The Experts below are selected from a list of 6792 Experts worldwide ranked by ideXlab platform
Haodong Wang - One of the best experts on this subject based on the ideXlab platform.
-
Achieving distributed user access control in sensor networks
Ad Hoc Networks, 2012Co-Authors: Haodong WangAbstract:User access control in sensor networks defines a process of granting user an access right to the stored information. It is essential for future real sensor network deployment in which sensors may provide users with different services in terms of data and resource accesses. A centralized access control mechanism requires the base station to be involved whenever a user requests to get authenticated and access the information stored in the sensor node, which is inefficient, not scalable, and is exposed to many potential attacks along long communication paths. In this paper, we propose a distributed user access control under a realistic adversary model in which sensors can be compromised and user may collude. We split the access control into Local Authentication conducted by a group of sensors physically close to a user, and a light remote Authentication based on the endorsement of the Local sensors. We implement the access control protocols on a testbed of TelosB motes. Our analysis and experimental results show that our schemes are feasible for real access control requirements.
-
DCOSS - Distributed user access control in sensor networks
Distributed Computing in Sensor Systems, 2006Co-Authors: Haodong WangAbstract:User access control in sensor networks defines a process of granting user the access right to the information and resources. It is essential for the future real sensor network deployment in which sensors may provide users with different services in terms of data and resource access. A centralized access control mechanism requires base station to be involved whenever a user requests to get authenticated and access the information stored in the sensor node, which is inefficient, not scalable, and is exposed to many potential attacks along the long communication path. In this paper, we propose a distributed user access control under a realistic adversary model in which sensors can be compromised and user may collude. We split the access control into Local Authentication conducted by the sensors physically close to the user, and a light remote Authentication based on the endorsement of the Local sensors. Elliptic Curve Cryptography (ECC), a public key cryptography scheme, is used for Local Authentication. We implement the access control protocols on a testbed of TelosB motes. Our analysis and experimental results show that our scheme is feasible for real access control requirement.
-
Distributed user access control in sensor networks
Lecture Notes in Computer Science, 2006Co-Authors: Haodong WangAbstract:User access control in sensor networks defines a process of granting user the access right to the information and resources. It is essential for the future real sensor network deployment in which sensors may provide users with different services in terms of data and resource access. A centralized access control mechanism requires base station to be involved whenever a user requests to get authenticated and access the information stored in the sensor node, which is inefficient, not scalable, and is exposed to many potential attacks along the long communication path. In this paper, we propose a distributed user access control under a realistic adversary model in which sensors can be compromised and user may collude. We split the access control into Local Authentication conducted by the sensors physically close to the user, and a light remote Authentication based on the endorsement of the Local sensors. Elliptic Curve Cryptography (ECC), a public key cryptography scheme, is used for Local Authentication. We implement the access control protocols on a testbed of TelosB motes. Our analysis and experimental results show that our scheme is feasible for real access control requirement.
Ronan Keryell - One of the best experts on this subject based on the ideXlab platform.
-
Improving virus protection with an efficient secure architecture with memory encryption, integrity and information leakage protection
Journal in Computer Virology, 2008Co-Authors: Ronan KeryellAbstract:Malicious software and other attacks are a major concern in the computing ecosystem and there is a need to go beyond the answers based on untrusted software. Trusted and secure computing can add a new hardware dimension to software protection. Several secure computing hardware architectures using memory encryption and memory integrity checkers have been proposed during the past few years to provide applications with a tamper resistant environment. Some solutions, such as HIDE, have also been proposed to solve the problem of information leakage on the address bus. We propose the C RYPTO P AGE architecture which implements memory encryption, memory integrity protection checking and information leakage protection together with a low performance penalty (3% slowdown on average) by combining the Counter Mode of operation, Local Authentication values and M ERKLE trees. It has also several other security features such as attestation, secure storage for applications and program identification. We present some applications of the C RYPTO P AGE architecture in the computer virology field as a proof of concept of improving security in presence of viruses compared to software only solutions.
-
cryptopage an efficient secure architecture with memory encryption integrity and information leakage protection
Annual Computer Security Applications Conference, 2006Co-Authors: Ronan KeryellAbstract:Several secure computing hardware architectures using memory encryption and memory integrity checkers have been proposed during the past few years to provide applications with a tamper resistant environment. Some solutions, such as HIDE, have also been proposed to solve the problem of information leakage on the address bus. We propose the CRYPTOPAGE architecture which implements memory encryption, memory integrity protection checking and information leakage protection together with a low performance penalty (3% slowdown on average) by combining the Counter Mode of operation, Local Authentication values and Merkle trees.
