The Experts below are selected from a list of 657 Experts worldwide ranked by ideXlab platform
Harihodin Selamat - One of the best experts on this subject based on the ideXlab platform.
-
New IV-Based database encryption schemeusing TS block cipher
2004Co-Authors: Zailani Mohamad Sidek, Norbik Bashah Idris, Harihodin SelamatAbstract:Current database security research classify four types of Controls for the protection of data in databases: access Controls, information flow Controls, inference Controls, and Cryptographic Controls. This paper covers the fourth type of Controls, Cryptographic Controls in database security that provides security of data stored in commercial RDBMS like Oracle. The proposed database encryption scheme is based on TS Block and Stream Ciphers, and is capable of protecting data at the data element, row, and column levels using both block and stream encryptions. The design of the scheme’s key generation and management system allows the Controls of users’ access to encrypted data in a multilevel fashion thus provide multilevel security. The scheme solves the problem of mandatory and discretionary access Controls in a given organization. The security of the scheme is based on the fact that no Cryptographic keys are stored in the database system. All encryption and decryption keys are stored securely in smartcards thus providing minimum Cryptographic information to users. The design of the encryption scheme is based on the provably strong ciphers with 128-bit keys which is currently infeasible to be broken even by exhaustive key search. Implementation of the scheme has been conducted successfully in Oracle RDBMS and complements the Oracle encryption security available
-
A New IV-Based Database Encryption Scheme Using TS Block Cipher
Asia-Pacific Journal of Information Technology and Multimedia, 2004Co-Authors: Zailani Mohamed Sidek, Norbik Bashah Idris, Harihodin SelamatAbstract:Current database security research classify four types of Controls for the protection of data in databases: access Controls, information flow Controls, inference Controls, and Cryptographic Controls. This paper covers the fourth type of Controls, Cryptographic Controls in database security that provides security of data stored in commercial RDBMS like Oracle. The proposed database encryption scheme is based on TS Block and Stream Ciphers, and is capable of protecting data at the data element, row, and column levels using both block and stream encryptions. The design of the scheme's key generation and management system allows the Controls of users' access to encrypted data in a multilevel fashion thus provide multilevel security. The scheme solves the problem of mandatory and discretionary access Controls in a given organization. The security of the scheme is based on the fact that no Cryptographic keys are stored in the database system. All encryption and decryption keys are stored securely in smartcards thus providing minimum Cryptographic information to users. The design of the encryption scheme is based on the provably strong ciphers with 128-bit keys which is currently infeasible to be broken even by exhaustive key search. Implementation of the scheme has been conducted sudcessfully in Oracle RDBMS and complements the Oracle encryption security available.
-
New IV-Based database encryption scheme using TS block cipher
Penerbit UKM, 2004Co-Authors: Zailani Mohamad Sidek, Norbik Bashah Idris, Harihodin SelamatAbstract:Current database security research classify four types of Controls for the protection of data in databases: access Controls, information flow Controls, inference Controls, and Cryptographic Controls. This paper covers the fourth type of Controls, Cryptographic Controls in database security that provides security of data stored in commercial RDBMS like Oracle. The proposed database encryption scheme is based on TS Block and Stream Ciphers, and is capable of protecting data at the data element, row, and column levels using both block and stream encryptions. The design of the scheme’s key generation and management system allows the Controls of users’ access to encrypted data in a multilevel fashion thus provide multilevel security. The scheme solves the problem of mandatory and discretionary access Controls in a given organization. The security of the scheme is based on the fact that no Cryptographic keys are stored in the database system. All encryption and decryption keys are stored securely in smartcards thus providing minimum Cryptographic information to users. The design of the encryption scheme is based on the provably strong ciphers with 128-bit keys which is currently infeasible to be broken even by exhaustive key search. Implementation of the scheme has been conducted successfully in Oracle RDBMS and complements the Oracle encryption security availabl
Steven Hanna - One of the best experts on this subject based on the ideXlab platform.
-
HealthSec - Take two software updates and see me in the morning: the case for software security evaluations of medical devices
2011Co-Authors: Steven Hanna, Rolf Rolles, Andres Molina-markham, Pongsin Poosankam, Dawn SongAbstract:Medical devices used for critical care are becoming increasingly reliant on software; however, little is understood about the security vulnerabilities facing medical devices and their software. To investigate this open question, we analyze the security of software that Controls a modern Automated External Defibrillator (AED) used for treating cardiac arrhythmias. This report represents the first public embedded software security analysis of a medical device. We identify several software security vulnerabilities and discuss key insights and open challenges in improving software-controlled medical devices to be resistant to malware. We found the AED would accept counterfeit firmware updates. We did not locate any standard Cryptographic Controls. We conclude with recommendations and open challenges in securing medical devices.
-
Take two software updates and see me in the morning: The Case for Software Security Evaluations of Medical Devices
… on Health Security …, 2011Co-Authors: Steven HannaAbstract:Medical devices used for critical care are becoming increasingly reliant on software; however, little is understood about the security vulnerabilities facing medical devices and their software. To investigate this open question, we analyze the security of software that Controls a modern Automated External Defibrillator (AED) used for treating cardiac arrhythmias. This report represents the first public embedded software security analysis of a medical device. We identify several software security vulnerabilities and discuss key insights and open challenges in improving software-controlled medical devices to be resistant to malware. We found the AED would accept counterfeit firmware updates. We did not locate any standard Cryptographic Controls. We conclude with recommendations and open challenges in securing medical devices.
Radim Remeš - One of the best experts on this subject based on the ideXlab platform.
