Change search
Link to record
Permanent link

Direct link
Publications (10 of 27) Show all publications
Svenningsson, J., Paladi, N. & Vahidi, A. (2022). SGX-Bundler: speeding up enclave transitions for IO-intensive applications. In: Proceedings - 22nd IEEE/ACM International Symposium on Cluster, Cloud and Internet Computing, CCGrid 2022: . Paper presented at 22nd IEEE/ACM International Symposium on Cluster, Cloud and Internet Computing, CCGrid 2022, 16 May 2022 through 19 May 2022 (pp. 269-278). Institute of Electrical and Electronics Engineers Inc.
Open this publication in new window or tab >>SGX-Bundler: speeding up enclave transitions for IO-intensive applications
2022 (English)In: Proceedings - 22nd IEEE/ACM International Symposium on Cluster, Cloud and Internet Computing, CCGrid 2022, Institute of Electrical and Electronics Engineers Inc. , 2022, p. 269-278Conference paper, Published paper (Refereed)
Abstract [en]

Process-based confidential computing enclaves such as Intel SGX can be used to protect the confidentiality and integrity of workloads, without the overhead of virtualisation. However, they introduce a notable performance overhead, especially when it comes to transitions in and out of the enclave context. Such overhead makes the use of enclaves impractical for running IO-intensive applications, such as network packet processing or biological sequence analysis. We build on earlier approaches to improve the IO performance of work-loads in Intel SGX enclaves and propose the SGX-Bundler library, which helps reduce the cost of both individual single enclave transitions well as of the total number of enclave transitions in trusted applications running in Intel SGX enclaves. We describe the implementation of the SGX-Bundler library, evaluate its performance and demonstrate its practicality using the case study of Open vSwitch, a widely used software switch implementation. 

Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers Inc., 2022
Keywords
Hardware security, Open vSwitch, Performance optimization, SGX, Biological sequence analysis, Network packets, Packet processing, Performance, Performance optimizations, Process-based, Virtualizations, Work loads
National Category
Computer and Information Sciences
Identifiers
urn:nbn:se:ri:diva-60063 (URN)10.1109/CCGrid54584.2022.00036 (DOI)2-s2.0-85135761247 (Scopus ID)9781665499569 (ISBN)
Conference
22nd IEEE/ACM International Symposium on Cluster, Cloud and Internet Computing, CCGrid 2022, 16 May 2022 through 19 May 2022
Note

Funding details: Stiftelsen för Strategisk Forskning, SSF, RIT17-0035; Funding text 1: This paper was partially supported by the Swedish Foundation for Strategic Research, grant RIT17-0035.

Available from: 2022-10-10 Created: 2022-10-10 Last updated: 2025-09-23Bibliographically approved
Guanciale, R., Paladi, N. & Vahidi, A. (2022). SoK: Confidential Quartet - Comparison of Platforms for Virtualization-Based Confidential Computing. In: Proceedings - 2022 IEEE International Symposium on Secure and Private Execution Environment Design, SEED 2022: . Paper presented at 2022 IEEE International Symposium on Secure and Private Execution Environment Design, SEED 2022, 26 September 2022 through 27 September 2022 (pp. 109-120). Institute of Electrical and Electronics Engineers Inc.
Open this publication in new window or tab >>SoK: Confidential Quartet - Comparison of Platforms for Virtualization-Based Confidential Computing
2022 (English)In: Proceedings - 2022 IEEE International Symposium on Secure and Private Execution Environment Design, SEED 2022, Institute of Electrical and Electronics Engineers Inc. , 2022, p. 109-120Conference paper, Published paper (Refereed)
Abstract [en]

Confidential computing allows processing sensitive workloads in securely isolated spaces. Following earlier adoption of process-based approaches to isolation, vendors are now enabling hardware and firmware support for virtualization-based confidential computing on several server platforms. Due to variations in the technology stack, threat model, implementation and functionality, the available solutions offer somewhat different capabilities, trade-offs and security guarantees. In this paper we review, compare and contextualize four virtualization-based confidential computing technologies for enterprise server platforms - AMD SEV, ARM CCA, IBM PEF and Intel TDX. 

Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers Inc., 2022
Keywords
Confidential Computing, Economic and social effects, Virtual reality, Virtualization, Computing technology, Contextualize, Enterprise servers, Model implementation, Process-based approach, Server platform, Threat modeling, Trade off, Virtualizations, Firmware
National Category
Computer Sciences
Identifiers
urn:nbn:se:ri:diva-61597 (URN)10.1109/SEED55351.2022.00017 (DOI)2-s2.0-85143079315 (Scopus ID)9781665485265 (ISBN)
Conference
2022 IEEE International Symposium on Secure and Private Execution Environment Design, SEED 2022, 26 September 2022 through 27 September 2022
Note

Funding details: Stiftelsen för Strategisk Forskning, SSF, RIT17-0035; Funding details: VINNOVA, 2021-01690; Funding text 1: We would like to thank our shepherd and the anonymous reviewers for the helpful comments. This work was supported in part by the VINNOVA grant 2021-01690 for the project CEST (Confidential Evaluation of Software Trustworthiness) and by the Swedish Foundation for Strategic Research, grant RIT17-0035.

Available from: 2022-12-21 Created: 2022-12-21 Last updated: 2025-09-23Bibliographically approved
Marsh, I., Paladi, N., Abrahamsson, H., Gustafsson, J., Sjöberg, J., Johnsson, A., . . . Amiribesheli, M. (2021). Evolving 5G: ANIARA, an edge-cloud perspective. In: CF '21: Proceedings of the 18th ACM International Conference on Computing FrontiersMay 2021: . Paper presented at CF '21: 18th ACM International Conference on Computing FrontiersMay 2021 (pp. 206-207). Association for Computing Machinery
Open this publication in new window or tab >>Evolving 5G: ANIARA, an edge-cloud perspective
Show others...
2021 (English)In: CF '21: Proceedings of the 18th ACM International Conference on Computing FrontiersMay 2021, Association for Computing Machinery , 2021, p. 206-207Conference paper, Published paper (Refereed)
Abstract [en]

ANIARA (https://www.celticnext.eu/project-ai-net) attempts to enhance edge architectures for smart manufacturing and cities. AI automation, orchestrated lightweight containers, and efficient power usage are key components of this three-year project. Edge infrastructure, virtualization, and containerization in future telecom systems enable new and more demanding use cases for telecom operators and industrial verticals. Increased service flexibility adds complexity that must be addressed with novel management and orchestration systems. To address this, ANIARA will provide en-ablers and solutions for services in the domains of smart cities and manufacturing deployed and operated at the network edge(s).

Place, publisher, year, edition, pages
Association for Computing Machinery, 2021
National Category
Communication Systems
Identifiers
urn:nbn:se:ri:diva-58315 (URN)10.1145/3457388.3458622 (DOI)
Conference
CF '21: 18th ACM International Conference on Computing FrontiersMay 2021
Available from: 2022-01-24 Created: 2022-01-24 Last updated: 2025-09-23Bibliographically approved
Marsh, I., Paladi, N., Abrahamsson, H., Gustafsson, J., Sjöberg, J., Johnsson, A., . . . Amiribesheli, M. (2021). Evolving 5G: ANIARA, an edge-cloud perspective. In: Proceedings of the 18th ACM International Conference on Computing Frontiers 2021, CF 2021: . Paper presented at 18th ACM International Conference on Computing Frontiers 2021, CF 2021, 11 May 2021 through 13 May 2021 (pp. 206-207). Association for Computing Machinery, Inc
Open this publication in new window or tab >>Evolving 5G: ANIARA, an edge-cloud perspective
Show others...
2021 (English)In: Proceedings of the 18th ACM International Conference on Computing Frontiers 2021, CF 2021, Association for Computing Machinery, Inc , 2021, p. 206-207Conference paper, Published paper (Refereed)
Abstract [en]

