The Experts below are selected from a list of 258 Experts worldwide ranked by ideXlab platform

Thomas Reps - One of the best experts on this subject based on the ideXlab platform.

  • Weighted pushdown systems and trust-management systems
    Lecture Notes in Computer Science, 2006
    Co-Authors: Somesh Jha, Stefan Schwoon, Hao Wang, Thomas Reps
    Abstract:

    The authorization problem is to decide whether, according to a security policy, some principal should be allowed access to a resource. In the trust-management system SPKI/SDSI, the security policy is given by a set of Certificates, and proofs of authorization take the form of Certificate Chains. The Certificate-Chain-discovery problem is to discover a proof of authorization for a given request. Certificate-Chain-discovery algorithms for SPKI/SDSI have been investigated by several researchers. We consider a variant of the Certificate-Chain discovery problem where the Certificates are distributed over a number of servers, which then have to cooperate to identify the proof of authorization for a given request. We propose two protocols for this purpose. These protocols are based on distributed model-checking algorithms for weighted pushdown systems (WPDSs). These protocols can also handle cases where Certificates are labeled with weights and where multiple Certificate Chains must be combined to form a proof of authorization. We have implemented these protocols in a prototype and report preliminary results of our evaluation.

  • TACAS - Weighted pushdown systems and trust-management systems
    Tools and Algorithms for the Construction and Analysis of Systems, 2006
    Co-Authors: Somesh Jha, Stefan Schwoon, Hao Wang, Thomas Reps
    Abstract:

    The authorization problem is to decide whether, according to a security policy, some principal should be allowed access to a resource. In the trust-management system SPKI/SDSI, the security policy is given by a set of Certificates, and proofs of authorization take the form of Certificate Chains. The Certificate-Chain-discovery problem is to discover a proof of authorization for a given request. Certificate-Chain-discovery algorithms for SPKI/SDSI have been investigated by several researchers. We consider a variant of the Certificate-Chain discovery problem where the Certificates are distributed over a number of servers, which then have to cooperate to identify the proof of authorization for a given request. We propose two protocols for this purpose. These protocols are based on distributed model-checking algorithms for weighted pushdown systems (WPDSs). These protocols can also handle cases where Certificates are labeled with weights and where multiple Certificate Chains must be combined to form a proof of authorization. We have implemented these protocols in a prototype and report preliminary results of our evaluation.

Somesh Jha - One of the best experts on this subject based on the ideXlab platform.

  • Weighted pushdown systems and trust-management systems
    Lecture Notes in Computer Science, 2006
    Co-Authors: Somesh Jha, Stefan Schwoon, Hao Wang, Thomas Reps
    Abstract:

    The authorization problem is to decide whether, according to a security policy, some principal should be allowed access to a resource. In the trust-management system SPKI/SDSI, the security policy is given by a set of Certificates, and proofs of authorization take the form of Certificate Chains. The Certificate-Chain-discovery problem is to discover a proof of authorization for a given request. Certificate-Chain-discovery algorithms for SPKI/SDSI have been investigated by several researchers. We consider a variant of the Certificate-Chain discovery problem where the Certificates are distributed over a number of servers, which then have to cooperate to identify the proof of authorization for a given request. We propose two protocols for this purpose. These protocols are based on distributed model-checking algorithms for weighted pushdown systems (WPDSs). These protocols can also handle cases where Certificates are labeled with weights and where multiple Certificate Chains must be combined to form a proof of authorization. We have implemented these protocols in a prototype and report preliminary results of our evaluation.

