks through an effective and efficient detection process. In the context of the Internet of Things (IoT), most ML-enabled IDS approaches use centralized approaches where IoT devices share their data with data centers for further analysis. To mitigate privacy concerns associated with centralized approaches, in recent years the use of Federated Learning (FL) has attracted a significant interest in different sectors, including healthcare and transport systems. However, the development of FL-enabled IDS for IoT is in its infancy, and still requires research efforts from various areas, in order to identify the main challenges for the deployment in real-world scenarios. In this direction, our work evaluates a FL-enabled IDS approach based on a multiclass classifier considering different data distributions for the detection of different attacks in an IoT scenario. In particular, we use three different settings that are obtained by partitioning the recent ToN_IoT dataset according to IoT devices’ IP address and types of attack. Furthermore, we evaluate the impact of different aggregation functions according to such setting by using the recent IBMFL framework as FL implementation. Additionally, we identify a set of challenges and future directions based on the existing literature and the analysis of our evaluation results. Enrique Mármol Campos, Pablo Fernández Saura, Aurora González-Vidal, José Luis Hernández-Ramos, Jorge Bernal Bernabé, Gianmarco Baldini, Antonio F. Skarmeta |
Comput. Networks | 7 |
| 2022 | QoS and Resource-Aware Security Orchestration and Life Cycle ManagementabstractZero-touch network and service management (ZSM) exploits network function virtualization (NFV) and software-defined networking (SDN) to efficiently and dynamically orchestrate different service function chaining (SFC), whereby reducing capital expenditure and operation expenses. The SFC is an optimization problem that shall consider different constraints, such as Quality of Service (QoS), and actual resources, to achieve cost-efficient scheduling and allocation of the service functions. However, the large-scale, complexity and security issues brought by virtualized IoT networks, which embrace different network segments, e.g., Fog, Edge, Core, Cloud, that can also exploit proximity (computation offloading of virtualized IoT functions to the Edge), imposes new challenges for ZSM orchestrators intended to optimize the SFC, thereby achieving seamless user-experience, minimal end-to-end delay at a minimal cost. To cope with these challenges, this paper proposes a cost-efficient optimized orchestration system that addresses the whole life-cycle management of different SFCs, that considers QoS (including end-to-end delay, bandwidth, jitters), actual capacities of Virtual Network Functions (VNFs), potentially deployed across multiple Clouds-Edges, in terms of resources (CPU, RAM, storage) and current network security levels to ensure trusted deployments. The proposed orchestration system has been implemented and evaluated in the scope of H2020 Anastacia EU project,1showing its feasibility and performance to efficiently manage SFC, optimizing deployment costs, reducing overall end-to-end delay and optimizing VNF instances distribution. Miloud Bagaa, Tarik Taleb, Jorge Bernal Bernabé, Antonio F. Skarmeta |
IEEE Trans. Mob. Comput. | 4 |
| 2021 | Towards a standardized model for privacy-preserving Verifiable CredentialsabstractLack of standardization and the subsequent difficulty of integration has been one of the main reasons for the scarce adoption of privacy-preserving Attribute-Based Credentials (p-ABC). Integration with the W3C’s Verifiable Credentials (VC) specification would help by encouraging homogenization between different p-ABC schemes and bringing them all closer to other digital credentials. What is more, p-ABCs can help to solve privacy issues that have been identified in applications of VCs to use cases like vaccination passports. However, there has not been much work focusing on the collaboration between p-ABCs and VCs. We address this topic by establishing initial steps for extra standardization of elements that will help with the integration of p-ABCs into the standard. Namely, we propose a data model for predicates, which are a staple of p-ABC systems, and tools and guidelines to ease the adaptation process like a validation meta-schema. These ideas have been applied in a proof-of-concept implementation of the OLYMPUS distributed p-ABC scheme paired with serialization following the VC data model. Jesús García Rodríguez, Rafael Torres Moreno, Jorge Bernal Bernabé, Antonio F. Skarmeta |
ARES | 4 |
| 2021 | BIGcoldTRUCKS: a BIG data dashboard for the management of COLD chain logistics in refrigerated TRUCKSabstractThe technological development of the food industry is bringing new opportunities for the optimization of cold chain logistics. Many businesses of all sizes have been capturing their trips’ data and they are ready to apply Big Data analytics and use Big Data tools in order to extract knowledge and patterns that can be useful for decision-making and therefore provide added value to their business. In this line, we developed a shiny dynamic dashboard that provides a friendly user interface to the business in order to visualize and understand their data in the form of rankings, trips duration, demand seasonality, and geographic representation of the trips. The dashboard connects seamlessly with two Big Data tools, elasticSearch and the DEEP training facility from the European Open Science Hub (EOSC). More specifically, those tools were used for data indexing and demand estimation of products using cloud computing respectively. Thanks to the interconnection of these tools, we are able to enhance the dynamic dashboard with Big Data Analytics in the form of multivariate demand prediction of the products using a Long Short Term Memory Network and ease query time and computation, creating real value for the cold chain logistics industry. The development of this solution was done with the support of the EOSC-Digital Innovation Hub initiative through a business pilot.The dashboard functionalities were implemented using a real-case dataset which cannot be shown for privacy reasons. In its place, we have simulated a meat-based products database for the purpose of this paper. Aurora González-Vidal, Paula Gómez-Bernal, José Mendoza-Bernal, Antonio F. Skarmeta |
IEEE BigData | 4 |
| 2021 | Missing Data Imputation With Bayesian Maximum Entropy for Internet of Things ApplicationsabstractInternet of Things (IoT) enables the seamless integration of sensors, actuators, and communication devices for real-time applications. IoT systems require good quality sensor data in order to make real-time decisions. However, values are often missing from the sensor data collected owing to faulty sensors, a loss of data during communication, interference, and measurement errors. Considering the spatiotemporal nature of IoT data and the uncertainty of the data collected by sensors, we propose a new framework with which to impute missing values utilizing Bayesian maximum entropy (BME) as a convenient means to estimate the missing data from IoT applications. Missing sensor measurements adversely affect the quality of data, and consequently the performance and outcomes of IoT systems. Our proposed framework incorporates BME in order to impute missing values in diverse IoT scenarios by making use of the combination of low- and high-precision sensors. Our approach can incorporate the measurement errors of low-precision sensors as interval quantities along with the high-precision sensor measurements, making it highly suitable for real-time IoT systems. Our framework is robust to variations in data, requires less execution time, and requires only a single input parameter, thus outperforming existing IoT data imputation methods. The experimental results obtained for three IoT data sets demonstrate the superiority of the BME framework as regards accuracy, running time, and robustness. The framework can additionally be extended to distributed IoT nodes for the online imputation of missing values. Aurora González-Vidal, Punit Rathore, Aravinda S. Rao, José Mendoza-Bernal, Marimuthu Palaniswami, Antonio F. Skarmeta |
IEEE Internet Things J. | 6 |
| 2021 | Implementation and evaluation of a privacy-preserving distributed ABC scheme based on multi-signaturesabstractDespite the latest efforts to foster the adoption of privacy-enhancing Attribute-Based Credential (p-ABC) systems in electronic services, those systems are not yet broadly adopted. The main reasons behind this are performance efficiency issues, lack of interoperability with standards, and the centralized architectural scheme that relies on a unique Identity Provider (IdP) for credential issuance. To cope with these limitations, this paper describes the first implementation of the Pointcheval–Sanders Multi-Signatures (PS-MS) crypto scheme proposed by Camenisch et al. and its integration in a distributed and privacy-preserving identity management system proposed in OLYMPUS H2020 European research project. Our efficient implementation provides remarkable privacy-preservation features for identity management in online transactions leveraging p-ABC systems, including unforgeability, minimal disclosure of personal data through zero-knowledge proofs, unlinkability in online transactions and fully distributed credential issuance across different IdPs, thereby removing the IdP as a unique point of failure. The performance of the implementation has been exhaustively analyzed and evaluated with different curves, signers and number of attributes, and compared against Identity Mixer, the best known p-ABC system, outperforming significantly the credential issuance and zero-knowledge proving and verification processes (2–4 times less execution time). Jesús García Rodríguez, Rafael Torres Moreno, Jorge Bernal Bernabé, Antonio F. Skarmeta |
J. Inf. Secur. Appl. | 4 |
| 2021 | Distributed real-time SlowDoS attacks detection over encrypted traffic using Artificial Intelligence
Norberto Garcia, Tomás Alcañiz, Aurora González-Vidal, Jorge Bernal Bernabé, Antonio F. Skarmeta |
J. Netw. Comput. Appl. | 6 |
| 2020 | INSPIRE-5Gplus: intelligent security and pervasive trust for 5G and beyond networksabstractThe promise of disparate features envisioned by the 3GPP for 5G, such as offering enhanced Mobile Broadband connectivity while providing massive Machine Type Communications likely with very low data rates and maintaining Ultra Reliable Low Latency Communications requirements, create a very challenging environment for protecting the 5G networks themselves and associated assets. To overcome such complexity, future 5G networks must employ a very high degree of network and service management automation, which is a security challenge by itself as well as an opportunity for smarter and more efficient security functions. In this paper, we present the smart, trustworthy and liable 5G security platform being designed and developed in the INSPIRE-5Gplus1 project. This platform takes advantage of new techniques such as Machine Learning (ML), Artificial Intelligence (AI), Distributed Ledger Technologies (DLT), network softwarization and Trusted Execution Environment (TEE) for closed-loop and end-to-end security management following a zero-touch model in 5G and Beyond 5G networks. To this end, we specifically elaborate on two key aspects of our platform, namely security management with Security Service Level Agreements (SSLAs) and liability management, in addition to the description of the overall architecture. Jordi Ortiz 0001, Ramon Sanchez-Iborra, Jorge Bernal Bernabé, Antonio F. Skarmeta, Chafika Benzaid, Tarik Taleb, Pol Alemany, Raul Muñoz 0001, Ricard Vilalta, Chrystel Gaber, Jean-Philippe Wary, Dhouha Ayed, Pascal Bisson, Maria Christopoulou, Georgios Xilouris, Edgardo Montes de Oca, Gürkan Gür, Gianni Santinelli, Vincent Lefebvre, Antonio Pastor 0001, Diego R. López |
ARES | 4 |
| 2020 | QoS and Resource aware Security Orchestration SystemabstractNetwork Function Virtualization (NFV) and Software Distributed Networking (SDN) technologies play a crucial role in enabling 5G system and beyond. A synergy between these both technologies has been identified for enabling a new concept dubbed service function chains (SFC) that aims to reduce both the capital expenditures (CAPEX) and operating expenses (OPEX). The SFC paradigm considers different constraints and key performance indicators (KPIs), that includes QoS and different resources, for enabling network slice services. However, the large-scale, complexity and security issues brought by these technologies create an extra overhead for ensuring secure network slicing. To cope with these challenges, this paper proposes a cost-efficient optimized SFC management system that enables the creation of SFCs for enabling efficient and secure network slices. The proposed system considers the network and computational resources and current network security levels to ensure trusted deployments. The simulation results demonstrated the efficiency of the proposed solution for achieving its designed objectives. The proposed solution efficiently manages the SFCs by optimizing deployment costs and reducing overall end-to-end delay. Miloud Bagaa, Tarik Taleb, Jorge Bernal Bernabé, Antonio F. Skarmeta |
GLOBECOM | 4 |
| 2020 | Dependable Content-Aware Prefetching for HTTP Applications over ICN as a ServiceabstractThe importance of Hypertext Transfer Protocol (HTTP) in the interaction of users with the Internet is undisputed. Content Delivery Networks (CDNs) have emerged as a promising solution to enhance Quality of Service (QoS) provided in this type of transactions and to improve the network scalability. In this line, a new paradigm known as Information Centric Networks (ICNs) has been envisioned focusing the network routing on the content itself instead of attending to the topological addressing of nodes. A recent trend is using Software Define Networks (SDN) to manage data flows in this context. On top of an ICN as a Service (ICNaaS) architecture that provides end-to-end HTTP Information Centric Networking (ICN) alike transmissions with HTTP in-network caching, this paper proposes a dependable content aware prefetching mechanism, to enhance data transmission rates for first requesters that usually do not benefit from previous access to the same content. The validation tests have been conducted by considering the case of a video streaming service using the H.264/SVC codec with DASH. The obtained results corroborate the validity of the solution with cache hit ratios and client performance near to pre-cached content for video streaming. Jordi Ortiz 0001, Ramon Sanchez-Iborra, José Santa, Antonio F. Skarmeta |
IECON | 4 |
| 2020 | Quality Criteria for Cyber Security MOOCs
Simone Fischer-Hübner, Matthias Beckerle, Alberto Lluch-Lafuente, Antonio Ruiz-Martínez, Karo Saharinen, Antonio F. Skarmeta, Pierantonia Sterlini |
WISE | 6 |
| 2020 | Evaluation of a zone encryption scheme for vehicular networksabstractVehicular communications are bringing a new wave of applications under the umbrella of the Cooperative Intelligent Transportation Systems (C-ITS). To this end, on-board units are expected to send messages periodically or upon the appearance of a relevant event, to feed an awareness ecosystem that enables safety or traffic efficiency services. This is the case of Cooperative Awareness Messages (CAMs) in Europe, which contain basic vehicle information such as its position or speed, among other parameters. From a network security perspective, CAMs are broadcasted unencrypted over an unprotected radio channel, hence enabling their potential interception and the disclosure of sensitive data. Although public key infrastructures (PKI)-like solutions have been proposed, high computational cost of asymmetric cryptography to cipher application data remains a challenge and a confidentiality alternative is needed. In this work, we present the implementation and evaluation of a symmetric encryption scheme based on disjoint security domains distributed in geographical areas. In the solution, vehicles are able to coordinate and agree on common keys to be used in different security zones. Simulation results show the validity of the zone encryption scheme in diverse vehicular scenarios with different traffic densities. A potential issue in the zone key redistribution consisting in the propagation of wrongly-generated duplicated keys is also detected, which is discussed in detail and a reliable solution based on the support of third-party data-forwarders is proposed and tested. Evaluations reveal good performance of the zone encryption mechanism in terms of robustness and latency, guaranteeing the efficient access to a secured channel while maintaining low computing load. Jorge Gallego-Madrid, Ramon Sanchez-Iborra, José Santa, Antonio F. Skarmeta |
Comput. Networks | 4 |
| 2020 | ARIES: Evaluation of a reliable and privacy-preserving European identity management framework
Jorge Bernal Bernabé, Martin David, Rafael Torres Moreno, Javier Presa Cordero, Sébastien Bahloul, Antonio F. Skarmeta |
Future Gener. Comput. Syst. | 6 |
| 2020 | Application Layer Key Establishment for End-to-End Security in IoTabstractIn most Internet of Things (IoT) deployments, intermediate entities are usually employed for efficiency and scalability reasons. These intermediate proxies break end-to-end security when using even the state-of-the-art transport layer security (TLS) solutions. In this direction, the recent object security for constrained RESTful environments (OSCORE) has been standardized to enable end-to-end security even in the presence of malicious proxies. In this article, we focus on the key establishment process based on application-layer techniques. In particular, we evaluate the ephemeral Diffie-Hellman over COSE (EDHOC), the de facto key establishment protocol for OSCORE. Based on EDHOC, we propose CompactEDHOC, as a lightweight alternative, in which negotiation of security parameters is extracted from the core protocol. In addition to providing end-to-end security properties, we perform extensive evaluation using real IoT hardware and simulation tools. Our evaluation results prove EDHOC-based proposals as an effective and efficient approach for the establishment of a security association in IoT-constrained scenarios. Salvador Pérez, José Luis Hernández-Ramos, Shahid Raza, Antonio F. Skarmeta |
IEEE Internet Things J. | 4 |
| 2020 | Virtual IoT HoneyNets to Mitigate Cyberattacks in SDN/NFV-Enabled IoT NetworksabstractAs the IoT adoption is growing in several fields, cybersecurity attacks involving low-cost end-user devices are increasing accordingly, undermining the expected deployment of IoT solutions in a broad range of scenarios. To address this challenge, emerging Network Function Virtualization (NFV) and Software Defined Networking (SDN) technologies can introduce new security enablers, thereby endowing IoT systems and networks with higher degree of scalability and flexibility required to cope with the security of massive IoT deployments. In this sense, honeynets can be enhanced with SDN and NFV support, to be applied into IoT scenarios thereby strengthening the overall security. IoT honeynets are virtualized services simulating real IoT networks deployments, so that attackers can be distracted from the real target. In this paper, we present a novel mechanism leveraging SDN and NFV aimed to autonomously deploy and enforce IoT honeynets. The system follows a security policy-based approach that facilitates management, enforcement and orchestration of the honeynets and it has been successfully implemented and tested in the scope of H2020 EU project ANASTACIA, showing its feasibility to mitigate cyber-attacks. Alejandro Molina Zarca, Jorge Bernal Bernabé, Antonio F. Skarmeta, José M. Alcaraz Calero |