-
The proposal of software development and acquisition metrics based on ISO/IEC 27001 standard
2009Co-Authors: Ladislav Beránek, Radim RemešAbstract:The implementation and operation of efficient information security management systems (ISMS) according to the ISO/IEC 27001 standard involves a number of steps, among others implementation and operation of appropriate processes, policies and objectives. The crucial issue is the correct definition of the metrics for measurement of the effectiveness of established processes and established Controls. The paper describes some practical metrics for ISMS processes review but primarily deals with the metrics for the security category “Security in development and support processes” from the security control clause “Information systems acquisition, development and maintenance processes” (ISO/IEC 27001, ISO/IEC 27002). Judged by the authors’ research and experience, organizations often concentrate mainly on other security categories (Correct processing in application, Cryptographic Controls, Security of system files) from the security control clause “Information systems acquisition, development and maintenance processes” (ISO/IEC 27001, ISO/IEC 27002). The aim of this paper is to refocus on the necessity to define appropriate metrics for all processes (Controls) corresponding to the “Information systems acquisition, development and maintenance” security clause.
-
The proposal of software development and acquisition metrics based on ISO/IEC 27001 standard
2009Co-Authors: Ladislav Beránek, Radim RemešAbstract:The implementation and operation of efficient information security management systems (ISMS) according to the ISO/IEC 27001 standard involves a number of steps, among others implementation and operation of appropriate processes, policies and objectives. The crucial issue is the correct definition of the metrics for measurement of the effectiveness of established processes and established Controls. The paper describes some practical metrics for ISMS processes review but primarily deals with the metrics for the security category “Security in development and support processes” from the security control clause “Information systems acquisition, development and maintenance processes” (ISO/IEC 27001, ISO/IEC 27002). Judged by the authors’ research and experience, organizations often concentrate mainly on other security categories (Correct processing in application, Cryptographic Controls, Security of system files) from the security control clause “Information systems acquisition, development and maintenance processes” (ISO/IEC 27001, ISO/IEC 27002). The aim of this paper is to refocus on the necessity to define appropriate metrics for all processes (Controls) corresponding to the “Information systems acquisition, development and maintenance” security clause.
Ethan L. Miller - One of the best experts on this subject based on the ideXlab platform.
-
Decentralized security for network attached storage
2000Co-Authors: William E. Freeman, Ethan L. MillerAbstract:With the growing connectivity of the world, many computer systems that were immune from remote attacks due to network isolation are now vulnerable. The most precious resource that frequently comes under attack is the distributed (network) file system, because this usually holds the entire contents of a company's electronically stored information. This study starts by claiming that microprocessors have just become fast enough to support full Cryptographic Controls for all read and write operations in performance-critical systems. This claim is proven through the design, implementation and analysis of a decentralized security system for network attached disks. This system merges the research in the area of network attached storage with the recent feasibility of applying complete Cryptographic Controls to each block in a distributed file system. The client computers employ Cryptographic Controls on each file block to ensure data confidentiality, integrity and proof-of origin before sending the block to the network attached disks. The microprocessors located at these disks verify the data integrity and authenticate the writer of a block, before it is written to the disk subsystem. This system has the property that no sensitive data is ever sent across the network or stored on the distributed file system. This dissertation presents various levels of security which, in turn, impose various levels of Cryptographic overhead. With the first two schemes, using 32 kilobyte blocks, a single client is able to read from a single server at over 40 Mbits/second, but can only write at 10 Mbits/second. The third scheme is by far the fastest, where a single client is able to read from a single server at over 50 Mbits/second, and write at over 65 Mbits/second which is fast enough for today's mainstream applications. With random-access read and write operations, the fastest scheme presented imposes almost no performance penalty when compared to the system with no Cryptographic Controls. The performance analysis chapter also covers the system performance with multiple clients and with multiple servers. The processor utilization both at the client and server is analyzed to determine where each sixteen nanosecond window was spend while performing file system operations to provide a solid framework for future research in high-performance Cryptographic systems.
-
MASCOTS - An experimental analysis of Cryptographic overhead in performance-critical systems
MASCOTS '99. Proceedings of the Seventh International Symposium on Modeling Analysis and Simulation of Computer and Telecommunication Systems, 1Co-Authors: W. Freeman, Ethan L. MillerAbstract:This paper studies the performance implications of using Cryptographic Controls in performance-critical systems. Full Cryptographic Controls beyond basic authentication are considered and experimentally validated in the concept of network file systems. This paper demonstrates that processor speeds have become fast enough to support Cryptographic Controls in many performance-critical systems. Integrity and authentication using keyed-hash and RSA as well as confidentiality using RC5 are tested. This analysis demonstrates that full Cryptographic Controls are feasible in a distributed network file system, by showing the performance overhead for including signature, hash and encryption algorithms on various embedded and workstation computers. The results from these experiments are used to predict the performance impact using three proposed network disk security schemes.
Mohammed Abdullah Mohammed Aysan - One of the best experts on this subject based on the ideXlab platform.
-
implementation of electronic fund transfer using new symmetric key algorithm based on simple logarithm
International journal of scientific research in science engineering and technology, 2014Co-Authors: Mohammed Abdullah Mohammed AysanAbstract:Electronic Fund Transfer involves electronic transfer of money by financial institutions. EFT is the groundwork of the cash-less and check-less culture where and paper bills, checks, envelopes, stamps are eliminated. EFT is used for transferring money from one bank account directly to another without any paper money changing hands. The most popular application of EFT is that instead of getting a paycheck and putting it into a bank account, the money is deposited to an account electronically. Cryptography has been used for years to secure electronic funds transfers. However, in theelectronic data interchange environment, Cryptographic Controls are still in their infancy. In this paper, we examine the function and operation flow of the electronic funds transfer process as well as its security control mechanism. To evaluate telecommunication and data security techniques, a standard-leading inter-bank payment system called the Society for Worldwide Inter-bank Financial Telecommunications System is introduced.