  • TACAS - Weighted pushdown systems and trust-management systems
    Tools and Algorithms for the Construction and Analysis of Systems, 2006
    Co-Authors: Somesh Jha, Stefan Schwoon, Hao Wang, Thomas Reps
    Abstract:

    The authorization problem is to decide whether, according to a security policy, some principal should be allowed access to a resource. In the trust-management system SPKI/SDSI, the security policy is given by a set of Certificates, and proofs of authorization take the form of Certificate Chains. The Certificate-Chain-discovery problem is to discover a proof of authorization for a given request. Certificate-Chain-discovery algorithms for SPKI/SDSI have been investigated by several researchers. We consider a variant of the Certificate-Chain discovery problem where the Certificates are distributed over a number of servers, which then have to cooperate to identify the proof of authorization for a given request. We propose two protocols for this purpose. These protocols are based on distributed model-checking algorithms for weighted pushdown systems (WPDSs). These protocols can also handle cases where Certificates are labeled with weights and where multiple Certificate Chains must be combined to form a proof of authorization. We have implemented these protocols in a prototype and report preliminary results of our evaluation.

Jordi Forné - One of the best experts on this subject based on the ideXlab platform.

  • Revocation Scheme for PMI Based Upon the Tracing of Certificates Chains
    Lecture Notes in Computer Science, 2006
    Co-Authors: M. Francisca Hinarejos, Jordi Forné
    Abstract:

    Public Key Infrastructure (PKI) and Privilege Management Infrastructure (PMI) can respectively be used to support authentication and authorization in distributed scenarios. The validation of Certificate Chains is a critical issue in both infrastructures, because it requires several costly processes, such as Certificate path discovery, validation of each Certificate, and so on. The problem becomes even worst in devices with limited resources (battery, memory, computational capacity, etc.) as mobile devices. In this paper we present an architecture that reduces the communication and computational overhead of Certificate status checking in a complete Certificate Chain. The proposed tracing of the Certificates Chains is based on a cascade Certificate revocation policy.

  • ICCSA (4) - Revocation scheme for PMI based upon the tracing of Certificates Chains
    Computational Science and Its Applications - ICCSA 2006, 2006
    Co-Authors: M. Francisca Hinarejos, Jordi Forné
    Abstract:

    Public Key Infrastructure (PKI) and Privilege Management Infrastructure (PMI) can respectively be used to support authentication and authorization in distributed scenarios. The validation of Certificate Chains is a critical issue in both infrastructures, because it requires several costly processes, such as Certificate path discovery, validation of each Certificate, and so on. The problem becomes even worst in devices with limited resources (battery, memory, computational capacity, etc.) as mobile devices. In this paper we present an architecture that reduces the communication and computational overhead of Certificate status checking in a complete Certificate Chain. The proposed tracing of the Certificates Chains is based on a cascade Certificate revocation policy.

Stefan Schwoon - One of the best experts on this subject based on the ideXlab platform.

  • Weighted pushdown systems and trust-management systems
    Lecture Notes in Computer Science, 2006
    Co-Authors: Somesh Jha, Stefan Schwoon, Hao Wang, Thomas Reps
    Abstract:

    The authorization problem is to decide whether, according to a security policy, some principal should be allowed access to a resource. In the trust-management system SPKI/SDSI, the security policy is given by a set of Certificates, and proofs of authorization take the form of Certificate Chains. The Certificate-Chain-discovery problem is to discover a proof of authorization for a given request. Certificate-Chain-discovery algorithms for SPKI/SDSI have been investigated by several researchers. We consider a variant of the Certificate-Chain discovery problem where the Certificates are distributed over a number of servers, which then have to cooperate to identify the proof of authorization for a given request. We propose two protocols for this purpose. These protocols are based on distributed model-checking algorithms for weighted pushdown systems (WPDSs). These protocols can also handle cases where Certificates are labeled with weights and where multiple Certificate Chains must be combined to form a proof of authorization. We have implemented these protocols in a prototype and report preliminary results of our evaluation.