IEEE J. Sel. Areas Commun. | 3 |
| 2020 | Distributed Security Framework for Reliable Threat Intelligence SharingabstractComputer security incident response teams typically rely on threat intelligence platforms for information about sightings of cyber threat events and indicators of compromise. Other security building blocks, such as Network Intrusion Detection Systems, can leverage the information to prevent malicious adversaries from spreading malware across critical infrastructures. The effectiveness of threat intelligence platforms heavily depends on the willingness to share among organizations and the responsible use of sensitive information that may potentially harm the reputation of the reporting organization. The challenge that we address is the lack of trust in the source providing the threat intelligence and the information itself. We enhance our security framework TATIS—offering fine-grained protection for threat intelligence platform APIs—with distributed ledger capabilities to enable reliable and trustworthy threat intelligence sharing with the ability to audit the provenance of threat intelligence. We have implemented and evaluated the feasibility of our distributed framework on top of the Malware Information Sharing Platform (MISP) solution, and we evaluate the performance impact using real-world open-source threat intelligence feeds. Davy Preuveneers, Wouter Joosen, Jorge Bernal Bernabé, Antonio F. Skarmeta |
Secur. Commun. Networks | 4 |
| 2019 | MEC-Assisted End-to-End 5G-Slicing for IoTabstractThe Internet of Things (IoT) has emerged as a key horizontal technology enabler within the 5G ecosystem, characterized by supporting the heterogeneity of end-devices, radio-access technologies, and services. Network slicing techniques allow to configure dedicated networks with assured resources to specific users or applications over a common physical infrastructure. This paper describes a novel end- to-end network slicing framework for IoT services in 5G systems, based on a Multi-Access Edge Computing (MEC) and central cloud architecture that permits the flexible and dynamic placement of micro-services encapsulated as Virtualized Network Functions (VNFs) along the end-to-end path. The critical analysis of the validation results highlights the performance and flexibility gains of our proposal. It allows deploying end-to-end slices over a number of participating domains in a very short time, it is able to isolate slices with guaranteed Quality of Service (QoS) parameters, and shows great scalability in terms of number of connected end-devices and application services. Ramon Sanchez-Iborra, Stefan Covaci, José Santa, Jesús Sánchez Gómez, Jorge Gallego-Madrid, Antonio F. Skarmeta |
GLOBECOM | 6 |
| 2019 | Architecture of security association establishment based on bootstrapping technologies for enabling secure IoT infrastructures
Salvador Pérez, Dan García-Carrillo, Rafael Marín López, José Luis Hernández-Ramos, Rafael Marín-Pérez, Antonio F. Skarmeta |
Future Gener. Comput. Syst. | 6 |
| 2019 | An open IoT platform for the management and analysis of energy data
Fernando Terroso-Saenz, Aurora González-Vidal, Alfonso P. Ramallo-González, Antonio F. Skarmeta |
Future Gener. Comput. Syst. | 4 |
| 2019 | Security Management Architecture for NFV/SDN-Aware IoT SystemsabstractThe Internet of Things (IoT) brings a multidisciplinary revolution in several application areas. However, security and privacy concerns are undermining a reliable and resilient broad-scale deployment of IoT-enabled critical infrastructures (IoT-CIs). To fill this gap, this paper proposes a comprehensive architectural design that captures the main security and privacy challenges related to cyber-physical systems and IoT-CIs. The architecture is devised to empower IoT systems and networks to make autonomous security decisions through the usage of novel technologies such as software defined networking and network function virtualization, as well as endowing them with intelligent and dynamic security reaction capabilities by relying on monitoring methodologies and cyber-situational tools. The architecture has been successfully implemented and evaluated in the scope of ANASTACIA H2020 EU research project. Alejandro Molina Zarca, Jorge Bernal Bernabé, Rubén Trapero, Jesus Villalobos, Antonio F. Skarmeta, Stefano Bianchi, Anastasios Zafeiropoulos, Panagiotis Gouvas |
IEEE Internet Things J. | 6 |
| 2018 | Empirical Study of Massive Set-Point Behavioral Data: Towards a Cloud-Based Artificial Intelligence that Democratizes ThermostatsabstractThe research showed in this document consisted on monitoring 546 air conditioners of individual offices located in two large buildings for the later evaluation of the behaviors of users with respect to their controllers. Data was collected over 14 months and provided important insights about the phenomenon. It was seen that users can be separated in two groups, one that likes to interact with the controllers often and change the temperature at least once a week and another that interact less. It was seen that the variability of users with respect to the thermostat values they prefer is high, and that this should be taken into account when creating a "one fits all" solution. Also, it appears that adaptive thermal comfort theories that suggest users want lower temperatures in cold months are not reflected on the set-points chosen. In addition, we have seen that people interacting more with the controllers tend to waste less energy, this would be interesting if an app to interact with the user for this purpose is design. More communication with the user may imply less energy wasted. Aurora González-Vidal, Alfonso P. Ramallo-González, Antonio F. Skarmeta |
SMARTCOMP | 3 |
| 2018 | Protecting personal data in IoT platform scenarios through encryption-based selective disclosure
José Luis Hernández-Ramos, Salvador Pérez, Christine Hennebert, Jorge Bernal Bernabé, Benoît Denis, Alexandre Macabies, Antonio F. Skarmeta |
Comput. Commun. | 7 |
| 2018 | Evolving IoT networks by the confluence of MEC and LP-WAN paradigms
Ramon Sanchez-Iborra, Jesús Sánchez Gómez, Antonio F. Skarmeta |
Future Gener. Comput. Syst. | 3 |
| 2018 | Matching federation identities, the eduGAIN and STORK approach
Elena Torroglosa-García, Jordi Ortiz 0001, Antonio F. Skarmeta |
Future Gener. Comput. Syst. | 3 |
| 2018 | 5G NB-IoT: Efficient Network Traffic Filtering for Multitenant IoT Cellular NetworksabstractInternet of Things (IoT) is a key business driver for the upcoming fifth-generation (5G) mobile networks, which in turn will enable numerous innovative IoT applications such as smart city, mobile health, and other massive IoT use cases being defined in 5G standards. To truly unlock the hidden value of such mission-critical IoT applications in a large scale in the 5G era, advanced self-protection capabilities are entailed in 5G-based Narrowband IoT (NB-IoT) networks to efficiently fight off cyber-attacks such as widespread Distributed Denial of Service (DDoS) attacks. However, insufficient research has been conducted in this crucial area, in particular, few if any solutions are capable of dealing with the multiple encapsulated 5G traffic for IoT security management. This paper proposes and prototypes a new security framework to achieve the highly desirable self-organizing networking capabilities to secure virtualized, multitenant 5G-based IoT traffic through an autonomic control loop featured with efficient 5G-aware traffic filtering. Empirical results have validated the design and implementation and demonstrated the efficiency of the proposed system, which is capable of processing thousands of 5G-aware traffic filtering rules and thus enables timely protection against large-scale attacks. Pablo Salva-Garcia, José M. Alcaraz Calero, Qi Wang 0001, Jorge Bernal Bernabé, Antonio F. Skarmeta |
Secur. Commun. Networks | 5 |
| 2018 | BEATS: Blocks of Eigenvalues Algorithm for Time Series SegmentationabstractThe massive collection of data via emerging technologies like the Internet of Things (IoT) requires finding optimal ways to reduce the observations in the time series analysis domain. The IoT time series require aggregation methods that can preserve and represent the key characteristics of the data. In this paper, we propose a segmentation algorithm that adapts to unannounced mutations of the data (i.e., data drifts). The algorithm splits the data streams into blocks and groups them in square matrices, computes the Discrete Cosine Transform (DCT), and quantizes them. The key information is contained in the upper-left part of the resulting matrix. We extract this sub-matrix, compute the modulus of its eigenvalues, and remove duplicates. The algorithm, called BEATS, is designed to tackle dynamic IoT streams, whose distribution changes over time. We implement experiments with six datasets combining real, synthetic, real-world data, and data with drifts. Compared to other segmentation methods like Symbolic Aggregate approXimation (SAX), BEATS shows significant improvements. Trying it with classification and clustering algorithms it provides efficient results. BEATS is an effective mechanism to work with dynamic and multi-variate data, making it suitable for IoT data sources. The datasets, code of the algorithm and the analysis results can be accessed publicly at: https://github.com/auroragonzalez/BEATS. Aurora González-Vidal, Payam M. Barnaghi, Antonio F. Skarmeta |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2018 | Offloading Positioning onto Network EdgeabstractWhile satellite or cellular positioning implies dedicated hardware or network infrastructure functions, indoor navigation or novel IoT positioning techniques include flexible storage and computation requirements that can be fulfilled by both end‐devices or cloud back‐ends. Hybrid positioning systems support the integration of several algorithms and technologies; however, the common trend of delegating position calculation and storage of local geoinformation to mobile devices or centralized servers causes performance degradation in terms of delay, battery usage, and waste of network resources. The strategy followed in this work is offloading this computation effort onto the network edge, following a Mobile Edge Computing (MEC) approach. MEC nodes in the access network of the mobile device are in charge of receiving navigation data coming from both the smart infrastructure and mobile devices, in order to compute the final position following a hybrid approach. With the aim of supporting mobility and the access to multiple networks, an Information Centric Networking (ICN) solution is used to access generic position information resources. The presented system currently supports WiFi, Bluetooth LE, GPS, cellular and NFC technologies, involving both indoor and outdoor positioning, using fingerprinting and proximity for indoor navigation, and the integration of smart infrastructure data sources such as the door opening system within real smart campus deployment. Evaluations carried out reveal latency improvements of 50%, as compared with a regular configuration where position fixes are computed by mobile devices; at the same time the MEC solution offers extra flexibility features to manage positioning databases and algorithms and move extensive computation from constrained devices to the edge. José Santa, Pedro J. Fernández, Ramon Sanchez-Iborra, Jordi Ortiz 0001, Antonio F. Skarmeta |
Wirel. Commun. Mob. Comput. | 5 |
| 2017 | Data driven modeling for energy consumption prediction in smart buildingsabstractEnergy efficiency is in the interest of everyone, from individuals to governments, since it yields economical savings, reduces greenhouse gas emissions and alleviates energy poverty. Buildings are one of the largest consumers of primary energy and attaining their efficiency is, therefore, an important goal. The Internet of Things currently provides vast amounts of data that can be used to extract knowledge of all kinds, including that regarding energy prediction. This has motivated us to test wether the prior information on the physics of building heat transfer, that is currently available is now redundant owing to the completeness of the data from the system. We propose a machine learning approach and a grey-box model approach with which to test this hypothesis. The former is blind to the physiscs of the problem, while the latter is greatly influenced by it. The energy consumption prediction models were created with both approaches and then used to estimate energy consumption in a normal operation state and compare it with energy consumption when an energy efficiency campaign is run. Our black-box method, which is based on a combination of statistical and machine learning models and on a time series structurization of the data, shows better prediction accuracy than the so-called grey-box methods that include basic physical equations. This shows that also a data driven approach outperforms more informed methods in this, like other fields. Aurora González-Vidal, Alfonso P. Ramallo-González, Fernando Terroso-Saenz, Antonio F. Skarmeta |
IEEE BigData | 4 |
| 2017 | Transmission Technologies Comparison for IoT Communications in Smart-CitiesabstractThe emergence of the Internet of Things (IoT) paradigm is boosting a great amount of new applications unimaginable short time ago. However, typical smart-city scenarios pose serious difficulties for providing connectivity to end- devices. Thus, a novel transmission technology, known as LP-WAN (Long Range - Wide Area Network), has attracted great attention during the last times due to its long-range transmission capabilities while preserving the end-device's energy consumption. This proposal is at its first stages of development, so comparative studies are needed in order to evaluate its validity over well-established solutions. For that reason, in this work we present an experimental performance evaluation of one the most extended LP-WAN- enabling modulation technologies, LoRa (Long Range). We compare its performance with that attained by the short-range modulation FSK (Frequency Shift Keying) in typical smart-city scenarios. Thereafter, the focus is exclusively on LoRa, so a coverage range study with different modulation configurations is presented. The obtained results suggest the superior performance of LoRa over FSK under adverse transmission conditions. Moreover, promising transmission ranges over 7 km in suburban scenarios were attained. Jesús Sánchez Gómez, Ramon Sanchez-Iborra, Antonio F. Skarmeta |
GLOBECOM | 3 |
| 2017 | Applicability of Big Data Techniques to Smart Cities DeploymentsabstractThis paper presents the main foundations of big data applied to smart cities. A general Internet of Things based architecture is proposed to be applied to different smart cities applications. We describe two scenarios of big data analysis. One of them illustrates some services implemented in the smart campus of the University of Murcia. The second one is focused on a tram service scenario, where thousands of transit-card transactions should be processed. Results obtained from both scenarios show the potential of the applicability of this kind of techniques to provide profitable services of smart cities, such as the management of the energy consumption and comfort in smart buildings, and the detection of travel profiles in smart transport. María Victoria Moreno Cano, Fernando Terroso-Saenz, Aurora González-Vidal, Mercedes Valdés-Vela, Antonio F. Skarmeta, Miguel A. Zamora 0001, Victor Chang 0001 |
IEEE Trans. Ind. Informatics | 5 |
| 2017 | SecRBAC: Secure data in the CloudsabstractMost current security solutions are based on perimeter security. However, Cloud computing breaks the organization perimeters. When data resides in the Cloud, they reside outside the organizational bounds. This leads users to a loos of control over their data and raises reasonable security concerns that slow down the adoption of Cloud computing. Is the Cloud service provider accessing the data? Is it legitimately applying the access control policy defined by the user? This paper presents a data-centric access control solution with enriched role-based expressiveness in which security is focused on protecting user data regardless the Cloud service provider that holds it. Novel identity-based and proxy re-encryption techniques are used to protect the authorization model. Data is encrypted and authorization rules are cryptographically protected to preserve user data against the service provider access or misbehavior. The authorization model provides high expressiveness with role hierarchy and resource hierarchy support. The solution takes advantage of the logic formalism provided by Semantic Web technologies, which enables advanced rule management like semantic conflict detection. A proof of concept implementation has been developed and a working prototypical deployment of the proposal has been integrated within Google services. Juan Manuel Marín Pérez, Gregorio Martínez Pérez, Antonio F. Skarmeta |
IEEE Trans. Serv. Comput. | 3 |
| 2017 | An ARM-Compliant Architecture for User Privacy in Smart Cities: SMARTIE - Quality by Design in the IoTabstractMuch has been said about the benefits that the Internet of Things (IoT) will bring to citizens’ life. Countless smart objects will be soon offering autonomous behavior in smart environments by sensing the physical world around us, collecting information about us, and taking proactive actions (many times without our consent) with the ultimate goal of improving our wellness. Without a strong guarantee on user privacy, the IoT may sound scary for many citizens. Indeed, the IoT-Architecture Reference Model (IoT-ARM) is a European effort for promoting IoT quality aspects such as security and privacy. This paper paves the way to the adoption of reference architectures by describing the application of the IoT-ARM within a European-funded project, SMARTIE. The SMARTIE architecture has been designed to empower citizens to take control of their IoT devices and privacy, while guaranteeing scalability for large deployments in smart cities. Victoria Beltran, Antonio F. Skarmeta, Pedro M. Ruiz |
Wirel. Commun. Mob. Comput. | 2 |
