EDBT 2026 Demo / reviewers in the wild / expert
Paulo Sousa 0001
dblp:s/PauloSousa · also Paulo Jorge Paiva de Sousa
· DBLP profile ↗
10ranked-venue papers
6as first author
0since 2021 · last 2020
0000-0003-3669-705XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 6 · 3 first-authorSecurity and privacy · 6 · 5 first-authorSoftware engineering, systems software and programming languages · 2 · 2 first-authorArtificial intelligence and machine learning · 1Graphics, computer vision, multimedia, augmented reality and games · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Computer architecture, parallel and distributed computing, and storage systems
3 papers |
Cloud and datacenter computing · 39% Storage systems · 31% Distributed systems · 30% | |
| Network and information security
1 paper |
Cryptographic primitives and cryptanalysis · 100% |
Topics — the 8 heaviest of 8, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Cloud and datacenter computing › cloud storage
cloud-of-clouds |
0.3 | 2 | 2013 | DepSky: Dependable and Secure Storage in a Cloud-of-Clouds · ACM Trans. Storage 2013 DepSky: dependable and secure storage in a cloud-of-clouds · EuroSys 2011 |
Cloud and datacenter computing
cloud storage |
0.3 | 2 | 2013 | DepSky: Dependable and Secure Storage in a Cloud-of-Clouds · ACM Trans. Storage 2013 DepSky: dependable and secure storage in a cloud-of-clouds · EuroSys 2011 |
Storage systems
storage reliability |
0.3 | 2 | 2013 | DepSky: Dependable and Secure Storage in a Cloud-of-Clouds · ACM Trans. Storage 2013 DepSky: dependable and secure storage in a cloud-of-clouds · EuroSys 2011 |
Distributed systems
replication |
0.2 | 2 | 2011 | DepSky: dependable and secure storage in a cloud-of-clouds · EuroSys 2011 Highly Available Intrusion-Tolerant Services with Proactive-Reactive Recovery · IEEE Trans. Parallel Distributed Syst. 2010 |
Storage systems
dependable storage |
0.2 | 1 | 2013 | DepSky: Dependable and Secure Storage in a Cloud-of-Clouds · ACM Trans. Storage 2013 |
Distributed systems
fault tolerance |
0.1 | 1 | 2010 | Highly Available Intrusion-Tolerant Services with Proactive-Reactive Recovery · IEEE Trans. Parallel Distributed Syst. 2010 |
Distributed systems › fault tolerance
intrusion tolerance |
0.1 | 1 | 2010 | Highly Available Intrusion-Tolerant Services with Proactive-Reactive Recovery · IEEE Trans. Parallel Distributed Syst. 2010 |
Cryptographic primitives and cryptanalysis
encryption |
0.0 | 1 | 2011 | DepSky: dependable and secure storage in a cloud-of-clouds · EuroSys 2011 |
Methods — techniques the papers use, named apart from their topics
replication · 0.4encryption · 0.4encoding · 0.2secret sharing · 0.2hybrid distributed system model · 0.1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2020 | Fault-Tolerant Architecture for Real-Time Control of Distributed Medical DevicesabstractClinical laboratories use a myriad of medical devices (e.g., automated analyzers) to determine the results of its tests. Modern laboratories have evolved towards almost complete automation, by making use of laboratory information systems (LIS) that interact with medical devices in an automatic way using real-time communication protocols. However, laboratories have been increasing in terms of size and complexity mostly due to economic reasons: large groups of geographically distributed laboratories have been replacing small laboratories. This trend poses challenges for traditional LIS architectures based on a centralized system, given that the distributed nature of modern laboratories has a negative impact on the performance of the communication between medical devices and LIS, and also increases the risk of temporary network disconnection. In this paper we address these challenges by proposing a novel architecture that seamlessly integrates distributed medical devices using mechanisms that provide real-time operation and ensure fault-tolerance. The proposed system is expected to continuously provide trustworthy services even in critical scenarios. Tiago Reis, Alexandre Correia, Paulo Sousa 0001, José Cecílio |
ICARCV | 3 |
| 2013 | DepSky: Dependable and Secure Storage in a Cloud-of-CloudsabstractThe increasing popularity of cloud storage services has lead companies that handle critical data to think about using these services for their storage needs. Medical record databases, large biomedical datasets, historical information about power systems and financial data are some examples of critical data that could be moved to the cloud. However, the reliability and security of data stored in the cloud still remain major concerns. In this work we present DepSky, a system that improves the availability, integrity, and confidentiality of information stored in the cloud through the encryption, encoding, and replication of the data on diverse clouds that form a cloud-of-clouds. We deployed our system using four commercial clouds and used PlanetLab to run clients accessing the service from different countries. We observed that our protocols improved the perceived availability, and in most cases, the access latency, when compared with cloud providers individually. Moreover, the monetary costs of using DepSky in this scenario is at most twice the cost of using a single cloud, which is optimal and seems to be a reasonable cost, given the benefits. Alysson Neves Bessani, Miguel Correia 0001, Bruno Quaresma, Fernando André, Paulo Sousa 0001 |
