The Experts below are selected from a list of 270 Experts worldwide ranked by ideXlab platform

Brent Waters - One of the best experts on this subject based on the ideXlab platform.

  • Ciphertext-policy attribute-based encryption
    Proceedings - IEEE Symposium on Security and Privacy, 2007
    Co-Authors: John Bethencourt, Amit Sahai, Brent Waters
    Abstract:

    In several distributed systems a user should only be able to access Data if a user posses a certain set of credentials or attributes. Currently, the only method for enforcing such policies is to employ a trusted server to store the Data and mediate access control. However, if any server storing the Data is compromised, then the confidentiality of the Data will be compromised. In this paper we present a system for realizing complex access control on encrypted Data that we call ciphertext-policy attribute-based encryption. By using our techniques encrypted Data can be kept confidential even if the storage server is untrusted; moreover, our methods are secure against collusion attacks. Previous attribute-based encryption systems used attributes to describe the encrypted Data and built policies into user's keys; while in our system attributes are used to describe a user's credentials, and a party Encrypting Data determines a policy for who can decrypt. Thus, our methods are conceptually closer to traditional access control methods such as role-based access control (RBAC). In addition, we provide an implementation of our system and give performance measurements.

  • Attribute-based encryption for fine-grained access control of encrypted Data
    Proceedings of the 13th ACM conference on Computer and communications security - CCS '06, 2006
    Co-Authors: Vipul Goyal, Omkant Pandey, Amit Sahai, Brent Waters
    Abstract:

    As more sensitive Data is shared and stored by third-party sites on the Internet, there will be a need to encrypt Data stored at these sites. One drawback of Encrypting Data, is that it can be selectively shared only at a coarse-grained level (i.e., giving another party your private key). We develop a new cryptosystem for fine-grained sharing of encrypted Data that we call Key-Policy Attribute-Based Encryption (KP-ABE). In our cryptosystem, ciphertexts are labeled with sets of attributes and private keys are associated with access structures that control which ciphertexts a user is able to decrypt. We demonstrate the applicability of our construction to sharing of audit-log information and broadcast encryption. Our construction supports delegation of private keys which subsumes Hierarchical Identity-Based Encryption (HIBE).

  • ACM Conference on Computer and Communications Security - Attribute-based encryption for fine-grained access control of encrypted Data
    Proceedings of the 13th ACM conference on Computer and communications security - CCS '06, 2006
    Co-Authors: Vipul Goyal, Omkant Pandey, Amit Sahai, Brent Waters
    Abstract:

    As more sensitive Data is shared and stored by third-party sites on the Internet, there will be a need to encrypt Data stored at these sites. One drawback of Encrypting Data, is that it can be selectively shared only at a coarse-grained level (i.e., giving another party your private key). We develop a new cryptosystem for fine-grained sharing of encrypted Data that we call Key-Policy Attribute-Based Encryption (KP-ABE). In our cryptosystem, ciphertexts are labeled with sets of attributes and private keys are associated with access structures that control which ciphertexts a user is able to decrypt. We demonstrate the applicability of our construction to sharing of audit-log information and broadcast encryption. Our construction supports delegation of private keys which subsumesHierarchical Identity-Based Encryption (HIBE).

Xu Maopeng - One of the best experts on this subject based on the ideXlab platform.

  • virtual machine safety protection method and virtual machine safety protection device
    2013
    Co-Authors: Xu Maopeng
    Abstract:

    An embodiment of the invention provides a virtual machine safety protection method and a virtual machine safety protection device. The virtual machine safety protection method includes establishing binding relations among virtual machines and certificate public keys by the aid of an encryption management system; respectively Encrypting Data encryption keys of Data volumes by the certificate public keys of the various virtual machines to form various encrypted Data encryption keys; transmitting requests for acquiring encrypted Data encryption keys corresponding to the requested virtual machines to the encryption management system when receiving Data volume access requests via the virtual machines; decrypting the encrypted Data encryption keys by the aid of certificate private keys of the requested virtual machines to obtain the Data encryption keys; and decrypting the Data volumes by the Data encryption keys to access the Data volumes. The Data encryption keys are used for storing Data of the Data volumes in an encrypted manner. By the virtual machine safety protection method, the same user can access the mounted Data volumes from different virtual machines under the condition that a Ukey [USB (universal serial bus) key] is not used.

Muhammad Rizwan Asghar - One of the best experts on this subject based on the ideXlab platform.