| 2016 | Opportunistic smart object aggregation based on clustering and event processingabstractIn the envisioned Internet of Things ecosystems, Smart objects are intended to create groups of devices in order to provide higher level services to be leveraged by citizens. However, because of the dynamic nature of such scenarios, the discovery, management and operation of such dynamic coalitions taking into account security and privacy concerns, is a challenging task that has not been properly addressed yet. In this sense, the present proposal devises a novel approach to automatically compose opportunistic aggregations of objects (bubbles) based on Complex Event Processing (CEP) and fuzzy clustering. While the former detects certain events that could give raise to discover new bubbles, the latter allows compose aggrupations of similar objects acting as candidate bubbles. Finally, the application of the proposal in an educational domain is put forward. Fernando Terroso-Saenz, José Luis Hernández-Ramos, Jorge Bernal Bernabé, Antonio F. Skarmeta |
ICC | 4 |
| 2016 | Message from the workshop co-chairsabstractIt is our pleasure to introduce the 2016 WoWMoM workshop program. This year's four WoWMoM workshops feature a wide range of topics in various emerging research areas in the field of wireless, mobile and multimedia networks. As the integral part of the main conference, the purpose of the workshops is to provide a less formal and more focused forum where novel and stimulating ideas and experiences are shared among researchers both from industry and academia, on all the topics of interest for the wireless, mobile and multimedia networking community. The number and quality of the workshops contribute to the relevance of WoWMoM as one of the reference forums for the research community working on these topics. Antonio F. Skarmeta |
WoWMoM | 1 |
| 2016 | Online route prediction based on clustering of meaningful velocity-change areas
Fernando Terroso-Saenz, Mercedes Valdés-Vela, Antonio F. Skarmeta |
Data Min. Knowl. Discov. | 3 |
| 2016 | Enabling end-to-end CoAP-based communications for the Web of Things
Miguel Castro 0003, Antonio J. Jara, Antonio F. Skarmeta |
J. Netw. Comput. Appl. | 3 |
| 2016 | Mobility and security in a real VANET deployed in a heterogeneous networksabstractAbstract This paper describes the experience and findings of deploying a vehicular scenario based on a heterogeneous network. WiMAX and Wi‐Fi have been chosen as access technologies because of their wide presence in the market and their different coverage range. Our approach has been developed, taking into account crucial aspects regarding mobility and security. These two aspects have been provided by Network Mobility and Internet Key Exchange version 2 protocols, respectively. In addition, a study about how to interoperate them has been performed, describing the benefits and drawbacks of every existing approach. Regarding handover latency, some improvements have been identified in order to reduce it to the minimum. Fast authentication methods, pre‐authentication method, and “multiple care‐of addresses” mechanism are examples of these improvements. Copyright © 2012 John Wiley & Sons, Ltd. Pedro J. Fernández, Fernando Bernal-Hidalgo, Cristian A. Nieto Guerra, Antonio F. Skarmeta |
Secur. Commun. Networks | 4 |
| 2016 | TACIoT: multidimensional trust-aware access control system for the Internet of Things
Jorge Bernal Bernabé, José Luis Hernández-Ramos, Antonio F. Skarmeta |
Soft Comput. | 3 |
| 2016 | Big data: the key to energy efficiency in smart buildings
María Victoria Moreno Cano, Luc Dufour, Antonio F. Skarmeta, Antonio J. Jara, Dominique Genoud, Bruno Ladevie, Jean Jacques Bezian |
Soft Comput. | 3 |
| 2016 | Securing Vehicular IPv6 CommunicationsabstractA common practice is applying security after a network has been designed or developed. We have the opportunity of not committing this error in vehicular networks. Apart from particular works in the literature, ETSI TC ITS has defined general security services for (vehicular) cooperative systems. However, existent efforts do not pay the needed attention to the integration of IPv6 yet. The potential of IPv6 in the field is being described within ISO TC 204, above all, but further work is needed for a proper integration of security. This work follows this direction, and a reference vehicular communication architecture considering ETSI/ISO regulations, uses Internet Protocol security (IPsec) and Internet Key Exchange version 2 (IKEv2) to secure IPv6 Network Mobility (NEMO). A key advance is also the implementation and experimental evaluation of the proposal in a challenging vertical handover scenario between 3G and 802.11p. The performance of the secured NEMO channel is widely analyzed in terms of the movement speed, bandwidth, traffic type or signal quality, and it is concluded that the addition of IPv6 security only implies a slight reduction in the overall performance, with the great advantage of providing confidentiality, integrity and authenticity to the communication path. Pedro J. Fernández, José Santa, Fernando Bernal-Hidalgo, Antonio F. Skarmeta |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2015 | Online Urban Mobility Detection Based on Velocity Features
Fernando Terroso-Saenz, Mercedes Valdés-Vela, Antonio F. Skarmeta |
DaWaK | 3 |
| 2015 | Exploiting IoT-based sensed data in smart buildings to model its energy consumptionabstractDue to the high impact that energy consumption of buildings has at global scale, it has been stated the need of achieving energy-efficient buildings to reduce CO2emissions and energy consumption at global scale. In this work we propose to model the energy consumption associated with services provided in buildings to help select the best strategies to save energy. To verify the feasibility of the proposed approach using measurements of relevant parameters affecting, we carry out some analysis in a reference building of which we have contextual data. Firstly, we provide a complete characterization of this building in term of its energy consumption and generate accurate building models able to predict its energy consumption given a concrete set of inputs. Finally, considering the generated energy usage profile of the building, we propose some concrete control actions and strategies to save energy. María Victoria Moreno Cano, Antonio F. Skarmeta, Luc Dufour, Dominique Genoud, Antonio J. Jara |
ICC | 2 |
| 2015 | Integrating an identity-based control plane with the HIMALIS network architectureabstractThe raise of Software Defined Networking (SDN) opens a wide spectrum of improvements for network architectures targeting different problems. It includes the case of those architectures designed to overcome mobility and multi-homing problems in big networks, such as the Internet, as is the case of the HIMALIS network architecture. In this paper we present an approach for HIMALIS to benefit from SDN technologies by changing the way it addresses its control operations. We propose to leverage control operations of the HIMALIS architecture through an identity-based control plane that has been designed following the principles of SDN. Thus, our approach proposes to integrate the main elements of HIMALIS with a controller, which provides enormous benefits to the architecture in general, such as the possibility to perform control operations with global knowledge of the network status and the evolution of the functions provided by the control plane without changing the implementation of the end nodes. Finally, in order to demonstrate those benefits, we have built architectonic models for both HIMALIS and our proposal, executed different simulations with them running on different mobility scenarios, and extracted the results that show clear improvement of our proposal. Pedro Martinez-Julia, Ved P. Kafle, Antonio F. Skarmeta |
NetSoft | 3 |
| 2015 | Intercloud Trust and Security Decision Support System: an Ontology-based Approach
Jorge Bernal Bernabé, Gregorio Martínez Pérez, Antonio F. Skarmeta |
J. Grid Comput. | 3 |
| 2015 | CEP-traj: An event-based solution to process trajectory data
Fernando Terroso-Saenz, Mercedes Valdés-Vela, Eric den Breejen, Patrick Hanckmann, Rob Dekker, Antonio F. Skarmeta |
Inf. Syst. | 6 |
| 2015 | SAFIR: Secure access framework for IoT-enabled services on smart buildings
José Luis Hernández-Ramos, María Victoria Moreno Cano, Jorge Bernal Bernabé, Dan García-Carrillo, Antonio F. Skarmeta |
J. Comput. Syst. Sci. | 5 |
| 2015 | Toward a Lightweight Authentication and Authorization Framework for Smart ObjectsabstractThe Internet of Things (IoT) represents the current technology revolution that is intended to transform the current environment into a more pervasive and ubiquitous world. In this emerging ecosystem, the application of standard security technologies has to cope with the inherent nature of constrained physical devices, which are seamlessly integrated into the Internet infrastructure. This work proposes a set of lightweight authentication and authorization mechanisms in order to support smart objects during their life cycle. Furthermore, such mechanisms are framed within a proposed security framework, which is compliant with the Architectural Reference Model, recently presented by the EU FP7 IoT-A project. The resulting architecture is intended to provide a holistic security approach to be leveraged in the design of novel and lightweight security protocols for IoT constrained environments. José Luis Hernández-Ramos, Marcin Piotr Pawlowski, Antonio J. Jara, Antonio F. Skarmeta, Latif Ladid |
IEEE J. Sel. Areas Commun. | 4 |
| 2014 | Design of an Event-based architecture for the intra-vehicular context perception
Fernando Terroso-Saenz, Mercedes Valdés-Vela, Antonio F. Skarmeta |
FUSION | 3 |
| 2014 | A holistic IoT-based management platform for smart environmentsabstractInternet of Things (IoT) is a vision towards Future Internet where “things” are provided with enough intelligence to communicate with each other without the human intervention. In the near future, the number of IoT-enabled nodes is expected to grow substantially, therefore the heterogeneous nature of implementations demands effective IoT deployments that ensure proper interoperability and reliability of network infrastructures. In this line, we present a holistic IoT-based platform to gather and analyze information, and propose concrete actions according to different goals in smart environments. This platform bases on the optimal integration and use of data collected from a plethora of different sources. It has been deployed in a real IoT context framed in the smart buildings field. For its validation and evaluation, a reference scenario for indoor energy efficiency and comfort has been considered, where a set of tests have been carried out to validate the building management techniques implemented to maintain user comfort while assuring a good energy balance. María Victoria Moreno Cano, José Santa, Miguel A. Zamora 0001, Antonio F. Skarmeta |
ICC | 4 |
| 2014 | Trustworthy placements: Improving quality and resilience in collaborative attack detection
Manuel Gil Pérez, Juan Tapiador, John A. Clark, Gregorio Martínez Pérez, Antonio F. Skarmeta |
Comput. Networks | 5 |
| 2014 | Semantic-aware multi-tenancy authorization system for cloud architectures
Jorge Bernal Bernabé, Juan Manuel Marín Pérez, José M. Alcaraz Calero, Félix J. García Clemente, Gregorio Martínez Pérez, Antonio F. Skarmeta |
Future Gener. Comput. Syst. | 6 |
| 2014 | Communication Protocol for Enabling Continuous Monitoring of Elderly People through Near Field CommunicationsabstractContinuous and wireless transmission of vital signs for personalized healthcare is gaining a great deal of interest from Ambient Assisted Living solutions. Personalized healthcare capabilities are limited to the patient data available, which is usually dynamic and incomplete. For that reason, regular monitoring of patients with the aim of offering a suitable analysis of patient evolution is required. Continuous monitoring requires the integration of wireless communication technologies and embedded systems into wearable and portable monitoring systems. In addition, a user interface intuitive is also required, which is easy to use and understand by the patients and caregivers. This work proposes a solution such as Near Field Communication (NFC) for personalized healthcare based on the Internet of Things. NFC is a technology integrated in smart phones that provides capabilities for identification of devices/sensors, and presents ubiquitous communication capabilities between the sensor and the device. NFC also presents challenges in terms of the performance and efficiency of data transmission, due to the constrained resources and capabilities of ubiquitous devices and the latency introduced by the NFC technology. These challenges are intrinsic to NFC since it was originally considered only for simple identification and not for continuous data transmission. In this context, this paper presents a novel monitoring system for continuous data transmission from a set of clinical devices based on NFC which has been optimized in order to make communications feasible. This novel monitoring system is also composed by a set of participatory sensing applications to support caregivers and for patients to self-monitor and self-manage their health status wirelessly. A technical evaluation based on latencies associated with use of NFC for continuous monitoring and an evaluation of usability by a group of elderly users and their caregivers, which studies the interactions between the users and the system, are demonstrated. Antonio J. Jara, Pablo Lopez, Miguel A. Zamora 0001, Benito Úbeda Miñaro, Antonio F. Skarmeta |
Interact. Comput. | 6 |
| 2014 | Building a reputation-based bootstrapping mechanism for newcomers in collaborative alert systems
Manuel Gil Pérez, Félix Gómez Mármol, Gregorio Martínez Pérez, Antonio F. Skarmeta |
J. Comput. Syst. Sci. | 4 |
| 2014 | Mobile digcovery: discovering and interacting with the world through the Internet of things
Antonio J. Jara, Pablo Lopez, Jose F. Castillo, Miguel A. Zamora 0001, Antonio F. Skarmeta |
Pers. Ubiquitous Comput. | 6 |
| 2014 | Participative marketing: extending social media marketing through the identification and interaction capabilities from the Internet of things
Antonio J. Jara, María Concepción Parra, Antonio F. Skarmeta |
Pers. Ubiquitous Comput. | 3 |
| 2014 | Drug identification and interaction checker based on IoT to minimize adverse drug reactions and improve drug compliance
Antonio J. Jara, Miguel A. Zamora 0001, Antonio F. Skarmeta |
Pers. Ubiquitous Comput. | 3 |
| 2014 | A soft computing based location-aware access control for smart buildings
José Luis Hernández-Ramos, María Victoria Moreno Cano, Antonio J. Jara, Antonio F. Skarmeta |
Soft Comput. | 4 |
| 2014 | Taxonomy of trust relationships in authorization domains for cloud computing
Juan Manuel Marín Pérez, Jorge Bernal Bernabé, José M. Alcaraz Calero, Félix J. García Clemente, Gregorio Martínez Pérez, Antonio F. Skarmeta |
J. Supercomput. | 6 |
| 2013 | IEEE AINA 2013 Keynote Talk II: The impact of internet of things in big data approach and future internetabstractSummary form only given. In this talk, recent efforts in the integration of IPv6 into the the Internet of Things (IoT), with emphasis on legacy system support and the coexistence strategy for the management of heterogeneous technologies and architectures. These integration efforts will be presented over some environments and instantiation that are devoted for support Smart Cities scenarios like efficient energy management, or intelligent transport systems and the use of the data gathering capabilities over new decision support system based on the IoT integration. Antonio F. Skarmeta |
AINA | 1 |
| 2013 | Lightweight Mobile IPv6: A mobility protocol for enabling transparent IPv6 mobility in the Internet of ThingsabstractMobility management is a desired feature for the emerging Internet of Things (IoT). Mobility aware solutions increase the connectivity and enhance adaptability to changes of the location and infrastructure. IoT is enabling a new generation of dynamic ecosystems in environments such as smart cities and hospitals. Dynamic ecosystems require ubiquitous access to Internet, seamless handover, flexible roaming policies, and an interoperable mobility protocol with existing Internet infrastructure. These features are challenges for IoT devices, which are usually constrained devices with low memory, processing, communication and energy capabilities. This work has, on the one hand, analysed suitability of Mobile IPv6 and IPSec for constrained devices, and on the other hand, analysed, designed, developed and evaluated a lightweight version of Mobile IPv6 and IPSec. The proposed solution of lightweight Mobile IPv6 with IPSec is aware of the requirements of the IoT and presents the best solution for dynamic ecosystems in terms of efficiency and security adapted to IoT-devices capabilities. This presents concerns in terms of higher overhead and memory requirements. But, it is proofed and concluded that even when higher memory is required and major overhead is presented, the integration of Mobile IPv6 and IPSec for constrained devices is feasible. Antonio J. Jara, Pablo Lopez, Miguel A. Zamora 0001, Antonio F. Skarmeta |
GLOBECOM | 5 |
| 2013 | Improving Kerberos Ticket Acquisition during Application Service Access Control
Fernando Pereñíguez-Garcia, Rafael Marín López, Antonio F. Skarmeta |
TrustBus | 3 |
| 2013 | Beyond the separation of identifier and locator: Building an identity-based overlay network architecture for the Future Internet
Pedro Martinez-Julia, Antonio F. Skarmeta |
Comput. Networks | 2 |
| 2013 | An indoor localization system based on artificial neural networks and particle filters applied to intelligent buildings
María Victoria Moreno Cano, Miguel A. Zamora 0001, José Santa, Antonio F. Skarmeta |
Neurocomputing | 4 |
| 2013 | Interconnection Framework for mHealth and Remote Monitoring Based on the Internet of ThingsabstractCommunication and information access defines the basis to reach a personalized health end-to-end framework. Personalized health capability is limited to the available data from the patient. The data is usually dynamic and incomplete. Therefore, it presents a critical issue for mining, analysis and trending. For that reason, this work presents an interconnection framework for mobile Health (mHealth) based on the Internet of Things. It makes continuous and remote vital sign monitoring feasible and introduces technological innovations for empowering health monitors and patient devices with Internet capabilities. It also allows patient monitoring and supervision by remote centers, and personal platforms such as tablets. In terms of hardware it offers a gateway and a personal clinical device used for the wireless transmission of continuous vital signs through 6LoWPAN, and patient identification through RFID. In terms of software, this interconnection framework presents a novel protocol, called YOAPY, for an efficient, secure, and scalable integration of the sensors deployed in the patient's personal environment. This paper presents the architecture and evaluates its capability to provide continuous monitoring, ubiquitous connectivity, extended device integration, reliability, and security and privacy support. The proposed interconnection framework and the proposed protocol for the sensors have been exhaustively evaluated in the framework of the AIRE project, which is focused on patients with breathing problem. This evaluates for the proposed protocol the data aggregation mechanism level, Round-Trip delay Time, impact of the distance, and the impact of the security. It has been concluded that secure continuous monitoring is feasible with the use of the proposed {YOAPY}} aggregation mechanisms and the capabilities from the proposed interconnection framework. Antonio J. Jara, Miguel A. Zamora 0001, Antonio F. Skarmeta |