ACM Trans. Storage | 5 |
| 2011 | DepSky: dependable and secure storage in a cloud-of-cloudsabstractThe increasing popularity of cloud storage services has lead companies that handle critical data to think about using these services for their storage needs. Medical record databases, power system historical information and financial data are some examples of critical data that could be moved to the cloud. However, the reliability and security of data stored in the cloud still remain major concerns. In this paper we present DEPSKY, a system that improves the availability, integrity and confidentiality of information stored in the cloud through the encryption, encoding and replication of the data on diverse clouds that form a cloud-of-clouds. We deployed our system using four commercial clouds and used PlanetLab to run clients accessing the service from different countries. We observed that our protocols improved the perceived availability and, in most cases, the access latency when compared with cloud providers individually. Moreover, the monetary costs of using DEPSKY on this scenario is twice the cost of using a single cloud, which is optimal and seems to be a reasonable cost, given the benefits. Alysson Neves Bessani, Miguel Correia 0001, Bruno Quaresma, Fernando André, Paulo Sousa 0001 |
EuroSys | 5 |
| 2010 | Highly Available Intrusion-Tolerant Services with Proactive-Reactive RecoveryabstractIn the past, some research has been done on how to use proactive recovery to build intrusion-tolerant replicated systems that are resilient to any number of faults, as long as recoveries are faster than an upper bound on fault production assumed at system deployment time. In this paper, we propose a complementary approach that enhances proactive recovery with additional reactive mechanisms giving correct replicas the capability of recovering other replicas that are detected or suspected of being compromised. One key feature of our proactive-reactive recovery approach is that, despite recoveries, it guarantees the availability of a minimum number of system replicas necessary to sustain correct operation of the system. We design a proactive-reactive recovery service based on a hybrid distributed system model and show, as a case study, how this service can effectively be used to increase the resilience of an intrusion-tolerant firewall adequate for the protection of critical infrastructures. Paulo Sousa 0001, Alysson Neves Bessani, Miguel Correia 0001, Nuno Neves 0001, Paulo Veríssimo |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2009 | Intrusion-tolerant self-healing devices for critical infrastructure protectionabstractCritical infrastructures like the power grid are essentially physical processes controlled by electronic devices. In the last decades, these electronic devices started to be controlled remotely through commodity computers, often directly or indirectly connected to the Internet. Therefore, many of these systems are currently exposed to threats similar to those endured by normal computer-based networks on the Internet, but the impact of failure of the former can be much higher to society. This paper presents a demonstration of a family of protection devices for critical information infrastructures developed in the context of the EU Crutial project. These devices, called Crutial information switches (CIS), enforce sophisticated access control policies of incoming/outgoing traffic, and are themselves designed with a range of different levels of intrusion tolerance and self healing, to serve different resilience requirements. Paulo Sousa 0001, Alysson Neves Bessani, Wagner Saback Dantas, Fabio Souto, Miguel Correia 0001, Nuno Neves 0001 |
DSN | 1 |
| 2007 | Resilient Intrusion Tolerance through Proactive and Reactive RecoveryabstractPrevious works have studied how to use proactive recovery to build intrusion-tolerant replicated systems that are resilient to any number of faults, as long as recoveries are faster than an upper-bound on fault production assumed at system deployment time. In this paper, we propose a complementary approach that combines proactive recovery with services that allow correct replicas to react and recover replicas that they detect or suspect to be compromised. One key feature of our proactive-reactive recovery approach is that, despite recoveries, it guarantees the availability of the minimum amount of system replicas necessary to sustain system's correct operation. We design a proactive-reactive recovery service based on a hybrid distributed system model and show, as a case study, how this service can effectively be used to augment the resilience of an intrusion-tolerant firewall adequate for the protection of critical infrastructures. Paulo Sousa 0001, Alysson Neves Bessani, Miguel Correia 0001, Nuno Neves 0001, Paulo Veríssimo |