ANIARA (https://www.celticnext.eu/project-ai-net) attempts to enhance edge architectures for smart manufacturing and cities. AI automation, orchestrated lightweight containers, and efficient power usage are key components of this three-year project. Edge infrastructure, virtualization, and containerization in future telecom systems enable new and more demanding use cases for telecom operators and industrial verticals. Increased service flexibility adds complexity that must be addressed with novel management and orchestration systems. To address this, ANIARA will provide en-ablers and solutions for services in the domains of smart cities and manufacturing deployed and operated at the network edge(s). © 2021 Owner/Author.

Place, publisher, year, edition, pages
Association for Computing Machinery, Inc, 2021
Keywords
AI, container tech, edge comp, energy metering, orchestration, Containers, Manufacture, EDGE architectures, Edge clouds, Efficient power, Network edges, Service flexibility, Smart manufacturing, Telecom operators, Telecom systems, 5G mobile communication systems
National Category
Communication Systems
Identifiers
urn:nbn:se:ri:diva-53472 (URN)10.1145/3457388.3458622 (DOI)2-s2.0-85106011241 (Scopus ID)9781450384049 (ISBN)
Conference
18th ACM International Conference on Computing Frontiers 2021, CF 2021, 11 May 2021 through 13 May 2021
Available from: 2021-06-14 Created: 2021-06-14 Last updated: 2025-09-23Bibliographically approved
Paladi, N., Tiloca, M., Nikbakht Bideh, P. & Hell, M. (2021). Flowrider: Fast On-Demand Key Provisioning for Cloud Networks. In: International Conference on Security and Privacy in Communication SystemsSecureComm 2021: Security and Privacy in Communication Networks pp 207-228: . Paper presented at International Conference on Security and Privacy in Communication SystemsSecureComm 2021. 6 September 2021 through 9 September 2021 (pp. 207-228). Springer Science and Business Media Deutschland GmbH
Open this publication in new window or tab >>Flowrider: Fast On-Demand Key Provisioning for Cloud Networks
2021 (English)In: International Conference on Security and Privacy in Communication SystemsSecureComm 2021: Security and Privacy in Communication Networks pp 207-228, Springer Science and Business Media Deutschland GmbH , 2021, p. 207-228Conference paper, Published paper (Refereed)
Abstract [en]

Increasingly fine-grained cloud billing creates incentives to review the software execution footprint in virtual environments. For example, virtual execution environments move towards lower overhead: from virtual machines to containers, unikernels, and serverless cloud computing. However, the execution footprint of security components in virtualized environments has either remained the same or even increased. We present Flowrider, a novel key provisioning mechanism for cloud networks that unlocks scalable use of symmetric keys and significantly reduces the related computational load on network endpoints. We describe the application of Flowrider to common transport security protocols, the results of its formal verification, and its prototype implementation. Our evaluation shows that Florwider uses up to an order of magnitude less CPU to establish a TLS session while preventing by construction some known attacks.

Place, publisher, year, edition, pages
Springer Science and Business Media Deutschland GmbH, 2021
Keywords
Cloud security, Key management, Network security, Secure communication, Software defined networking, Cloud computing, Cloud data security, Virtual reality, Cloud networks, Cloud securities, Fine grained, Key-management, Low overhead, Networks security, On demands, Software execution, Software-defined networkings, Virtual execution environments
National Category
Computer Systems
Identifiers
urn:nbn:se:ri:diva-57358 (URN)10.1007/978-3-030-90022-9_11 (DOI)2-s2.0-85120078340 (Scopus ID)9783030900212 (ISBN)
Conference
International Conference on Security and Privacy in Communication SystemsSecureComm 2021. 6 September 2021 through 9 September 2021
Note

Funding details: 952652; Funding details: Horizon 2020 Framework Programme, H2020; Funding details: Stiftelsen för Strategisk Forskning, SSF, RIT17-0035; Funding details: VINNOVA; Funding text 1: Acknowledgments. This work was financially supported in part by the Swedish Foundation for Strategic Research, with the grant RIT17-0035; by the H2020 project SIFIS-Home (Grant agreement 952652); VINNOVA and the CelticNext project CRI-TISEC and by the Wallenberg AI, Autonomous Systems and Software Program (WASP).