IEEE J. Sel. Areas Commun. | 3 |
| 2012 | An adaptive learning fuzzy logic system for indoor localisation using Wi-Fi in Ambient Intelligent EnvironmentsabstractOne of the important requirements for Ambient Intelligent Environments (AIEs) is the ability to localise the whereabouts of the user in the AIE to address her/his needs. The outdoor localisation means (like GPS systems) cannot be used in indoor environments. The majority of non intrusive and non camera based indoor localisation systems require the installation of extra hardware such as ultra sound emitters/antennas, RFID antennas, etc. In this paper, we will propose a novel fuzzy logic based indoor localisation system which is based on the WiFi signals which are free to receive and they are available in abundance in the majority of domestic spaces. The proposed system receives WiFi signals from a big number of existing WiFi Access Points (up to 170 Access Points) with no prior knowledge of the access points locations and the environment. The proposed system is able to adapt online incrementally in a lifelong learning mode to deal with the uncertainties and changing conditions facing unknown indoor structures with a few days of calibration at zero-cost deployment with high accuracy. The proposed system was tested in simulated and real environments where the system has given high accuracy (that outperformed the existing techniques) to detect the user in the given AIE and the system was able also to adapt its behaviour to changes in the AIE or the WiFi signals. Teresa García-Valverde, Alberto García-Sola, Antonio F. Skarmeta, Juan A. Botía Blaya, Hani Hagras, James Dooley, Vic Callaghan |
FUZZ-IEEE | 3 |
| 2012 | Ubiquitous deployment configuration of indoor location servicesabstractThe development of services in Ubiquitous Computing is a hard task. Services must adapt to context information about users. One of the most important pieces of context is user location, which allows Location Based Services (LBS) to adapt their functionality regarding the users nearest features of interest. In this paper, we will propose a hybrid system to solve the problem of finding the best configuration of antennas within an intelligent environment that minimizes cost and intrusion but maximizes the accuracy of the LBS in the prediction task. The approach combines Hidden Markov Models (HMM) for user location prediction with a multiobjective genetic algorithm which is able to get suboptimal configurations of the number and position of the antennas in the intelligent building. In the experiments, our system has given configurations of antennas which provide high accuracy to predict the location (based on Radio Frequency Identification, RFID) of the user while a minimal deployment of antennas in the building is needed. Teresa García-Valverde, Alberto García-Sola, Juan A. Botía Blaya, Antonio F. Skarmeta |
IJCNN | 4 |
| 2012 | Building Network-aware Composite Services with the GEMBus FrameworkabstractThe GEMBus framework is intended to provide the necessary mechanisms to build federated composite services. Thus, it can constitute a key element in achieving cross-stratum optimization by combining network-layer events with service-layer operation knowledge. Taking advantage of the unique service perspective of the high level network operations we can use the GEMBus framework to compose the services with the network elements in order to build an enhanced and network-aware service. In this paper we give a brief description of the GEMBus architecture and discuss how to use it to build such services. We also evaluate the architecture using a proof-of-concept implementation and discuss the obtained results. Pedro Martinez-Julia, Diego R. López, Antonio F. Skarmeta |
ISPA | 3 |
| 2012 | Knowledge Acquisition and Management Architecture for Mobile and Personal Health Environments Based on the Internet of ThingsabstractPersonalized health capability is limited to the available data from the patient, which is usually dynamic and incomplete. Therefore, it is presenting a critical issue for knowledge mining, analysis and trending. For that reason, this work presents a knowledge acquisition and management platform based on the Internet of Things (IoT). IoT is presenting the capability to connect any object to Internet. These Smart Objects are providing an enormous quantity of data. This work is focused on the personal and mobile health areas, where the integration of clinical devices in the patient's environment, this will enable new services with capabilities to predict health anomalies in real time, send alerts, reminders and offer an enriched feedback to the patient. This feedback will help and motivate to the patients with the treatments adherence and compliance and to follow a healthy lifestyle. In order to reach these services and feedback capabilities, it is required a full integration of the clinical devices and efficient processing of the collected data. The presented knowledge acquisition and management architecture is composed of, on the one hand, a gateway and a personal clinical device used for the integration of clinical devices, wireless transmission of continuous vital signs through 6LoWPAN, and patient identification through RFID. On the other hand, it is complemented with a data model and pre-processing module called YOAPY, which analyses the data from the sensors at the personal devices level. This offers an enriched data to the knowledge-based systems, and this also aggregate the data acquired in order to improve the performance of the communications to the constrains from the Smart Objects in aspects such as low bandwidth, frame size and power consumption. This architecture is being evaluated with an extended set of sensors required for patients with breathing problem in the framework of the AIRE project, it has evaluated the capabilities to provide knowledge acquisition and management from continuous monitored vital signs, the capabilities for diagnosis and detection of anomalies, and finally the support for security and privacy. Antonio J. Jara, Miguel A. Zamora 0001, Antonio F. Skarmeta |
TrustCom | 3 |
| 2012 | Responsive on-line gateway load-balancing for wireless mesh networks
Juan Jose Galvez, Pedro M. Ruiz, Antonio F. Skarmeta |
Ad Hoc Networks | 3 |
| 2012 | A Non-monotonic Expressiveness Extension on the Semantic Web Rule Language
José M. Alcaraz Calero, Andrés Muñoz 0001, Gregorio Martínez Pérez, Juan A. Botía Blaya, Antonio F. Skarmeta |
J. Web Eng. | 5 |
| 2012 | A Cooperative Approach to Traffic Congestion Detection With Complex Event Processing and VANETabstractCurrently, distributed traffic information systems have come up as one of the most important approaches for detecting traffic flow problems on a road. For that purpose, they usually make use of the location information that vehicles share among them through periodical messages that are transmitted across a vehicular ad hoc network (VANET). This paper puts forward an event-driven architecture (EDA) as a novel mechanism to get insight into VANET messages to detect different levels of traffic jams; furthermore, it also takes into account environmental data that come from external data sources, such as weather conditions. The proposed EDA has been developed through the complex-event-processing technology. Simulation tests show that the proposed mechanism can detect traffic congestions, which involve different numbers of lanes and lengths with short delay. Fernando Terroso-Saenz, Mercedes Valdés-Vela, Cristina Sotomayor Martínez, Rafael Toledo-Moreo, Antonio F. Skarmeta |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2012 | Automatic Design of an Indoor User Location Infrastructure Using a Memetic Multiobjective ApproachabstractServices in ambient intelligence (AmI) environments should adapt to contextual information (context-aware) of users and environment in a nonintrusive and natural way. Location-aware, i.e., the user location, is one of the most important pieces in context-aware. According to this premise, a location-based service (LBS) using radio frequency identification technology is presented. The service is based on hidden Markov models for location within an intelligent building. This problem leads to a multiobjective optimization problem, in which, the best configuration of antennas that minimizes the set of antennas but maximizes the precision of the prediction should be found. Specifically, this study presents a memetic approach for multiobjective improvement of LBS in AmI environments. The memetic algorithm provides, in this problem, the exploitation of domain knowledge and the combination of metaheuristics. Experimental results show that the approach obtains a configuration of antennas which optimally configures the number and position of the antennas while keeping a high quality of the precision of the location prediction. Teresa García-Valverde, Alberto García-Sola, Juan A. Botía Blaya, Antonio F. Skarmeta |
IEEE Trans. Syst. Man Cybern. Part C | 4 |
| 2011 | Shifting Primes: Extension of Pseudo-Mersenne Primes to Optimize ECC for MSP430-Based Future Internet of Things Devices
Leandro Marín, Antonio J. Jara, Antonio F. Skarmeta |
ARES | 3 |
| 2011 | Providing security using IKEv2 in a vehicular network based on WiMAX technologyabstractThis paper describes how mobility and security services are provided together in a vehicular scenario based on WiMAX technology. MIPv6 and IKEv2 protocols have been chosen for this purpose, in particular the “Mip6d” and “OpenIKEv2” implementations respectively. But this cooperation is performed in a different way as usual, because they also implement an access control mechanism for visited networks. This mechanism is based on the EAP protocol, that let us change the authentication method and test their different behaviours in a mobility scenario. “OpenIKEv2” has been developed in the University of Murcia. For this reason, all changes preformed in order to interoperate with “Mip6d” have been performed in our IKEv2 implementation. Pedro J. Fernández, Antonio F. Skarmeta |
CCNC | 2 |
| 2011 | TCP Flow-Aware Channel Re-Assignment in Multi-Radio Multi-Channel Wireless Mesh NetworksabstractWe consider the traffic-aware channel assignment problem in a multi-radio Wireless Mesh Network that involves assigning channels to radio interfaces to optimize the performance of a set of TCP flows (flow throughput and fairness). The resulting optimization problem is NP-hard. At the TCP flow level, rapid traffic fluctuations are expected, imposing the need for frequent channel re-assignment to adapt to current traffic conditions. We develop a centralized greedy channel assignment algorithm suited for this task that can support frequent channel re-assignment by two properties: (i) low computational complexity, permitting it to quickly calculate a solution, and (ii) by taking into account the previous channel assignment to generate a new one with minimum variation. Focusing on the gateway access scenario, we observe an important benefit to optimizing the performance of TCP flows with the proposed algorithm. Juan Jose Galvez, Pedro M. Ruiz, Antonio F. Skarmeta |
MASS | 3 |
| 2011 | Towards an Authorization System for Cloud Infrastructure Providers
Jorge Bernal Bernabé, Juan Manuel Marín Pérez, José M. Alcaraz Calero, Félix J. García Clemente, Gregorio Martínez Pérez, Antonio F. Skarmeta |
SECRYPT | 6 |
| 2011 | Multipath routing with spatial separation in wireless multi-hop networks without location information
Juan Jose Galvez, Pedro M. Ruiz, Antonio F. Skarmeta |
Comput. Networks | 3 |
| 2011 | PrivaKERB: A user privacy framework for Kerberos
Fernando Pereñíguez-Garcia, Rafael Marín López, Georgios Kambourakis, Stefanos Gritzalis, Antonio F. Skarmeta |
Comput. Secur. | 5 |
| 2011 | Using cognitive agents in social simulations
Alberto Caballero, Juan A. Botía Blaya, Antonio F. Skarmeta |
Eng. Appl. Artif. Intell. | 3 |
| 2011 | Formal description of the SWIFT identity management framework
Alejandro Pérez-Méndez, Gabriel López Millán, Óscar Cánovas Reverte, Antonio F. Skarmeta |
Future Gener. Comput. Syst. | 4 |
| 2011 | Semantic-based authorization architecture for Grid
Juan Manuel Marín Pérez, Jorge Bernal Bernabé, José M. Alcaraz Calero, Félix J. García Clemente, Gregorio Martínez Pérez, Antonio F. Skarmeta |
Future Gener. Comput. Syst. | 6 |
| 2011 | An internet of things-based personal device for diabetes therapy management in ambient assisted living (AAL)
Antonio J. Jara, Miguel A. Zamora 0001, Antonio F. Skarmeta |
Pers. Ubiquitous Comput. | 3 |
| 2011 | An advanced certificate validation service and architecture based on XKMSabstractAbstract The appearance of some laws that make the electronic signature (e‐signature) legally equivalent to the handwritten signature (under some circumstances) has favoured its use in different fields, such as e‐commerce and e‐government. In these fields, the e‐signatures associated to some documents have to remain valid over long periods of time. For these kinds of e‐signatures, Advanced Electronic Signature (AdES) forms have appeared. These forms specify the information to include along with the e‐signature so that it remains valid for a long time after its creation. Basically, this information comprises signers' certificates, a set of certificates up to a trust anchor, certificate validation responses, etc. These data can be gathered by using different Public Key Infrastructure‐compliant protocols. However, the support of different protocols is complex for clients. XML Key Management Specification (XKMS) appeared with the aim of simplifying the certificate management, but it only supports a simple validation mechanism that does not provide the information needed for long‐term validation. As a solution to this problem, we have extended XKMS by defining an advanced certificate validation service to support the obtaining of validation data needed for different scenarios, such as the building of AdES forms or validation data registries. This extension also defines the different components needed to support this kind of a service. Furthermore, the defined service has been implemented and incorporated into an e‐government infrastructure. Copyright © 2010 John Wiley & Sons, Ltd. Antonio Ruiz-Martínez, Daniel Sánchez-Martínez, C. Inmaculada Marín-López, Manuel Gil Pérez, Antonio F. Skarmeta |
Softw. Pract. Exp. | 5 |
| 2010 | Deployment of a Secure Wireless Infrastructure Oriented to Vehicular NetworksabstractThis paper describes a testbed scenario deployed over a WiMAX1 [11] based wireless access network using IKEv22 [3] protocol for authentication purposes. OpenIKEv2[8] is the chosen implementation of IKEv2, that provides security to wireless communications, but also allows us to use the EAP3 [6] authentication protocol that lets us reach the main purpose of this testbed: to test the behaviour of recent designed authentication methods in a mobility scenario of vertical and horizontal handovers. These researches are aimed at vehicular networks[1], where mobility is the crucial aspect to be taken into account. Pedro J. Fernández, Cristian A. Nieto Guerra, Antonio F. Skarmeta |
AINA | 3 |
| 2010 | An Architecture Based on Internet of Things to Support Mobility and Security in Medical EnvironmentsabstractRecently the problem of providing effective and appropriate healthcare to elderly and disable people is an important field in relative to the aging of population problems. The objective of information and communication technologies (ICT) is to focus on the new technologies the medical environments, so that it can provide management to accelerate and improve the clinical process. Our contribution is to introduce an approach based on Internet of things (IoT) in medical environments to achieve a global connectivity with the patient, sensors and everything around it. The main goal of this globality feature is to provide a context awareness to make the patient's life easier and the clinical process more effective. To achieve this approach, firstly has been developed an architecture which has been designed to offer great potential and flexibility of communications, monitoring and control. This architecture includes several advanced communication technologies; among them are 6LoWPAN and RFID/NFC, which are the basis of the IoT. Moreover the research deal with the problems related to the mobility and security that happens when IoT is applied in medical environments. The mobility issue requires developing a protocol over 6LoWPAN network to be carried out in sensor networks with high specification related with low power consumption and capacity. While in the RFID/NFC technologies need to support secure communications, our proposal is to introduce a set of security techniques and cryptographic SIM card to authenticate, encrypt and sign the communications with medical devices. The preliminary results showed a reduction of time in the handover process with the protocol for mobility defined, by omitting the stages of addressing and simplifying the MIPv6 protocol. In addition to increase the security in the communications carried out by NFC devices enhanced with the inclusion of cryptographic SIM card. Antonio J. Jara, Miguel A. Zamora 0001, Antonio F. Skarmeta |
CCNC | 3 |
| 2010 | Semantic description of multimedia contents for the optimization of the advertising impact on TV program gridsabstractThe problem of advertising impact optimization in program grids consists to find a fully design of advertising contents in the program grid maximizing the satisfaction of advertisers and viewers. In this work, the problem of advertising impact optimization of program grids is approached. Standards for semantic description of multimedia contents are used for expressing contents in a television grid and the optimization process is based on semantic similarity measures between the descriptions of the TV contents. The overall optimization of the advertising impact is guaranteed using an evolutive approach. Teresa García-Valverde, Alberto Caballero, Juan A. Botía Blaya, Antonio F. Skarmeta |
IJCNN | 4 |
| 2010 | A service oriented architecture for basic autonomic network managementabstractIn this paper we show a service-oriented architecture for managing network systems and services without human intervention, ensuring compliance with rules and policies set by administrators. Furthermore, we show the evaluation results of a proof-of-concept implementation of the architecture running in a test environment where it has to manage the links that connects the main router of an organization to the backbone of its provider, following simple policies that fixes saturation situations and improve network availability. Pedro Martinez-Julia, Antonio Marín Cerezuela, Antonio F. Skarmeta |
ISCC | 3 |