  • AuthStore: Password-based Authentication and Encrypted Data Storage in Untrusted Environments.
    arXiv: Cryptography and Security, 2018
    Co-Authors: Clemens Zeidler, Muhammad Rizwan Asghar
    Abstract:

    Passwords are widely used for client to server authentication as well as for Encrypting Data stored in untrusted environments, such as cloud storage. Both, authentication and encrypted cloud storage, are usually discussed in isolation. In this work, we propose AuthStore, a flexible authentication framework that allows users to securely reuse passwords for authentication as well as for encrypted cloud storage at a single or multiple service providers. Users can configure how secure passwords are protected using password stretching techniques. We present a compact password-authenticated key exchange protocol (CompactPAKE) that integrates the retrieval of password stretching parameters. A parameter attack is described and we show how existing solutions suffer from this attack. Furthermore, we introduce a password manager that supports CompactPAKE.

  • TrustCom/BigDataSE - AuthStore: Password-Based Authentication and Encrypted Data Storage in Untrusted Environments
    2018 17th IEEE International Conference On Trust Security And Privacy In Computing And Communications 12th IEEE International Conference On Big Data S, 2018
    Co-Authors: Clemens Zeidler, Muhammad Rizwan Asghar
    Abstract:

    Passwords are widely used for client to server authentication as well as for Encrypting Data stored in untrusted environments, such as cloud storage. Both, authentication and encrypted cloud storage, are usually discussed in isolation. In this work, we propose AuthStore, a flexible authentication framework that allows users to securely reuse passwords for authentication as well as for encrypted cloud storage at a single or multiple service providers. Users can configure how secure passwords are protected using password stretching techniques. We present a compact password-authenticated key exchange protocol (CompactPAKE) that integrates the retrieval of password stretching parameters. A parameter attack is described and we show how existing solutions suffer from this attack. Furthermore, we introduce a password manager that supports CompactPAKE.

Aiman Tahir Laghari - One of the best experts on this subject based on the ideXlab platform.

  • Trends to store digital Data in DNA: an overview
    Molecular Biology Reports, 2018
    Co-Authors: Fatima Akram, Ikram Ul Haq, Haider Ali, Aiman Tahir Laghari
    Abstract:

    There has been an ascending growth in the capacity of information being generated. The increased production of Data in turn has put forward other challenges as well thus, and there is the need to store this information and not only to store it but also to retain it for a prolonged time period. The reliance on DNA as a dense storage medium with high storage capacity and its ability to withstand extreme environmental conditions has increased over the past few years. There have been developments in reading and writing different forms of Data on DNA, codes for Encrypting Data and using DNA as a way of secret writing leading towards new styles like stenography and cryptography. The article outlines different methods adopted for storing digital Data on DNA with pros and cons of each method that has been applied plus the advantages and limitations of using DNA as a storage medium.

Clemens Zeidler - One of the best experts on this subject based on the ideXlab platform.

  • AuthStore: Password-based Authentication and Encrypted Data Storage in Untrusted Environments.
    arXiv: Cryptography and Security, 2018
    Co-Authors: Clemens Zeidler, Muhammad Rizwan Asghar
    Abstract:

    Passwords are widely used for client to server authentication as well as for Encrypting Data stored in untrusted environments, such as cloud storage. Both, authentication and encrypted cloud storage, are usually discussed in isolation. In this work, we propose AuthStore, a flexible authentication framework that allows users to securely reuse passwords for authentication as well as for encrypted cloud storage at a single or multiple service providers. Users can configure how secure passwords are protected using password stretching techniques. We present a compact password-authenticated key exchange protocol (CompactPAKE) that integrates the retrieval of password stretching parameters. A parameter attack is described and we show how existing solutions suffer from this attack. Furthermore, we introduce a password manager that supports CompactPAKE.

  • TrustCom/BigDataSE - AuthStore: Password-Based Authentication and Encrypted Data Storage in Untrusted Environments
    2018 17th IEEE International Conference On Trust Security And Privacy In Computing And Communications 12th IEEE International Conference On Big Data S, 2018
    Co-Authors: Clemens Zeidler, Muhammad Rizwan Asghar
    Abstract:

    Passwords are widely used for client to server authentication as well as for Encrypting Data stored in untrusted environments, such as cloud storage. Both, authentication and encrypted cloud storage, are usually discussed in isolation. In this work, we propose AuthStore, a flexible authentication framework that allows users to securely reuse passwords for authentication as well as for encrypted cloud storage at a single or multiple service providers. Users can configure how secure passwords are protected using password stretching techniques. We present a compact password-authenticated key exchange protocol (CompactPAKE) that integrates the retrieval of password stretching parameters. A parameter attack is described and we show how existing solutions suffer from this attack. Furthermore, we introduce a password manager that supports CompactPAKE.