Available from: 2021-12-29 Created: 2021-12-29 Last updated: 2025-09-23Bibliographically approved
Paladi, N., Tiloca, M., Bideh, P. & Hell, M. (2021). On-demand Key Distribution for Cloud Networks. In: 2021 24th Conference on Innovation in Clouds, Internet and Networks and Workshops, ICIN 2021: . Paper presented at 24th Conference on Innovation in Clouds, Internet and Networks and Workshops, ICIN 2021, 1 March 2021 through 4 March 2021 (pp. 80-82). Institute of Electrical and Electronics Engineers Inc.
Open this publication in new window or tab >>On-demand Key Distribution for Cloud Networks
2021 (English)In: 2021 24th Conference on Innovation in Clouds, Internet and Networks and Workshops, ICIN 2021, Institute of Electrical and Electronics Engineers Inc. , 2021, p. 80-82Conference paper, Published paper (Refereed)
Abstract [en]

Emerging fine-grained cloud resource billing creates incentives to review the software execution footprint in virtual environments. Operators can use novel virtual execution environments with ever lower overhead: from virtual machines to containers, to unikernels and serverless functions. However, the execution footprint of security mechanisms in virtualized deployments has either remained the same or even increased. In this demo, we present a novel key provisioning mechanism for cloud networks that unlocks scalable use of symmetric keys and significantly reduces the related computational load on network endpoints

Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers Inc., 2021
Keywords
Computer networks, Information systems, Cloud networks, Computational loads, Fine grained, Key distribution, Security mechanism, Software execution, Symmetric keys, Virtual execution environments, Network security
National Category
Computer Systems
Identifiers
urn:nbn:se:ri:diva-53021 (URN)10.1109/ICIN51074.2021.9385528 (DOI)2-s2.0-85104189111 (Scopus ID)9781728177052 (ISBN)
Conference
24th Conference on Innovation in Clouds, Internet and Networks and Workshops, ICIN 2021, 1 March 2021 through 4 March 2021
Note

Funding details: 826093, 952652; Funding details: Horizon 2020 Framework Programme, H2020; Funding details: Stiftelsen för Strategisk Forskning, SSF, RTT17-0035; Funding details: VINNOVA; Funding text 1: This work was supported in part by the Swedish Foundation for Strategic Research, grant RTT17-0035; by VINNOVA and the Celtic-Next project C.RITISEC; by the H2020 projects SIFIS-Homc and ASC.LEPIOS (Grant agreements 952652 and 826093); and by the Wallenberg AI, Autonomous Systems and Software Program (WASP)

Available from: 2021-05-25 Created: 2021-05-25 Last updated: 2025-09-23Bibliographically approved
Paladi, N. & Gehrmann, C. (2019). SDN Access Control for the Masses. Computers & Security, 80, 155-172
Open this publication in new window or tab >>SDN Access Control for the Masses
2019 (English)In: Computers & Security, ISSN 0167-4048, E-ISSN 1872-6208, Vol. 80, p. 155-172Article in journal (Refereed) Published
Abstract [en]

The evolution of Software-Defined Networking (SDN) has so far been predominantly geared towards defining and refining the abstractions on the forwarding and control planes. However, despite a maturing south-bound interface and a range of proposed network operating systems, the network management application layer is yet to be specified and standardized. It has currently poorly defined access control mechanisms that could be exposed to network applications. Available mechanisms allow only rudimentary control and lack procedures to partition resource access across multiple dimensions. We address this by extending the SDN north-bound interface to provide control over shared resources to key stakeholders of network infrastructure: network providers, operators and application developers. We introduce a taxonomy of SDN access models, describe a comprehensive design for SDN access control and implement the proposed solution as an extension of the ONOS network controller intent framework.