| 2010 | Modeling and analysis of the packet-level loss process in wireless channelsabstractLosses in real-time multimedia communications have a big impact on the quality experienced by users. In wireless networks, some application level mechanism of Forward Error Correction (FEC) is useful to protect the transmission. In order to adjust the configuration of FEC, a model of the packet-level loss process is required. This work proposes a methodology for the analysis of the loss process of packet-oriented communications using semi-Markov models, hierarchical Markov models, and Monte Carlo simulation. The methodology is applied to the analysis of HSDPA channels, and the models obtained are used to verify the performance of FEC implemented with Reed-Solomon codes. Eduardo Martínez-Gracía, Jordi Ortiz 0001, Antonio F. Skarmeta |
MSWiM | 3 |
| 2010 | An IMS Based Vehicular Service PlatformabstractThis paper presents an innovative solution for the deployment and management of vehicular services based on IP Multimedia Subsystem (IMS). We justify our proposal by analysing the advantages of IMS applied in vehicular scenarios. For this purpose we have designed and experimentally developed a platform that consists of an IMS Core, advanced enablers and two IMS Clients. We demonstrate the potential of this solution by evaluating the performance of two vehicular services, explicitly tested in real conditions using our platform. We provide qualitative analysis and quantitative results, including performance metrics of the services using our solution through different access technologies. Ivan Lequerica Roca, Antonio Jesus Ruiz Ruiz, Andres Samuel Garcia Ruiz, Antonio F. Skarmeta |
VTC Fall | 4 |
| 2010 | A feedback-based adaptive online algorithm for Multi-Gateway load-balancing in wireless mesh networksabstractWe propose an adaptive online load-balancing protocol for Multi-Gateway Wireless Mesh Networks (WMNs) which, based on the current network conditions, balances load between gateways. Our protocol (GWLB) achieves two goals: (i) alleviating congestion in affected domains and (ii) balancing load to improve flow fairness across domains. As a result of applying GWLB the throughput and fairness of flows improves. The proposed scheme effectively takes into account the elastic nature of TCP traffic, and intra-flow and inter-flow interference when switching flows between domains. Through simulations, we analyze performance and compare with a number of proposed strategies, showing that GWLB outperforms them. In particular, we have observed average flow throughput gains of 104% over the nearest gateway strategy. Juan Jose Galvez, Pedro M. Ruiz, Antonio F. Skarmeta |
WOWMOM | 3 |
| 2010 | Secure three-party key distribution protocol for fast network access in EAP-based wireless networks
Rafael Marín López, Fernando Pereñíguez-Garcia, Fernando Bernal-Hidalgo, Antonio F. Skarmeta |
Comput. Networks | 4 |
| 2010 | Privacy-enhanced fast re-authentication for EAP-based next generation network
Fernando Pereñíguez-Garcia, Georgios Kambourakis, Rafael Marín López, Stefanos Gritzalis, Antonio F. Skarmeta |
Comput. Commun. | 5 |
| 2010 | PKI-based trust management in inter-domain scenarios
Gabriel López Millán, Manuel Gil Pérez, Gregorio Martínez Pérez, Antonio F. Skarmeta |
Comput. Secur. | 4 |
| 2010 | Detection of semantic conflicts in ontology and rule-based information systems
José M. Alcaraz Calero, Juan Manuel Marín Pérez, Jorge Bernal Bernabé, Félix J. García Clemente, Gregorio Martínez Pérez, Antonio F. Skarmeta |
Data Knowl. Eng. | 6 |
| 2010 | Towards an authorisation model for distributed systems based on the Semantic WebabstractAuthorisation is a crucial process in current information systems. Nowadays, many of the current authorisation systems do not provide methods to describe the semantics of the underlying information model which they are protecting. This fact can lead to mismatch problems between the semantics of the authorisation model and the semantics of the underlying data and resources being protected. In order to solve this problem, this paper describes an authorisation model based on Semantic Web technologies. This authorisation model uses the common information model (CIM) to represent the underlying information model. For this reason, a new conversion process of CIM into the Semantic Web languages has been proposed converting properly the semantics available in the CIM model. This representation provides a suitable information model based on a well-known logic formalism for implementing the authorisation model and a formal language for describing concisely the semantic of the information models being protected. The formal authorisation model supports role-based access control (RBAC), hierarchical RBAC, conditional RBAC and object hierarchies, among other features. Moreover, this paper describes an authorisation architecture for distributed systems taking into account aspects such as privacy among parties and trust management. Finally, some implementation aspects of this system have also been described. José M. Alcaraz Calero, Gregorio Martínez Pérez, Antonio F. Skarmeta |
IET Inf. Secur. | 3 |
| 2010 | A Kerberized Architecture for Fast Re-authentication in Heterogeneous Wireless Networks
Rafael Marín López, Fernando Pereñíguez-Garcia, Yoshihiro Ohba, Fernando Bernal-Hidalgo, Antonio F. Skarmeta |
Mob. Networks Appl. | 5 |
| 2009 | A Cluster-Based Framework for Spontaneous Collaboration without InfrastructureabstractIn this paper, the authors describe the development of a framework for collaborative spontaneous networks. A spontaneous network is created when a group of users comes together and uses wireless computing devices in order to carry- out a collaborative activity. The target of this framework is to provide efficient communications for groups of users in such a scarce resource environment. The architecture proposed in this work is based on three main design decisions: multicast technology is used to reduce the traffic, a clustering scheme has been proposed to minimize the network overhead and a cross-layer adaptation between our framework and the multicast routing protocol allows our architecture to take advantage of the network topology information collected by the routing protocols at the network layer. The experiments performed using a real testbed show that the framework provides rapid response times in static and dynamic environments. Juan A. Martínez 0001, Francisco J. Galera, Miguel A. Sanchis, Antonio F. Skarmeta |
CCNC | 4 |
| 2009 | Trusted Network Access Control in the Eduroam FederationabstractIn order to ensure end user devices are healthy enough to gain access to the network, providers are making use of advanced network access control solutions, which propose an evaluation of configuration information (posture) about the device itself before providing access to the network. However, current solutions are focused on intra-domain scenarios, where end users and network belong to the same organization. This work proposes an architecture to provide this trusted network access control in other emerging scenarios: network roaming federations, like eduroam, where the accessed network provider is not where the end user belongs to. The paper describes how authentication and authorization mechanisms for these scenarios can be integrated to provide trusted network access control. Fernando Bernal-Hidalgo, Manuel Sánchez, Gabriel López Millán, Antonio F. Skarmeta, Óscar Cánovas Reverte |
NSS | 4 |
| 2009 | Achieving spatial disjointness in multipath routing without location informationabstractWe develop an on-demand multipath routing protocol for multi-hop wireless networks (MWNs), capable of finding spatially disjoint paths without the need of location information. Multipath routing can enable various applications and enhancements in MWNs, such as load balancing, bandwidth aggregation, reliability and secure communications. The use of spatially disjoint routes is important to effectively achieve these gains, due to the non-interfering nature of the paths. Most of the proposed multipath protocols for MWNs focus on reliability and do not find spatially disjoint paths. We propose a new on-demand protocol called Spatially Disjoint Multipath Routing (SDMR), capable of finding multiple paths in one route discovery, measuring the distance between them and choosing paths with most separation. Simulations demonstrate the effectiveness of the protocol in finding spatially separate routes. Juan Jose Galvez, Pedro M. Ruiz, Antonio F. Skarmeta |
WCNC | 3 |
| 2009 | Performance analysis of a cross-layer SSO mechanism for a roaming infrastructure
Manuel Sánchez, Gabriel López Millán, Óscar Cánovas Reverte, Antonio F. Skarmeta |
J. Netw. Comput. Appl. | 4 |
| 2009 | Towards the homogeneous access and use of PKI solutions: Design and implementation of a WS-XKMS server
José M. Alcaraz Calero, Gabriel López Millán, Gregorio Martínez Pérez, Antonio F. Skarmeta |
J. Syst. Archit. | 4 |
| 2008 | Towards a Generic Payment Framework for Internet Media-on-Demand Services Based on RTSPabstractBroadband connections to Internet make possible offering new services such as Multimedia on Demand (MoD). To the date, content providers and distributors resort to use specifically developed software to deal with payments. The problem is that those customized solutions are limited to either a specific payment protocol, brand and payment service provider, or a determinate architecture or a concrete business model. Moreover, at the moment, there is not any general framework to make payments as a part of the MoD service. In this paper we propose a new generic payment framework for Internet MoD Services based on RTSP which, being a payment-independent protocol, solves interoperability problems and links payment information with content requests. Our framework extends both SDP and RTSP to facilitate the access to pay-per-view MoD. It supports an offer/answer model that allows the choice of he quality of the streams and the payment method. Furthermore, it is extensible and not only supports payments but also more complex business models. Thus, we facilitate the incorporation of new payment methods and business models in vendor’s software. Antonio Ruiz-Martínez, Juan A. Sánchez-Laguna, Antonio F. Skarmeta |
AINA | 3 |
| 2008 | Adaptability of the TRSIM Model to Some Changes in Agents Behaviour
Alberto Caballero, Juan A. Botía Blaya, Antonio F. Skarmeta |
ATC | 3 |
| 2008 | LightPS: Lightweight Content-Based Publish/Subscribe for Peer-to-Peer SystemsabstractIn this paper we present a technique for content-based publish/subscribe (pub/sub) systems that works without (distributed) explicit multicast group management. This technique, so-called LightPS, employs a rendezvous-based approach and, thus, maps subscription and event information into the peer-to-peer node Id keyspace. On the contrary to what could be expected, LightPS suits for high-dimensional pub/sub domains, requiring very low memory capacity and time to run subscription and event notification processes. We present its good performance through a formal theoretical analysis. Jordi Pujol Ahulló, Pedro García López, Antonio F. Skarmeta |
CISIS | 3 |
| 2008 | Secure Forwarding in DHTs - Is Redundancy the Key to Robustness?
Marc Sánchez Artigas, Pedro García López, Antonio F. Skarmeta |
Euro-Par | 3 |
| 2008 | ACVS: An Advanced Certificate Validation Service in Service-Oriented ArchitecturesabstractProposals such as CAdES, XAdES and LTANS have made the need of remaining evidences over long periods of time clear. Between these evidences we have electronic signatures, certificates, requests and responses of validation mechanisms and so on. In order to gather these evidences, clients have to support several PKI-compliant protocols. Then, with the aim of simplifying this task XKMS appeared. However, XKMS only provides a simple validation mechanism that does not allow clients to specify some useful aspects needed for purposes of long term validation, such as trust anchors, information to store, responses to obtain, and so on. Therefore, in order to solve this problem, we present both an extension to XKMS and the different modules that are involved in this new specification. Antonio Ruiz-Martínez, Daniel Sánchez-Martínez, C. Inmaculada Marín-López, Manuel Gil Pérez, Antonio F. Skarmeta |
ICIW | 5 |
| 2008 | Bypass: Providing secure DHT routing through bypassing malicious peersabstractMuch research in the last years has been devoted to the development of efficient Distributed Hash Tables (DHTs). While many works have studied DHT systems, few have examined their security issues. For example, Chord and other DHT implementations rely on the cooperation of individual peers to route requests. Consequently, any malicious node can drop and misroute messages at will, censoring the access of honest peers to content. In this paper, we introduce Bypass, a novel DHT routing protocol designed to mitigate routing attacks. A key distinguishing feature of Bypass from other implementations is a feedback-based filtering protocol that allows peers to avoid adversarial nodes when routing to the correct holders of a key. Our experimental results show that in principle Bypass can achieve a lookup success rate close to theoretical bounds. Marc Sánchez Artigas, Pedro García López, Antonio F. Skarmeta |
ISCC | 3 |
| 2008 | Supporting geographical queries onto DHTsabstractLocation-based services (LBS) are currently receiving world-wide attention as a consequence of the massive usage of mobile devices, but such location services require scalable distributed infrastructures in order to resolve spatial queries efficiently. We propose a novel methodology to enable geographical query support to distributed hash tables (DHTs). The contributions of our methodology are the followings: a) our technique is DHT-generic, b) it makes an effective clusterization of nodes and information into geographical areas, c) providing data locality without sacrificing routing and data load balancing, d) it is able to answer classical spatial range queries, as well as e) a new kind of queries we call geocast, all of them in a distributed, scalable way. We demonstrate the feasibility of our approach through representative simulations. Jordi Pujol Ahulló, Pedro García López, Marc Sánchez Artigas, Antonio F. Skarmeta |
LCN | 4 |
| 2008 | Spatially Disjoint Multipath Routing protocol without location informationabstractMultipath routing permits the discovery and use of multiple paths between a source and a destination. We develop a distributed on-demand multipath routing protocol for MANETs capable of finding spatially disjoint paths without location information. The use of spatially disjoint routes in multipath routing is important due to the non-interfering nature of the paths. This enables applications such as load-balancing, bandwidth aggregation, secure communications and multimedia transmission. Most of the proposed multipath protocols for MANETs focus on reliability and are not adequate for these types of applications because of route coupling between alternate paths. We propose Spatially Disjoint Multipath Routing (SDMR) protocol, capable of finding multiple paths in one route discovery, measuring the distance between them and choosing paths with most separation. SDMR is evaluated through simulation. Juan Jose Galvez, Pedro M. Ruiz, Antonio F. Skarmeta |
LCN | 3 |
| 2008 | On the Feasibility of Dynamic Superpeer Ratio MaintenanceabstractThe notion of "superpeer" has been shown to be very effective to increase the scalability of P2P applications. For superpeer systems to work, it is critical to preserve the optimal ratio between the number of superpeers and normal peers participating in the overlay. This requires that peers change dynamically their role (i.e., from su-perpeer to normal peer and vice versa) in the presence of node arrivals and departures, a problem that is hard to solve if no peer has global knowledge of the network. In this article, we first investigate the feasibility of superpeer ratio maintenance when each peer can decide to be a superpeer independently of each other. We then show how this problem can be treated as an optimization problem, and we propose a distributed algorithm, based on particle swarm optimization (PSO), to solve it. Our simulation results prove the viability of a PSO-based approach for this problem. Marc Sánchez Artigas, Pedro García López, Antonio F. Skarmeta |
Peer-to-Peer Computing | 3 |
| 2008 | Building and Managing Policy-Based Secure Overlay NetworksabstractOverlay networks represent a flexible approach for distributed services deployed across different administrative domains to group according to a given criteria without modification of the underlying network. Two key features for such overlays to be effective and useful are security and dynamicity. This paper introduces a proposal for the elements (i.e., architecture, protocols, and formal information models) needed to dynamically deploy secure overlay networks in certain multi-domain scenarios. Gregorio Martínez Pérez, Félix J. García Clemente, Antonio F. Skarmeta |
PDP | 3 |
| 2008 | Managing the lifecycle of XACML delegation policies in federated environments
Manuel Sánchez, Óscar Cánovas Reverte, Gabriel López Millán, Antonio F. Skarmeta |
SEC | 4 |
| 2008 | TR-clustering: Alleviating the impact of false clustering on P2P overlay networks
Marc Sánchez Artigas, Pedro García López, Antonio F. Skarmeta, José Santa |
Comput. Networks | 3 |
| 2008 | Architecture and evaluation of a unified V2V and V2I communication system based on cellular networks
José Santa, Antonio F. Skarmeta, Marc Sánchez Artigas |
Comput. Commun. | 2 |
| 2008 | Towards interoperability: a wrapper model for integrating remote laboratories in a collaborative discovery learning environmentabstractAbstract Collaborative theories in learning are playing a vital role in the way learners interact with each other. More concretely, in collaborative learning the communication between learners is considered the most important element in their knowledge building. Regarding experimental subjects, the discovery learning discipline has emerged, in which students construct their knowledge through experimentation. In this sense, platforms such as Pedagogica, Web‐based inquiry science environment, SimQuest, Interactive Physics, Working Models and Co‐Lab provide support of this kind of learning. Regarding experimentation, one of the resources that may enrich the learning of students is the use of remote laboratories. However, the majority of these learning systems lack interfaces and models to provide interoperability with remote laboratories. Regarding interoperability issues, service‐oriented architecture (SOA) is the most well‐known paradigm for this issue. In this paper, we describe a wrapper model based on SOA for interoperability between Co‐Lab and existing remote laboratories. Moreover, we explain how we have integrated the existing remote laboratories in Co‐Lab using this model and we show the general pattern for including external experiments. Copyright © 2008 John Wiley & Sons, Ltd. M. Antonia Martínez-Carreras, Antonio F. Skarmeta |
Softw. Pract. Exp. | 2 |