PRDC | 1 |
| 2006 | Proactive Resilience Revisited: The Delicate Balance Between Resisting Intrusions and Remaining AvailableabstractIn a recent paper, we presented proactive resilience as a new approach to proactive recovery, based on architectural hybridization. We showed that, with appropriate assumptions about fault rate, proactive resilience makes it possible to build distributed intrusion-tolerant systems guaranteed not to suffer more than the assumed number of faults during their lifetime. In this paper, we explore the impact of these assumptions in asynchronous systems, and derive conditions that should be met by practical systems in order to guarantee long-lived, i.e., available, intrusion-tolerant operation. Our conclusions are based on analytical and simulation results as implemented in Mobius, and we use the same modeling environment to show that our approach offers higher resilience in comparison with other proactive intrusion-tolerant system models Paulo Sousa 0001, Nuno Neves 0001, Paulo Veríssimo, William H. Sanders |
SRDS | 1 |
| 2005 | How Resilient are Distributed f Fault/Intrusion-Tolerant Systems?abstractFault-tolerant protocols, asynchronous and synchronous alike, make stationary fault assumptions: only a fraction f of the total n nodes may fail. Whilst a synchronous protocol is expected to have a bounded execution time, an asynchronous one may execute for an arbitrary amount of time, possibly sufficient for f+1 nodes to fail. This can compromise the safety of the protocol and ultimately the safety of the system. Recent papers propose asynchronous protocols that can tolerate any number of faults over the lifetime of the system, provided that at most f nodes become faulty during a given interval. This is achieved through the so-called proactive recovery, which consists of periodically rejuvenating the system. Proactive recovery in asynchronous systems, though a major breakthrough, has some limitations which had not been identified before. In this paper, we introduce a system model expressive enough to represent these problems which remained in oblivion with the classical models. We introduce the predicate exhaustion-safe, meaning freedom from exhaustion-failures. Based on it, we predict the extent to which fault/intrusion-tolerant distributed systems (synchronous and asynchronous) can be made to work correctly. Namely, our model predicts the impossibility of guaranteeing correct behavior of asynchronous proactive recovery systems as exist today. To prove our point, we give an example of how these problems impact an existing fault/intrusion-tolerant distributed system, the CODEX system, and having identified the problem, we suggest one (certainly not the only) way to tackle it. Paulo Sousa 0001, Nuno Neves 0001, Paulo Veríssimo |
DSN | 1 |
| 2005 | Resilient State Machine ReplicationabstractNowadays, one of the major concerns about the services provided over the Internet is related to their availability. Replication is a well known way to increase the availability of a service. However, replication has some associated costs, namely it is necessary to guarantee a correct coordination among the replicas. Moreover, being the Internet such an unpredictable and insecure environment, coordination correctness should be tolerant to Byzantine faults and immune to timing failures. Several past works address agreement and replication techniques that tolerate Byzantine faults under the asynchronous model, but they all make the assumption that the number of faulty replicas is bounded and known. Assuming a maximum number of f faulty replicas under the asynchronous model is dangerous - there is no way of guaranteeing that no more than f faults will occur during the execution of the system. In this paper, we describe a resilient f fault/intrusion-tolerant state machine replication system, which guarantees that no more than f faults ever occur. The system is asynchronous in its most part and it resorts to a synchronous oracle to periodically remove the effects of faults/attacks from the replicas. Paulo Sousa 0001, Nuno Neves 0001, Paulo Veríssimo |
PRDC | 1 |
| 2004 | Dependable Adaptive Real-Time Applications in Wormhole-based SystemsabstractThis paper describes and discusses the work carried on in the context of the CORTEX project, for the development of adaptive real-time applications in wormhole based systems. The architecture of CORTEX relies on the existence of a timeliness wormhole, called timely computing base (TCB), which we have described in previous papers. Here we focus on the practical demonstration of the wormhole concept, through a demo with two complementary facets. The objective is to illustrate the effectiveness of the concept from a practical, yet rigorous, perspective, which is done with the help of an emulation framework that we present in the paper. Furthermore, the paper also describes two different ways of implementing timeliness wormholes on top of both wired and wireless infrastructures. Paulo Sousa 0001, António Casimiro, Paulo Veríssimo |
DSN | 2 |