Place, publisher, year, edition, pages
Elsevier Ltd, 2019
Keywords
Access control, Network abstractions, North-bound interface, Security, Software-defined networking, Abstracting, Flight control systems, Network layers, Software defined networking, Access control mechanism, Application developers, Management applications, Network infrastructure, Network operating system, Software defined networking (SDN)
National Category
Natural Sciences
Identifiers
urn:nbn:se:ri:diva-35566 (URN)10.1016/j.cose.2018.10.003 (DOI)2-s2.0-85054899526 (Scopus ID)
Note

Funding details: 731574; Funding text: The research was conducted within the COLA project and received funding from the European Union’s Horizon 2020 research and innovation programme under grant No 731574.

Available from: 2018-11-06 Created: 2018-11-06 Last updated: 2025-09-23Bibliographically approved
Nikbakht Bideh, P., Paladi, N. & Hell, M. (2019). Software-Defined Networking for Emergency Traffic Management in Smart Cities. In: 3rd International Workshop on Vehicular Ad-hoc Networks for Smart Cities, IWVSC 2019 (Vehicular Ad-hoc Networks for Smart Cities): . Paper presented at 3rd International Workshop on Vehicular Ad-hoc Networks for Smart Cities, IWVSC 2019. 13 November 2019 through 13 November 2019 (pp. 59-70). Springer
Open this publication in new window or tab >>Software-Defined Networking for Emergency Traffic Management in Smart Cities
2019 (English)In: 3rd International Workshop on Vehicular Ad-hoc Networks for Smart Cities, IWVSC 2019 (Vehicular Ad-hoc Networks for Smart Cities), Springer , 2019, p. 59-70Conference paper, Published paper (Refereed)
Abstract [en]

Vehicle traffic management is becoming more complex due to increased traffic density in cities. Novel solutions are necessary for emergency vehicles, which despite growing congestion must be able to quickly reach their destination. Emergency vehicles are usually equipped with transmitters to control the traffic lights on their path and warn other vehicles with sirens. Transmitters are operated manually and, like sirens, have a limited range. Smart cities can make use of novel network models to facilitate traffic management. In this paper, we design a traffic management application leveraging software-defined network controllers for traffic preemption. The proposed application leverages the logical centralization of the SDN control plane to improve traffic management. Results from evaluating the application under five different scenarios indicate that emergency vehicles can reach their destination much faster, with very little effect on the surrounding traffic. 

Place, publisher, year, edition, pages
Springer, 2019
Keywords
Application programs, Emergency traffic control, Emergency vehicles, Signaling, Smart city, Software defined networking, Traffic congestion, Transmitters, Control planes, Emergency traffic management, Network models, Novel solutions, Traffic densities, Traffic light, Traffic management, Vehicle traffic, Vehicular ad hoc networks
National Category
Natural Sciences
Identifiers
urn:nbn:se:ri:diva-45094 (URN)10.1007/978-981-15-3750-9_5 (DOI)2-s2.0-85084924409 (Scopus ID)9789811537493 (ISBN)
Conference
3rd International Workshop on Vehicular Ad-hoc Networks for Smart Cities, IWVSC 2019. 13 November 2019 through 13 November 2019
Note

Funding details: Stiftelsen för Strategisk Forskning, SSF, RIT17-0035; Funding text 1: This paper was partially supported by the Swedish Foundation for Strategic Research, grant RIT17-0035, and partially supported by the Wallenberg Autonomous Systems and Software Program (WASP).