| 2007 | SIP extensions to support (micro)paymentsabstractSIP is a protocol designed to create and manage multimedia sessions such as telephone calls over the Internet, distributed conferences, or, in general, every kind of communication between two or more peers. The introduction of payment in SIP is an interesting idea in order to charge for this media services. This payment services have been proposed in several scenarios such as charging for accessing to services, microbilling or as a solution to SPAM in VoIP systems. In this context, there is a proposal for making payments on SIP that is based on SAML. However, this proposal is not good enough to make low payments or micropayments because involves that the payment service provider participates in every payment. This implies that the transaction costs are high and therefore it is not suitable for this kind of payments. Additionally, this proposal only deals with the scenario in which the payment covers the whole session. Finally, this proposal does not take into account that streams with different quality could be used in the session, and therefore the amount to pay could be different. In response to these limitations we propose a new extension for supporting payments on SIP which, being payment-independent protocol, solves interoperability problems and links payment information to requests. For this purpose, we have extended both SDP and SIP to facilitate the access to SIP services based on payment. The extension supports an offer/answer model that allows the choice of the quality of the streams as well as the payment method to use. Furthermore, it is extensible and not only supports payment but also more complex business models such as loyalty models, credentials and subscriptions. Thus, we facilitate the incorporation of new payment methods and business models in the vendor's software. This paper describes this extension as well as some scenarios where it can be applied. Antonio Ruiz-Martínez, Juan A. Sánchez-Laguna, Antonio F. Skarmeta |
AINA | 3 |
| 2007 | A Payment Framework for Internet Media-on-Demand Services based on RTSP
Antonio Ruiz-Martínez, Juan A. Sánchez-Laguna, Antonio F. Skarmeta |
CCNC | 3 |
| 2007 | A Multiplatform OSGi Based Architecture for Developing Road Vehicle ServicesabstractAbstract — Nowadays, the growing demand on the implantation of onboard services for road vehicles encourages its development as a part of the current and future vehicles. In this sense, the implementation of new facilities cannot lead to an increase of hardware devices in the driver compartment, because space limitations and the need of an easy non-distracting interface with the user must be considered. For these reasons, it is advisable to have a service architecture suitable for further developments, considering the requirements of extensibility. New services should be created using modules shareable with the rest of applications in the vehicle. For this purpose, this work shows an extensible architecture useful in the software development of road services for vehicles. The solution presented is based on the division of services in different levels of abstraction, according to the underlying hardware. This structure is placed over a general purpose computer. A wide range of sensors has been installed in our test vehicle, allowing the implementation of several context aware services, and proving the feasibility of the proposed solution. A set of examples of location based services (LBS), multimedia services, and advanced driver assistance systems (ADAS) has been developed as described in this paper. José Santa, Benito Úbeda Miñaro, Antonio F. Skarmeta |
CCNC | 3 |
| 2007 | Designing an interoperable infrastructure for synchronous collaborationabstractThe use of synchronous groupware offers to collaborators similar advantages than face to face meeting. Regarding the design of systems of this kind, the most accurate middleware is the use of messages oriented middleware (MOM). One of the current issues which affects also to collaborative environments is interoperability. More concretely, the use of web service standards has gained its prominence in this area. The use of WS-Eventing and WS-Notification seem to be the most accurate specification for the building of interoperable MOM systems. The aim of this paper is to offer the design and implementation of an interoperable synchronous architecture for the delivery of messages between applications developed in different programming languages devoted to text-based tools, such as instant messaging and chat. M. Antonia Martínez-Carreras, Alejandro Piqueras, Miguel A. Hernández, Antonio F. Skarmeta |
CollaborateCom | 4 |
| 2007 | A Proposal for the Definition of Operational Plans to Provide Dependability and Security
Daniel J. Martínez-Manzano, Manuel Gil Pérez, Gabriel López Millán, Antonio F. Skarmeta |
CRITIS | 4 |
| 2007 | Extending the Common Services of eduGAIN with a Credential Conversion Service
Gabriel López Millán, Óscar Cánovas Reverte, Diego R. López, Antonio F. Skarmeta |
ESORICS | 4 |
| 2007 | Secure Protocol for Fast Authentication in EAP-Based Wireless Networks
Rafael Marín López, Santiago Zapata Hernandez, Antonio F. Skarmeta |
ICCSA (2) | 3 |
| 2007 | A Context-Aware Solution for Personalized En-route Information Through a P2P Agent-Based Architecture
José Santa, Andrés Muñoz 0001, Antonio F. Skarmeta |
ICCSA (3) | 3 |
| 2007 | Designing a Generic Collaborative Working EnvironmentabstractGroupware provides an essential support for the maintenance of Knowledge Management in many organizations. Accordingly, the use of groupware systems has become widespread. However, still some problems regarding the way in which business process are implemented exist, because they require the communication between several of these groupware systems to fulfill all required objectives in the organization. For that reason, interoperability issues have taken a vital role in the business sector. In this area, one of the leading technologies is the Web Service standard.. In this paper we describe the design of a Generic Collaborative Working Environment to provide the basis for allowing interoperability with several groupware systems. We also reflect how Web Services technologies are used in the design of this environment. M. Antonia Martínez-Carreras, Antonio Ruiz-Martínez, Antonio F. Skarmeta, Wolfgang Prinz |
ICWS | 3 |
| 2007 | SQS: Similarity Query Scheme for Peer-to-Peer DatabasesabstractSimilarity search is a hot research topic on peer-to-peer systems. In this paper we present SQS, a similarity query scheme for peer-to-peer databases. In this work we provide a novel linearization mechanism that enables structured queries without the burden of a global information maintenance scheme. The system offers exact match and range searches to multidimensional data. SQS employs Cyclone, a hierarchical overlay that is able to build disjoint clusters in terms of network latency and enables data search load balancing by caching per cluster scheme. Finally, we show the good properties of SQS through representative simulation results. Jordi Pujol Ahulló, Pedro García López, Marc Sánchez Artigas, Antonio F. Skarmeta |
ISCC | 4 |
| 2007 | Pre-Authentication Based Enhancement for Access Control in Hybrid MANETsabstractWe analyze the problem of reducing packet losses due to the authentication time which is required when an ad hoc node switches across different gateways in a mobile ad hoc network connected to Internet (hybrid MANET). Our goal is to provide a mechanism allowing Internet gateways to accept only authorized traffic without decreasing the overall performance of the system. We propose a solution based on pre-authentication which uses utility-based optimal control to choose with which gateways to pre-authenticate over time. Our simulation results show that the proposed scheme outperforms traditional schemes across a variety of network scenarios and configurations. Rafael Marín López, Pedro M. Ruiz, Francisco J. Ros, Juan A. Martínez 0001, Antonio F. Skarmeta |
ISCC | 5 |
| 2007 | A Comparative Study of Hierarchical DHT SystemsabstractMuch research in the last few years has been devoted to development of efficient structured peer-to-peer (P2P) overlay networks, which offer distributed hash table (DHT) functionality. Most of these systems have been devised as flat, non-hierarchical structures, in contrast to the most scalable distributed systems of the past. To cope with this, a significant number of hierarchical DHT designs have been proposed in the literature. Unfortunately, no design is "universally" better. Actually, what is lacking is an analytic framework to identify the good hierarchical design for a given workload. In this paper, we provide such a framework, and we use it to compare the two main hierarchical DHT designs: The homogenous design, in which all nodes act equal roles, against the superpeer design, in which a small subset of peers (i.e., the most powerful and stable), behave as proxies, interconnecting clusters with highly dynamic membership. Our analysis reveals that, on the contrary to what was initially expected, the costs incurred by hierarchical superpeer design are not necessarily minimized. Marc Sánchez Artigas, Pedro García López, Antonio F. Skarmeta |
LCN | 3 |
| 2007 | Network-Layer Assisted Mechanism to Optimize Authentication Delay during Handoff in 802.11 NetworksabstractSecured and seamless mobility across heterogeneous access networks needs optimization at all layers. Authentication and security association at the link layer is one of the major components of delay during handoff. We propose a network- layer assisted proactive handoff scheme that helps to optimize the handoff process involving link-layer security across multiple subnets. We demonstrate this proactive scheme and analyze the results for IEEE 802.11-based networks for both roaming and non-roaming scenarios. We then compare these results with the pre-authentication techniques offered by IEEE 802.11i. Rafael Marín López, Ashutosh Dutta, Yoshihiro Ohba, Henning Schulzrinne, Antonio F. Skarmeta |
MobiQuitous | 5 |
| 2007 | Aspect-Oriented Programing Techniques to support Distribution, Fault Tolerance, and Load Balancing in the CORBA-LC Component ModelabstractThe design and implementation of distributed High Performance Computing (HPC) applications is becoming harder as the scale and number of distributed resources and application is growing. Programming abstractions, libraries and frameworks are needed to better overcome that complexity. Moreover, when Quality of Service (QoS) requirements such as load balancing, efficient resource usage and fault tolerance have to be met, the resulting code is harder to develop, maintain, and reuse, as the code for providing the QoS requirements gets normally mixed with the functionality code. Component Technology, on the other hand, allows a better modularity and reusability of applications and even a better support for the development of distributed applications, as those applications can be partitioned in terms of components installed and running (deployed) in the different hosts participating in the system. Components also have requirements in forms of the aforementioned non-functional aspects. In our approach, the code for ensuring these aspects can be automatically generated based on the requirements stated by components and applications, thus leveraging the component implementer of having to deal with these non-functional aspects. In this paper we present the characteristics and the convenience of the generated code for dealing with load balancing, distribution, and fault-tolerance aspects in the context of CORBA-LC. CORBA-LC is a lightweight distributed reflective component model based on CORBA that imposes a peer network model in which the whole network acts as a repository for managing and assigning the whole set of resources: components, CPU cycles, memory, etc. Diego Sevilla Ruiz, José M. García 0001, Antonio F. Skarmeta |
NCA | 3 |
| 2007 | Editorial Wireless Mobile Networks: Cross-Layer Communication
Han-Chieh Chao, C. M. Huang, Mohsen Guizani, Sy-Yen Kuo, Antonio F. Skarmeta, Winston Khoon Guan Seah |
IET Commun. | 5 |
| 2007 | Improving interpretability in approximative fuzzy models via multiobjective evolutionary algorithmsabstractCurrent research lines in fuzzy modeling mostly tackle improving the accuracy in descriptive models and improving of the interpretability in approximative models. This article deals with the second issue, approaching the problem by means of multiobjective optimization in which accuracy and interpretability criteria are simultaneously considered. Evolutionary algorithms are especially appropriated for multiobjective optimization because they can capture multiple Pareto solutions in a single run of the algorithm. We propose a multiobjective evolutionary algorithm to find multiple Pareto solutions (fuzzy models) showing a trade-off between accuracy and interpretability. Additionally, neural-network-based techniques in combination with ad hoc techniques for improving interpretability are incorporated into the multiobjective evolutionary algorithm to improve the efficiency of the algorithm. © 2007 Wiley Periodicals, Inc. Int J Int Syst 22: 943–969, 2007. Antonio F. Skarmeta, Fernando Jiménez, Gracia Sánchez |
Int. J. Intell. Syst. | 1 |
| 2007 | A network access control approach based on the AAA architecture and authorization attributes
Gabriel López Millán, Óscar Cánovas Reverte, Antonio F. Skarmeta, Jesús D. Jiménez Re, Rafael Marín López |
J. Netw. Comput. Appl. | 3 |
| 2007 | High-Integrity IMM-EKF-Based Road Vehicle Navigation With Low-Cost GPS/SBAS/INSabstractUser requirements for the performance of Global Navigation Satellite System (GNSS)-based road applications have been significantly increasing in recent years. Safety systems based on vehicle localization, electronic fee-collection systems, and traveler information services are just a few examples of interesting applications requiring onboard equipment (OBE) capable of offering a high available accurate position, even in unfriendly environments with low satellite visibility such as built-up areas or tunnels and at low cost. In addition to that, users and service providers demand from the OBEs not only accurate continuous positioning but integrity information of the reliability of this position as well. Specifically, in life-critical applications, high-integrity monitored positioning is absolutely required. This paper presents a solution based on the fusion of GNSS and inertial sensors (a Global Positioning System/satellite-based augmentation system/inertial navigation system integrated system) running an extended Kalman filter combined with an interactive multimodel method (IMM-EKF). The solution developed in this paper supplies continuous positioning in marketable conditions and a meaningful trust level of the given solution. A set of tests performed in controlled and real scenarios proves the suitability of the proposed IMM-EKF implementation as compared with low-cost GNSS-based solutions, dead reckoning systems, single-model EKF, and other filtering approaches of the current literature. Rafael Toledo-Moreo, Miguel A. Zamora 0001, Benito Úbeda Miñaro, Antonio F. Skarmeta |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2006 | Towards Interoperability in Collaborative EnvironmentsabstractThe impact of information and communication technologies (ICT) has gained its prominence in several areas such as business and education. More concretely, during the last years it has been developed several tools and platforms so as to enrich the way of learning. Projects as NETCOIL and ECOSPACE study the way of establishing interoperation between different tools. More concretely, this paper analyzes the work done in NETCOIL and how it should be improved using Web services standards, taken from the business area. This paper also deals with the design of a generic interoperable collaborative platform, that can be useful also in business area, such as the ECOSPACE project, or in learning area M. Antonia Martínez-Carreras, Antonio F. Skarmeta |
CollaborateCom | 2 |
| 2006 | ECOSPACE - Towards an Integrated Collaboration Space for eProfessionalsabstractThis paper provides an overview on the ECOSPACE Integrated Project that is partly funded by the European Commission in the framework of the collaborative work environments framework. We present the motivation, goals and research approach of the project Wolfgang Prinz, Hermann Loeh, Marc Pallot, Hans Schaffers, Antonio F. Skarmeta, Stefan Decker |
CollaborateCom | 5 |
| 2006 | Multidomain Virtual Security Negotiation over the Session Initiation Protocol (SIP)
Daniel J. Martínez-Manzano, Gabriel López Millán, Antonio F. Skarmeta |
CRITIS | 3 |
| 2006 | Improved EAP keying framework for a secure mobility access serviceabstractUsers roaming is an important feature to be provided by current ISPs. The goal is to allow users to access to the Internet from everywhere without the need to have multiple subscriptions.A suitable authentication and key distribution mechanism between different domains involved is required to provide a secure network access service. The IETF solution for this is the Extensible Authentication Protocol (EAP) which supports various authentication methods while defining a keying framework. However, this framework suffers from some limitations in roaming scenario, specially in a mobility context. The reason is that each time the visited network needs to reauthenticate the client, the home domain must be contacted. This may introduce some consequent delay if the client is far from it.This paper proposes a new design which improves the current EAP keying distribution framework. The basic idea is to allow the visited domain to play a more active role in the key distribution. For this, we introduce a new level in the key hierarchy defined in the EAP keying framework. Thanks to this one, a new key can be used between the mobile and the visited network. This brings better performance during reauthentication as the home domain is no longer solicited. Rafael Marín López, Antonio F. Skarmeta, Julien Bournelle, Maryline Laurent, Jean Michel Combes |
IWCMC | 2 |
| 2006 | Virtual identities in authentication and authorization scenariosabstractUsers accessing to the Internet from everywhere will require to have access to the services in which they have a signed contract. This is the most important feature for roaming users: a way to access to all their services without having in mind where are they connected. Santiago Zapata Hernandez, Antonio F. Skarmeta |
PST | 2 |
| 2006 | A new fair non-repudiation protocol for secure negotiation and contract signingabstractIn some scenarios, such as B2B or IPR contracting, or by legal requirement, the participation of an e-notary in the contract signing is required in many cases, that is, an on-line TTP. This e-notary gives validity to the contract or performs some tasks related to the contract, such as contract registration or fraud detection. In these B2B or DRM contracting scenarios, two important additional features are needed: the negotiation of the e-contract and confidentiality. However, until now, e-contract signing protocols have not considered both of these as an essential part of the protocol. In this paper, we present a new protocol which is designed to make negotiation and contract signing secure and in a confidential way. Moreover, the protocol, compared to other previous proposals based on an on-line TTP, reduces the e-notary's workload. Finally, we describe how the protocol is being used in conjunction with an extended version of ODRL to achieve agreements on the rights of copyright works in a DRM infrastructure. Antonio Ruiz-Martínez, C. Inmaculada Marín-López, Laura Baño-López, Antonio F. Skarmeta |