  • TACAS - Weighted pushdown systems and trust-management systems
    Tools and Algorithms for the Construction and Analysis of Systems, 2006
    Co-Authors: Somesh Jha, Stefan Schwoon, Hao Wang, Thomas Reps
    Abstract:

    The authorization problem is to decide whether, according to a security policy, some principal should be allowed access to a resource. In the trust-management system SPKI/SDSI, the security policy is given by a set of Certificates, and proofs of authorization take the form of Certificate Chains. The Certificate-Chain-discovery problem is to discover a proof of authorization for a given request. Certificate-Chain-discovery algorithms for SPKI/SDSI have been investigated by several researchers. We consider a variant of the Certificate-Chain discovery problem where the Certificates are distributed over a number of servers, which then have to cooperate to identify the proof of authorization for a given request. We propose two protocols for this purpose. These protocols are based on distributed model-checking algorithms for weighted pushdown systems (WPDSs). These protocols can also handle cases where Certificates are labeled with weights and where multiple Certificate Chains must be combined to form a proof of authorization. We have implemented these protocols in a prototype and report preliminary results of our evaluation.

  • Efficient algorithms for alternating pushdown systems : application to Certificate Chain discovery with threshold subjects
    2006
    Co-Authors: Dejvuth Suwimonteerabuth, Stefan Schwoon, Javier Esparza
    Abstract:

    Motivated by recent applications of pushdown systems to computer security problems, we present an efficient algorithm for the reachability problem of alternating pushdown systems. Although the algorithm is exponential, a careful analysis reveals that the exponent is usually small in typical applications. We show that the algorithm can be used to compute winning regions in pushdown games. In a second contribution, we observe that the algorithm runs in polynomial time for a certain subproblem, and show that the computation of Certificate Chains with threshold Certificates in the SPKI/SDSI authorization framework can be reduced to this subproblem. We present a detailed complexity analysis of the algorithm and its application, and report on experimental results obtained with a prototype implementation.

Hao Wang - One of the best experts on this subject based on the ideXlab platform.

  • Weighted pushdown systems and trust-management systems
    Lecture Notes in Computer Science, 2006
    Co-Authors: Somesh Jha, Stefan Schwoon, Hao Wang, Thomas Reps
    Abstract:

    The authorization problem is to decide whether, according to a security policy, some principal should be allowed access to a resource. In the trust-management system SPKI/SDSI, the security policy is given by a set of Certificates, and proofs of authorization take the form of Certificate Chains. The Certificate-Chain-discovery problem is to discover a proof of authorization for a given request. Certificate-Chain-discovery algorithms for SPKI/SDSI have been investigated by several researchers. We consider a variant of the Certificate-Chain discovery problem where the Certificates are distributed over a number of servers, which then have to cooperate to identify the proof of authorization for a given request. We propose two protocols for this purpose. These protocols are based on distributed model-checking algorithms for weighted pushdown systems (WPDSs). These protocols can also handle cases where Certificates are labeled with weights and where multiple Certificate Chains must be combined to form a proof of authorization. We have implemented these protocols in a prototype and report preliminary results of our evaluation.

  • TACAS - Weighted pushdown systems and trust-management systems
    Tools and Algorithms for the Construction and Analysis of Systems, 2006
    Co-Authors: Somesh Jha, Stefan Schwoon, Hao Wang, Thomas Reps
    Abstract:

    The authorization problem is to decide whether, according to a security policy, some principal should be allowed access to a resource. In the trust-management system SPKI/SDSI, the security policy is given by a set of Certificates, and proofs of authorization take the form of Certificate Chains. The Certificate-Chain-discovery problem is to discover a proof of authorization for a given request. Certificate-Chain-discovery algorithms for SPKI/SDSI have been investigated by several researchers. We consider a variant of the Certificate-Chain discovery problem where the Certificates are distributed over a number of servers, which then have to cooperate to identify the proof of authorization for a given request. We propose two protocols for this purpose. These protocols are based on distributed model-checking algorithms for weighted pushdown systems (WPDSs). These protocols can also handle cases where Certificates are labeled with weights and where multiple Certificate Chains must be combined to form a proof of authorization. We have implemented these protocols in a prototype and report preliminary results of our evaluation.