Available from: 2020-07-02 Created: 2020-07-02 Last updated: 2025-09-23Bibliographically approved
Paladi, N., Michalas, A. & Hai-Van, D. (2018). Towards Secure Cloud Orchestration for Multi-Cloud Deployments. In: CrossCloud 2018 - 5th Workshop on CrossCloud Infrastructures and Platforms, colocated with EuroSys 2018: . Paper presented at 5th Workshop on CrossCloud Infrastructures and Platforms, CrossCloud 2018; Porto; Portugal; 23 April 2018 through 23 April 2018.
Open this publication in new window or tab >>Towards Secure Cloud Orchestration for Multi-Cloud Deployments
2018 (English)In: CrossCloud 2018 - 5th Workshop on CrossCloud Infrastructures and Platforms, colocated with EuroSys 2018, 2018Conference paper, Published paper (Refereed)
Abstract [en]

Cloud orchestration frameworks are commonly used to deploy and operate cloud infrastructure. Their role spans both vertically (deployment on infrastructure, platform, application and microservice levels) and horizontally (deployments from many distinct cloud resource providers). However, despite the central role of orchestration, the popular orchestration frameworks lack mechanisms to provide security guarantees for cloud operators. In this work, we analyze the security landscape of cloud orchestration frameworks for multicloud infrastructure. We identify a set of attack scenarios, define security enforcement enablers and propose an architecture for a security-enabled cloud orchestration framework for multi-cloud application deployments.

Keywords
cloud, security, orchestration
National Category
Computer Systems
Identifiers
urn:nbn:se:ri:diva-33491 (URN)10.1145/3195870.3195874 (DOI)2-s2.0-85049685222 (Scopus ID)
Conference
5th Workshop on CrossCloud Infrastructures and Platforms, CrossCloud 2018; Porto; Portugal; 23 April 2018 through 23 April 2018
Funder
EU, Horizon 2020, 731574
Available from: 2018-03-16 Created: 2018-03-16 Last updated: 2025-09-23Bibliographically approved
Paladi, N., Karlsson, L. & Elbashir, K. (2018). Trust Anchors in Software Defined Networks. In: Javier Lopez · Jianying Zhou Miguel Soriano (Ed.), Computer Security: 23rd European Symposium on Research in Computer Security, ESORICS 2018 Barcelona, Spain, September 3–7, 2018, Proceedings, Part II. Paper presented at ESORICS (pp. 485-594). Springer, 11099
Open this publication in new window or tab >>Trust Anchors in Software Defined Networks
2018 (English)In: Computer Security: 23rd European Symposium on Research in Computer Security, ESORICS 2018 Barcelona, Spain, September 3–7, 2018, Proceedings, Part II / [ed] Javier Lopez · Jianying Zhou Miguel Soriano, Springer, 2018, Vol. 11099, p. 485-594Conference paper, Published paper (Refereed)
Abstract [en]

Advances in software virtualization and network processing lead to increasing network softwarization. Software network elements running on commodity platforms replace or complement hardware com- ponents in cloud and mobile network infrastructure. However, such com- modity platforms have a large attack surface and often lack granular control and tight integration of the underlying hardware and software stack. Often, software network elements are either themselves vulnerable to software attacks or can be compromised through the bloated trusted computing base. To address this, we protect the core security assets of network elements - authentication credentials and cryptographic context - by provisioning them to and maintaining them exclusively in isolated execution environments. We complement this with a secure and scalable mechanism to enroll network elements into software defined networks. Our evaluation results show a negligible impact on run-time performance and only a moderate performance impact at the deployment stage.

Place, publisher, year, edition, pages
Springer, 2018
Keywords
Software Defined Networking, Software Guard Extensions, Open vSwitch, Network Function Virtualization
National Category
Computer Systems
Identifiers
urn:nbn:se:ri:diva-35117 (URN)10.1007/978-3-319-98989-1_24 (DOI)2-s2.0-85051855924 (Scopus ID)978-3-319-98988-4 (ISBN)
Conference
ESORICS
Funder
EU, European Research Council, 731574
Available from: 2018-09-05 Created: 2018-09-05 Last updated: 2025-09-23Bibliographically approved
Organisations
Identifiers
ORCID iD: ORCID iD iconorcid.org/0000-0003-0132-857x

Search in DiVA

Show all publications