PST | 4 |
| 2006 | Combination of a Smartcard E-Purse and E-Coin to Make Electronic Payments on the Internet
Antonio Ruiz-Martínez, Antonio F. Skarmeta, Óscar Cánovas Reverte |
SECRYPT | 2 |
| 2006 | Using Microsoft Office Infopath to Generate XACML Policies
Manuel Sánchez, Gabriel López Millán, Antonio F. Skarmeta, Óscar Cánovas Reverte |
SECRYPT | 3 |
| 2006 | Monitoring the Position Integrity in Road Transport Localization Based ServicesabstractNowadays, a new generation of civil location based services (LBS) included in the intelligent road transport systems (ITS-R) field is emerging. The reliability of positioning sensors and the communication infrastructure will be the key to the success of such services. A recommended basic onboard equipment (OBE) can include a GNSS based sensor, an embedded computer, a communication equipment and some other aiding sensors. The current GPS based sensors, operating in standard positioning service (SPS) or differential GPS (DGPS) modes, supply the level of accuracy required by many services of interest. However, the solution availability and the integrity monitoring are the main problems for GNSS based road applications, where the cost plays a significant role. In this paper, an embedded software for monitoring the availability and integrity of a GNSS positioning system is presented. The software developed allows the study of the HPLSBAS(Horizontal Protection Level) parameter as a reliable integrity indicator of the positioning system performance. Its suitability for road applications, and the importance of the geostationary satellite visibility and the GPRS/UMTS coverage are analyzed in this paper. Finally, selected results of these investigations and their conclusions are commented. José Santa, Benito Úbeda Miñaro, Rafael Toledo, Antonio F. Skarmeta |
VTC Fall | 4 |
| 2006 | Dynamic and secure management of VPNs in IPv6 multi-domain scenarios
Gregorio Martínez Pérez, Gabriel López Millán, Félix J. García Clemente, Antonio F. Skarmeta |
Comput. Commun. | 4 |
| 2006 | Multi-objective evolutionary computation and fuzzy optimization
Fernando Jiménez, José Manuel Cadenas, Gracia Sánchez, Antonio F. Skarmeta, José L. Verdegay |
Int. J. Approx. Reason. | 4 |
| 2006 | Fuzzy approach to the intelligent management of virtual spacesabstractThis paper presents research carried out toward the improvement of current virtual environments from an intelligent systems approach. A novel architecture to solve vague queries that allows users to find objects and scenes in virtual environments is described. As a base, a new virtual worlds representation model and an associated fuzzy querying approach are used. The new representation model adds a semantic level to the usual models, providing more suitable environments for the interaction with users. The query solver is able to work with queries expressing the vagueness inherent to human conceptualization of visual perception (for example, tall tree, a park with many tall trees, or a park bench near approximately five tall trees). The system has been developed and evaluated with user experiments, where comparison with navigation and keyword-based query approaches have been realized. The results of this study show that the proposed architecture is more powerful and intuitive for finding the targets. Jesús Ibáñez 0001, Antonio F. Skarmeta, Josep Blat |
IEEE Trans. Syst. Man Cybern. Part B | 2 |
| 2005 | Implementing RADIUS and Diameter AAA Systems in IPv6-Based ScenariosabstractAAA (authentication, authorization and accounting) frameworks are defined as a set of models, infrastructures and protocols needed to interconnect AAA entities. They have been mainly deployed so far using the RADIUS protocol in IPv4 networks. However, when taking such AAA systems to IPv6 networks some interesting issues appear that need to be addressed. This is the main focus of this paper where both RADIUS and diameter protocols are deployed in different IPv6-related scenarios. Rafael Marín López, Gregorio Martínez Pérez, Antonio F. Skarmeta |
AINA | 3 |
| 2005 | Deploying Secure Cryptographic Services in Multi-Domain IPv6 NetworksabstractThere are several reasons to offer PKI (public key infrastructure) services in IPv6 multidomain scenarios. The first reason is to provide IPv6-only or dual-stack connectivity to those Internet users and entities who want to use certification services, but there are other important motivations. If we want to enable and promote security services in IPv6 networks, like end-to-end security, AAA (authentication, authorization and accounting) services, HTTP or DNSsec services, or VPN networks, it is needed to offer the public key services required by the involved protocols. Other relevant reason is to allow services or devices to use X.509 public key certificates containing IPv6 information, such as IPv6 addresses used, for example, by any IPsec-based VPN end point. This is the main motivation of the research work presented in this paper where the most relevant design and implementation issues related with the deployment of PKI services in a multidomain IPv6 network are presented. Gabriel López Millán, Félix J. García Clemente, Manuel Gil Pérez, Gregorio Martínez Pérez, Antonio F. Skarmeta |
AINA | 5 |
| 2005 | The Planet Project: collaborative educational content repositories on structured peer-to-peer gridsabstractIn this paper we present the Planet Project. Its main goal is focused on educational content generation and wide-area distribution. For that matter, we have designed a distributed content repository (PlanetDR) which has been built on top of a structured peer-to-peer grid middleware called Dermi. The system has been made with interoperability in mind and it thus follows the IMS Digital Repositories Interoperability standard through an implementation of the eduSource Communication Language protocol. PlanetDR has been extended to support a federation mode, which to the best of our knowledge constitutes the first attempt in providing an alliance of content repositories throughout a structured peer-to-peer grid. Moreover, we have also created several collaborative tools which will he integrated in the content's life cycle in order to promote knowledge communities around educational content hierarchies. Subsequently, we have developed PlanetDR Communities which allow researchers to easily locate themselves by their own keywords of interest, which are stored and looked up in a peer-to-peer grid decentralized infrastructure. Carles Pairot, Pedro García López, Robert Rallo, Josep Blat, Antonio F. Skarmeta |
CCGRID | 5 |
| 2005 | Designing collaborative environments and their application in learningabstractNowadays there is an increase on the research to provide a collaborative environment in several areas such as business, health and education. More concretely, our study is focused on providing collaborative systems, offering both types of scenarios, the synchronous and the asynchronous. This paper aims to bring out the design and implementation of two collaborative systems and theirs application to education. One of them is a synchronous collaborative system to be integrated in existing Web environments. This system is part of the research carried out in the ITCOLE (IST 2000-26249). This previous result brought out some key aspects to build a entire collaborative platform for building any kind of collaborative environment, including those environments to support experimentation. This platform was the core of COLAB which is an application for discovery learning and it is the result of the COLAB project (IST-2000-25035). Both environments offer APIs to allow the development of collaborative tools with both types of collaborative scenarios so as to enrich user collaboration. M. Antonia Martínez-Carreras, Antonio F. Skarmeta, Eduardo Martínez-Gracía |
CollaborateCom | 2 |
| 2005 | Distributed Contextual Information Storage Using Content-Centric Hash Tables
Ignacio Nieto-Carvajal, Juan A. Botía Blaya, Pedro M. Ruiz, Antonio F. Skarmeta |
EUC | 4 |
| 2005 | A Building-Block Approach to Hybrid Fuzzy ModelingabstractIn the last years, many authors have solved the data-driven fuzzy modeling (DDFM) problem by combining different techniques into hybrid strategies. Moreover, the hybridization in DDFM has demonstrated to be a successful approach. However, these combinations are made in an ad hoc manner and there exists a lack of mechanisms to make these combinations in an easy and unified manner. This work proposes a new DDFM reference model called METHOD starting from which frameworks for hybridization could be designed. This model offers the functionalities needed to seamlessly combine techniques as building blocks into hybrid strategies for DDFM tasks Mercedes Valdés-Vela, Antonio F. Skarmeta, Juan A. Botía Blaya |
FUZZ-IEEE | 2 |
| 2005 | Some Applications of Hybrid Fuzzy ModelingabstractFuzzy modeling is an effective approach for system identification. It is based on fuzzy sets and logic and describes the system behaviour by means of fuzzy IF-THEN rules. In its turn, data driven fuzzy modeling (DDFM) extracts these models from a set of input-output observations about the system. Three main stages compose DDFM: rules number identification, rules generation and parameter optimization. One way to carry out a DDFM process is by means of a combination of techniques, each one solving one of the DDFM phases. In this paper, the authors applied hybridizations of clustering algorithms and neural networks (NN) in order to solve several regression problems from different domains showing up the suitability and success of hybridization in DDFM Mercedes Valdés-Vela, Juan A. Botía Blaya, Antonio F. Skarmeta |
FUZZ-IEEE | 3 |
| 2005 | Approximating Optimal Multicast Trees in Wireless Multihop NetworksabstractWe study the problem of computing minimal cost multicast trees in multi-hop wireless mesh networks. This problem is known as the Steiner tree problem, and it has been widely studied in fixed networks. However, we show in this paper that in multi-hop wireless mesh networks, a Steiner tree is no longer offering the lowest bandwidth consumption. So, we re-formulate the problem in terms of minimizing the number of transmissions. We show that the new problem is also NP-complete and propose heuristics to approximate such trees. Our simulations results show that the proposed heuristics offer a lower cost than Steiner trees over a variety of scenarios. Pedro M. Ruiz, Antonio F. Skarmeta |
ISCC | 2 |
| 2005 | Performance Evaluation of Existing Approaches for Hybrid Ad Hoc Networks Across Mobility Models
Francisco J. Ros, Pedro M. Ruiz, Antonio F. Skarmeta |
MSN | 3 |
| 2005 | Cyclone: A Novel Design Schema for Hierarchical DHTsabstractRecent research efforts have improved the existing flat distributed hash tables to accommodate hierarchical structure. Nevertheless, many problems still remain to be solved regarding scalability issues, autonomous systems, connection degree, and network proximity. In this paper, we present a new hierarchical DHT called Cyclone that aims to solve the aforementioned issues with a near-optimal architecture. Cyclone provides optimal logarithmic routing hops without establishing unnecessary connection links to other nodes. Our approach follows a horizontal and uniform leaf-based approach that considerably reduces the overall number of links per node. Furthermore, Cyclone also offers a disjoint multipath routing scheme that benefits from network proximity and thus creates a more robust overlay infrastructure. Marc Sánchez Artigas, Pedro García López, Jordi Pujol Ahulló, Antonio F. Skarmeta |
Peer-to-Peer Computing | 4 |
| 2005 | Towards new load-balancing schemes for structured peer-to-peer grids
Carles Pairot, Pedro García López, Antonio F. Skarmeta, Rubén Mondéjar |
Future Gener. Comput. Syst. | 3 |
| 2005 | Toward a framework for the specification of hybrid fuzzy modelingabstractDuring the few last years, several successful approaches for the integration of soft computing techniques have been proposed in the area of data-driven fuzzy modeling (DDFM). However, there is a lack of methodological and general purpose hybridization in an easy and unified manner. This work outlines the design of a new DDFM framework called METHOD, offering the functionalities needed to combine techniques into hybrid strategies for DDFM tasks. Bearing in mind our main goal, a previous analysis of several existing DDFM techniques helps us: (1) to identify the most usual interaction schemes, by means of which methods are combined into DDFM hybrid strategies; (2) to exemplify requirements and effects for different techniques determining suitable combinations; and (3) to establish the universe of discourse based on which of these requirements and effect are defined. All these ideas are illustrated with examples. © 2005 Wiley Periodicals, Inc. Int J Int Syst 20: 225–252, 2005. Mercedes Valdés-Vela, Antonio F. Skarmeta, Juan A. Botía Blaya |
Int. J. Intell. Syst. | 2 |
| 2004 | ACLAnalyser: A Tool for Debugging Multi-Agent Systems
Juan A. Botía Blaya, Alberto López-Acosta, Antonio F. Skarmeta |
ECAI | 3 |
| 2004 | Implementation and Evaluation of a Location-Aware Wireless Multi-agent System
Ignacio Nieto-Carvajal, Juan A. Botía Blaya, Pedro M. Ruiz, Antonio F. Skarmeta |
EUC | 4 |
| 2004 | DERMI: A Decentralized Peer-to-Peer Event-Based Object MiddlewareabstractWe present DERMI, a decentralized wide-area event-based object middleware built on top of a peer-to-peer substrate. Its main building block is the underlying publish/subscribe event notification system provided by the peer-to-peer layer. By using this methodology, innovative benefits like distributed interception, high performance synchronous/asynchronous one-to-one/one-to-many notifications and decentralized object location services are provided. Moreover, new programming abstractions (anycall and manycall) are introduced, which allow the programmer to make calls to groups of objects without taking care of which of them responds until a determinate condition is met. We believe that such middleware is a solid building block for future wide-area distributed component infrastructures. Carles Pairot, Pedro García López, Antonio F. Skarmeta |
ICDCS | 3 |
| 2004 | Enhanced Internet Connectivity for Hybrid Ad hoc Networks Through Adaptive Gateway DiscoveryabstractOne of the key components affecting the overall performance of hybrid ad hoc networks is the algorithm used to discover and select Internet gateways. We have analytically modeled existing proposals (i.e., proactive, reactive and hybrid gateway discovery) showing that each of them is most suited only for a limited range of network parameters. We propose a new adaptive gateway discovery algorithm called "maximal benefit coverage" based on the dynamic adjustment of the scope of the gateway advertisement packets. We show, by simulation, that the ability of our proposed scheme to adapt to the changes in network conditions allows it to outperform existing alternative mechanisms over a variety of scenarios and mobility rates. Pedro M. Ruiz, Antonio F. Skarmeta |
LCN | 2 |
| 2004 | Integrated IP multicast in mobile ad hoc networks with multiple attachments to wired IP networksabstractLittle has been accomplished to date in bringing together the traditional IP multicast model used in fixed networks and multicast routing protocols for wireless ad hoc networks. We analyse the provision of an integrated IP multicast service in which mobile hosts can seamlessly participate in IP multicast sessions regardless of their point of attachment to the network (e.g. fixed network, ad hoc network, etc.). We propose a multicast architecture in combination with a new ad hoc multicast routing protocol called MMARP. It combines the efficiency of multicast ad hoc routing protocols with the support of standard IP nodes without an impairment in the overall performance. Our empirical studies on the handover between different access routers shows that the proposed approach clearly outperforms the traditional single-hop wireless multicast handoff by several orders of magnitude. Pedro M. Ruiz, Antonio F. Skarmeta |
PIMRC | 2 |
| 2004 | Reducing data-overhead of mesh-based ad hoc multicast routing protocols by Steiner tree meshesabstractWe study the problem of reducing data overhead of mesh-based multicast ad hoc routing protocols by reducing the number of forwarding nodes. We show that minimizing the number of forwarding nodes is equivalent to the problem of finding the minimal cost multicast tree. In addition, we demonstrate the problem to be NP-complete by a transformation to the Steiner tree problem. We propose a distributed heuristic algorithm based on the epidemic propagation of the number of forwarding nodes. Our simulation results show that the proposed heuristic, when implemented into ODMRP, is able to offer similar performance results and a lower average latency while improving the forwarding efficiency in around a 40-50% with respect to the original ODMRP. Pedro M. Ruiz, Antonio F. Skarmeta |
SECON | 2 |
| 2004 | A fuzzy language
Daniel Sánchez Alvarez, Antonio F. Skarmeta |
Fuzzy Sets Syst. | 2 |
| 2004 | Providing QoS through machine-learning-driven adaptive multimedia applicationsabstractWe investigate the optimization of the quality of service (QoS) offered by real-time multimedia adaptive applications through machine learning algorithms. These applications are able to adapt in real time their internal settings (i.e., video sizes, audio and video codecs, among others) to the unpredictably changing capacity of the network. Traditional adaptive applications just select a set of settings to consume less than the available bandwidth. We propose a novel approach in which the selected set of settings is the one which offers a better user-perceived QoS among all those combinations which satisfy the bandwidth restrictions. We use a genetic algorithm to decide when to trigger the adaptation process depending on the network conditions (i.e., loss-rate, jitter, etc.). Additionally, the selection of the new set of settings is done according to a set of rules which model the user-perceived QoS. These rules are learned using the SLIPPER rule induction algorithm over a set of examples extracted from scores provided by real users. We will demonstrate that the proposed approach guarantees a good user-perceived QoS even when the network conditions are constantly changing. Pedro M. Ruiz, Juan A. Botía Blaya, Antonio F. Skarmeta |
IEEE Trans. Syst. Man Cybern. Part B | 3 |
| 2003 | Towards a formal framework for the specification hybrid fuzzy modelingabstractThis architecture starts when a previously existing software system ends. This software tool offers the needed functionality to work with general purpose inductive learning. Now, new functionalities, those needed to cope with hybrid fuzzy modeling, are being added to it. In order to reach our main goal, the following four ones are the most important ideas that we will consider. The first one is that we see data driven fuzzy modeling as a set of successive transformations done to data, starting from the raw source data and finishing at the desired fuzzy inference system. The second one is the modelization of the "fuzzy modeling task" concept in terms of domains, codomains, preconditions, postconditions inside a concrete domain of discourse. The third one is the definition of different schemes for tasks composition to form higher level tasks in a transparent manner. Finally, the fourth one is the concretion of the methodological steps to follow on the integration into this new framework of base techniques to be used as building blocks to compound higher level tasks. All these ideas are finally illustrated with an example. Mercedes Valdés-Vela, Juan A. Botía Blaya, Antonio F. Skarmeta |
FUZZ-IEEE | 3 |
| 2003 | i-Fork: a flexible AGV system using topological and grid mapsabstractIn this paper we describe the navigation and planning of the i-Fork system, a flexible AGV intended to operate in partially structured warehouses where frequent floor plant layout modifications occur. This is achieved by using a combination of topological and grid maps in such a way that the operator work in layout modification procedures is greatly reduced. The system is currently working in an agricultural company with great success. Humberto Martínez Barberá, Juan Petro Canovas Quiñonero, Miguel A. Zamora 0001, Antonio F. Skarmeta |
ICRA | 4 |
| 2003 | DJ-boids: emergent collective behavior as multichannel radio station programmingabstractIn this paper we propose to apply emergent collective behavior ideas to automatically program Internet multichannel radio stations. The proposed model simulates n virtual Dj's (one per channel) playing songs at the same time. Every virtual Dj takes into account the songs played by the other ones, programming a sequence of songs whose order is also coherent. That is, every song played in a channel takes into account both, the song previously played in the same channel and the songs being played in the other channels at the same time Jesús Ibáñez 0001, Antonio F. Skarmeta, Josep Blat |
IUI | 2 |
| 2003 | Intelligent and adaptive middleware to improve user-perceived QoS in multimedia applicationsabstractWe investigate the use of adaptive multimedia applications to improve the user-perceived QoS in next-generation wireless networks. These networks will be characterized by the heterogeneity of the access technologies including ad hoc wireless network extensions. In these network scenarios in which the links are error-prone, their capacity is extremely variable and even the topology can change due to handovers and mobility of the nodes, it is unrealistic to think of traditional network-layer QoS mechanisms alone, as a means to offer strict end-to-end QoS guarantees. As a complement to the network-layer QoS protocols, this paper presents an intelligent adaptation middleware allowing multimedia applications to dynamically adapt their internal settings. This intelligence enables the applications to minimize the impact of the adverse and changing network conditions in the QoS level perceived by the user. We use a machine learning technique to model the user's perception of QoS from a large set of QoS scores given by real users. We present some results demonstrating that our proposal clearly outperforms traditional multimedia internetworking. Pedro M. Ruiz, Juan A. Botía Blaya, Antonio F. Skarmeta, Pedro Martinez-Julia |
PIMRC | 3 |
| 2003 | Multi-objective Evolutionary Algorithms based fuzzy optimizationabstractWe deal with nonlinear programming problems with fuzzy constrains for which we use parametric programming based solution methods. We propose a multi-objective approach to solve parametric programming problems, and a multi-objective Pareto-based Evolutionary Algorithm is used. Results with linear and nonlinear test problems studied in literature are shown. Gracia Sánchez, Fernando Jiménez, Antonio F. Skarmeta |
SMC | 3 |
| 2003 | Using genetic algorithms to optimize the behaviour of adaptive multimedia applications in wireless and mobile scenariosabstractAdaptive applications are a key concept to take into account when dealing with multimedia internetworking in wireless and mobile environments in which abrupt changes in the network conditions may occur. In these scenarios not all the problems in the multimedia quality are due to congestion, as it happens in fixed networks, but also to interference, mobility, and many other issues. This paper presents an adaptation architecture allowing applications to use adaptation techniques at the application layer to minimize the impact of adverse and changing network conditions. This allows maintaining the QoS perceived by the user in an acceptable level. In addition, we optimize the adaptive behavior using genetic algorithms to estimate the optimal triggers for the adaptation function. We present some results comparing the fitness of using such adaptive techniques against the traditional multimedia internetworking. Pedro M. Ruiz, Antonio F. Skarmeta |
WCNC | 2 |
| 2003 | New security services based on PKI
Antonio F. Skarmeta, Gregorio Martínez Pérez, Óscar Cánovas Reverte |
Future Gener. Comput. Syst. | 1 |
| 2002 | An evolutionary algorithm for constrained multi-objective optimizationabstractThe paper follows the line of the design and evaluation of new evolutionary algorithms for constrained multi-objective optimization. The evolutionary algorithm proposed (ENORA) incorporates the Pareto concept of multi-objective optimization with a constraint handling technique and with a powerful diversity mechanism to obtain multiple nondominated solutions through the simple run of the algorithm. Constraint handling is carried out in an evolutionary way and using the min-max formulation, while the diversity technique is based on the partitioning of search space in a set of radial slots along which are positioned the successive populations generated by the algorithm. A set of test problems recently proposed for the evaluation of this kind of algorithm has been used in the evaluation of the algorithm presented. The results obtained with ENORA were very good and considerably better than those obtained with algorithms recently proposed by other authors. Fernando Jiménez, Antonio F. Skarmeta, Gracia Sánchez, Kalyanmoy Deb |
IEEE Congress on Evolutionary Computation | 2 |
| 2002 | Towards a modeling framework for integrating hybrid techniquesabstractNowadays, it is easy to find a number of different hybrid approaches for fuzzy modeling. All these approaches were built in a very ad-hoc manner, and did not follow a systematic approach. However, we think that some kind of information system which helps in the study of how algorithms can combine to model systems in a fuzzy fashion should be very helpful. In this article, we propose METALA (META-Learning Architecture), an architecture to study the typical processes of machine learning, to study the particular issue of fuzzy modeling. Antonio F. Skarmeta, Fernando Jiménez, Mercedes Valdés-Vela, Juan A. Botía Blaya, Antonio M. Padilla |
FUZZ-IEEE | 1 |
| 2002 | A framework for defining and learning fuzzy behaviors for autonomous mobile robotsabstractIn this paper we show our work on the use of fuzzy behaviors in the field of autonomous mobile robots. We address here how we use learning techniques to efficiently coordinate the conflicts between the different behaviors that compete with each other to take control of the robot. We use fuzzy rules to perform such fusion. These rules can be set using expert knowledge, but as this can be a complex task, we show how to automatically define them using genetic algorithms. We also describe the working environment, which includes a custom programming language (named BG) based on the multi-agent paradigm. Finally, some results related to simple goods-delivery tasks in an unknown environment are presented. © 2002 John Wiley & Sons, Inc. Humberto Martínez Barberá, Antonio F. Skarmeta |
Int. J. Intell. Syst. | 2 |
| 2001 | Accurate, Transparent, and Compact Fuzzy Models for Function Approximation and Dynamic Modeling through Multi-objective Evolutionary Optimization
Fernando Jiménez, Antonio F. Skarmeta, Johannes A. Roubos, Robert Babuska |
EMO | 2 |
| 2001 | CORBA Lightweight Components : A Model for Distributed Component-BasedHeterogeneous Computation
Diego Sevilla Ruiz, José M. García 0001, Antonio F. Skarmeta |
Euro-Par | 3 |
| 2001 | Fuzzy and Hybrid Methods Applied to GIS InterpolationabstractSoft computing can be a powerful approach in the agricultural domain. In particular two different techniques have been developed for the approximation of solar radiation, a key parameter for the calculus of irrigation water for crops. Besides, one of the methods has been developed on the basis of the cooperation of two well known techniques, and it is presented as a novel approach. Juan A. Botía Blaya, Antonio F. Skarmeta, Mercedes Valdés-Vela, Antonio Stou |
FUZZ-IEEE | 2 |
| 2001 | Navigation of a Mobile Robot With Fuzzy SegmentsabstractThis paper outlines the problem of a mobile robot navigating in an unknown environment. This is solved in a two step process by the application of two navigation techniques. In the first step a fuzzy grid map is applied for the map-building problem, and an A* search method is applied for the path-planning problem. In the second step a fuzzy segments map is applied for the map-building and localisation problems. Some results in both simulator and real robot are presented. Humberto Martínez, Miguel A. Zamora 0001, Antonio F. Skarmeta |
FUZZ-IEEE | 3 |
| 2001 | AMBAR Protocol: Access Management Based on Authorization Reduction
Óscar Cánovas Reverte, Antonio F. Skarmeta |
ICICS | 2 |
| 2001 | SPEED Protocol: Smartcard-Based Payment with Encrypted Electronic Delivery
Antonio Ruiz-Martínez, Gregorio Martínez Pérez, Óscar Cánovas Reverte, Antonio F. Skarmeta |
ISC | 4 |
| 2001 | A regression methodology to induce a fuzzy modelabstractIn this work, we present the induction of a fuzzy model that represents the behavior of a partial known function. We extend the approach of classical induction of a classifier by building a decision tree, and its generalization for regression problems by CART, to build a fuzzy model. It is defined by a collection of fuzzy regions fixed in the input domain of the function. To obtain fuzzy regions of the input domain, we have defined a new method (FCMD) to get a fuzzy partition of a fuzzy set, which generalizes the classical Bezdeck's method FCM. © 2001 John Wiley & Sons, Inc. Miguel Delgado 0001, Antonio F. Skarmeta, Luis Jiménez 0001 |
Int. J. Intell. Syst. | 2 |
| 2001 | Approximative fuzzy rules approaches for classification with hybrid-GA techniques
Antonio F. Skarmeta, Mercedes Valdés-Vela, Fernando Jiménez, Javier G. Marín-Blázquez |
Inf. Sci. | 1 |
| 2000 | Evolutionary computation techniques for behaviour fusion in autonomous mobile robotsabstractIn this paper, we present evolutionary techniques to solve the problem of the conflicts between different behaviours in the context of an autonomous mobile robot. We also describe the working environment, based on a custom programming language (named BG after its inventors, Barber/spl acute/a and Go/spl acute/mez, 1996) and an agent architecture, where we test a series of behaviours that were developed using fuzzy logic. Finally, some results related to a simple navigational task in an unknown environment are presented. Humberto Martínez, Antonio F. Skarmeta, Fernando Jiménez, Miguel Zamora |
CEC | 2 |
| 2000 | Time series prediction using crisp and fuzzy neural networks: a comparative studyabstractEvery organization needs adequate forecasts for planning the future. The accuracy of forecasts is influenced by both the quality of past data and the method selected to forecast the future. In this paper, we carry out a comparative study between the time series forecasts from (1) the Quick-prop neural network, (2) a fuzzy neural network (adaptive-network-based fuzzy inference system (ANFIS)), (3) a fuzzy regression and identification decision tree (ADRI), and (4) traditional time series methods (ARIMA models). We augment ANFIS by using fuzzy curves to identify the input variables that have the most influence on the output. This method identifies the significant input variables that lead to a considerable decrease in training time for ANFIS, while keeping the performance at least as good. We test the performance of ANFIS with the fuzzy curve pruning technique on empirical time series data (the national private consumption) from the Spanish economy. ANFIS produced the best performance on forecasting the empirical time series data compared to ADRI and ARIMA. Bouchra Bouqata, Amine Bensaid, Ralph Palliam, Antonio F. Skarmeta |
CIFEr | 4 |
| 2000 | Soft computing applied to irrigation in farming environmentsabstractThe present work shows the first results obtained in the application of various intelligent techniques to the calculation of the water needs of many different cultivation types. The area in which these studies have been realised is the south-east of Spain. These results are part of a research project developed along with the CIDA (Centro de Investigacion y Desarrollo Agroalimentario). Its final goal is to develop a decision support system using many intelligent techniques in order to ease the optimization in the use of irrigation water and fertilizers. The access to the system is intended to be generic, through a Web-based platform. Juan A. Botía Blaya, Antonio F. Skarmeta, Gracia Sánchez y Mercedes Valdés, Juan Antonio López-Morales |
FUZZ-IEEE | 2 |
| 2000 | From approximative to descriptive modelsabstractPresents a technique for translating rules that use approximative sets to rules that use descriptive sets and linguistic hedges of predefined meaning. The translated descriptive rules will be functionally equivalent to the original approximative ones, or the closest equivalence possible, while reflecting their underlying semantics. Thus, descriptive models can take advantage of any existing approach to approximative modelling which is generally efficient and accurate, whilst employing rules that are comprehensible to human users. Javier G. Marín-Blázquez, Antonio F. Skarmeta |
FUZZ-IEEE | 3 |
| 2000 | IGMPv3-Based Method for Avoiding DoS Attacks in Multicast-Enabled NetworksabstractIP multicast has proven to be very good for many-to-many multimedia communications like audio and video conferencing. However there are only a few Internet service providers offering it as a true Internet service to their customers. The reason is that nowadays, IP multicast has many issues like billing, authentication, security protection against malicious people and so on. In fact, DoS attacks can be easily caused in IP multicast-enabled networks. We describe how to solve some of these problems. Antonio F. Skarmeta, Angel L. Mateo-Martinez, Pedro M. Ruiz |
LCN | 1 |
| 2000 | Data mining for text categorization with semi-supervised agglomerative hierarchical clusteringabstractIn this paper we study the use of a semi-supervised agglomerative hierarchical clustering (ssAHC) algorithm to text categorization, which consists of assigning text documents to predefined categories. ssAHC is (i) a clustering algorithm that (ii) uses a finite design set of labeled data to (iii) help agglomerative hierarchical clustering (AHC) algorithms partition a finite set of unlabeled data and then (iv) terminates without the capability to label other objects. We first describe the text representation method we use in this work; we then present a feature selection method that is used to reduce the dimensionality of the feature space. Finally, we apply the ssAHC algorithm to the Reuters database of documents and show that its performance is superior to the Bayes classifier and to the Expectation-Maximization algorithm combined with Bayes classifier. We showed also that ssAHC helps AHC techniques to improve their performance. © 2000 John Wiley & Sons, Inc. Antonio F. Skarmeta, Amine Bensaid, Nadia Tazi Labzour |
Int. J. Intell. Syst. | 1 |
| 1999 | About the use of fuzzy clustering techniques for fuzzy model identification
Antonio F. Skarmeta, Miguel Delgado 0001, Maria-Amparo Vila |
Fuzzy Sets Syst. | 1 |
| 1999 | Fuzzy modeling with hybrid systems
Antonio F. Skarmeta, Fernando Jiménez |
Fuzzy Sets Syst. | 1 |
| 1999 | A multiagent architecture for fuzzy modelingabstractIn this paper a hybrid learning system that combines different fuzzy modeling techniques is being investigated. In order to implement the different methods, we propose the use of intelligent agents, which collaborate by means of a multiagent architecture. This approach, involving agents which embody the different problem solving methods, is a potentially useful strategy for enhancing the power of fuzzy modeling systems. ©1999 John Wiley & Sons, Inc. Miguel Delgado 0001, Antonio F. Skarmeta, J. Gómez Marín-Blázquez, Humberto Martínez Barberá |
Int. J. Intell. Syst. | 2 |
| 1999 | Pattern recognition with evidential knowledgeabstractMany real situations may be seen as classifications problems if the information used to relate items with classes is a probability measure on 𝒫(X×C) (set of all subsets of X×C). It is well known that a probability measure on 𝒫(X×C) induces two evidence measures on X×C. We will formulate a classification model where it is assumed classes are fuzzy sets and the available information is evidential. Two bad classification loss functions will be established for this purpose, by using Dempster's upper and lower integrals. ©1999 John Wiley & Sons, Inc. Maria-Amparo Vila, Miguel Delgado 0001, Antonio F. Skarmeta |
Int. J. Intell. Syst. | 3 |
| 1998 | A methodology to model fuzzy systems using fuzzy clustering in a rapid-prototyping approach
Miguel Delgado 0001, Antonio F. Skarmeta, F. Martín |
Fuzzy Sets Syst. | 2 |
| 1997 | Some methods to model fuzzy systems for inference purposes
Miguel Delgado 0001, Antonio F. Skarmeta, F. Martín |
Int. J. Approx. Reason. | 2 |
| 1997 | A fuzzy clustering-based rapid prototyping for fuzzy rule-based modelingabstractThis paper presents different approaches to the problem of fuzzy rules extraction by using fuzzy clustering as the main tool. Within these approaches we describe six methods that represent different alternatives in the fuzzy modeling process and how they can be integrated with a genetic algorithms. These approaches attempt to obtain a first approximation to the fuzzy rules without any assumption about the structure of the data. Because the main objective is to obtain an approximation, the methods we propose must be as simple as possible, but also, they must have a great approximative capacity and in that way we work directly with fuzzy sets induced in the variables input space. The methods are applied to four examples and the errors obtained are specified in the different cases. Miguel Delgado 0001, Antonio F. Skarmeta, F. Martín |
IEEE Trans. Fuzzy Syst. | 2 |
| 1996 | Report on the Spanish association of fuzzy logic and technologies
José Manuel Cadenas, Antonio F. Skarmeta |
Fuzzy Sets Syst. | 2 |
| 1996 | On the use of hierarchical clustering in fuzzy modeling
Miguel Delgado 0001, Antonio F. Skarmeta, Maria-Amparo Vila |
Int. J. Approx. Reason. | 2 |
| 1994 | A frequency model in a fuzzy environment
Miguel Delgado 0001, Antonio F. Skarmeta |
Int. J. Approx. Reason. | 2 |