-
ACSAC - CryptoPage: An Efficient Secure Architecture with Memory Encryption, Integrity and Information Leakage Protection
2006 22nd Annual Computer Security Applications Conference (ACSAC'06), 2006Co-Authors: Guillaume Duc, Ronan KeryellAbstract:Several secure computing hardware architectures using memory encryption and memory integrity checkers have been proposed during the past few years to provide applications with a tamper resistant environment. Some solutions, such as HIDE, have also been proposed to solve the problem of information leakage on the address bus. We propose the CRYPTOPAGE architecture which implements memory encryption, memory integrity protection checking and information leakage protection together with a low performance penalty (3% slowdown on average) by combining the Counter Mode of operation, Local Authentication values and Merkle trees.
Hans D. Schotten - One of the best experts on this subject based on the ideXlab platform.
-
Context-Awareness Enhances 5G Multi-Access Edge Computing Reliability
IEEE Access, 2019Co-Authors: Bin Han, Stan Wong, Christian Mannweiler, Marcos Rates Crippa, Hans D. SchottenAbstract:The fifth-generation mobile telecommunication network is expected to support multi-access edge computing (MEC), which intends to distribute computation tasks and services from the central cloud to the edge clouds. Toward ultra-responsive, ultra-reliable, and ultra-low-latency MEC services, the current mobile network security architecture should enable a more decentralized approach for Authentication and authorization processes. This paper proposes a novel decentralized Authentication architecture that supports flexible and low-cost Local Authentication with the awareness of context information of network elements such as user equipment and virtual network functions. Based on a Markov model for backhaul link quality as well as a random walk mobility model with mixed mobility classes and traffic scenarios, numerical simulations have demonstrated that the proposed approach is able to achieve a flexible balance between the network operating cost and the MEC reliability.
-
Reliable Distributed Authentication in Multi-Access Mobile Edge Computing.
2017Co-Authors: Bin Han, Stan Wong, Christian Mannweiler, Marcos Rates Crippa, Hans D. SchottenAbstract:The fifth generation (5G) mobile telecommunication network is expected to support multi-access mobile edge computing (MEC), which intends to distribute computation tasks and services from the central cloud to the edge clouds. Towards ultraresponsive, ultra-reliable and ultra-low-latency MEC services, the current mobile network security architecture should enable more decentralized approach for Authentication and authorization process. This paper proposes a novel distributed Authentication architecture that supports flexible, intelligent and low-cost Local Authentication with the awareness of network elements, e.g. user equipment, virtual network functions etc., context information.
Wenye Wang - One of the best experts on this subject based on the ideXlab platform.
-
A Local Authentication control scheme based on AAA architecture in wireless networks
IEEE 60th Vehicular Technology Conference 2004. VTC2004-Fall. 2004, 1Co-Authors: Wei Liang, Wenye WangAbstract:In this paper, we propose a novel control scheme to Locally authorize inter-domain roaming users for efficient Authentication in wireless networks, which is based on Authentication, authorization, accounting (AAA) architecture. We develop a detailed procedure to establish Local security associations (SAs) for Authentication and determine a threshold to trigger the proposed scheme. By considering the traffic and mobility patterns of a mobile user (MU), as well as the number of hops between the MU and its home AAA server, we demonstrate that the performance of the proposed scheme outperforms DIAMETER protocol with respect to Authentication latency and cost for macro-mobility users with a high volume of Authentication requests.
Ming-chin Chuang - One of the best experts on this subject based on the ideXlab platform.
-
SF-PMIPv6
Journal of Systems and Software, 2013Co-Authors: Ming-chin Chuang, Jeng-farn LeeAbstract:Highlights? We develop a secure fast handover mechanism for Proxy Mobile IPv6 networks. ? SF-PMIPv6 can resist various attacks. ? SF-PMIPv6 outperforms all existing schemes in terms of packet loss, Authentication latency, and handoff latency. An efficient mobility management mechanism is one of the major challenges for ubiquitous computing. Recently, the IETF NETLMM working group proposed Proxy Mobile IPv6 (PMIPv6), a network-based Localized mobility management protocol to support mobility management without the participation of mobile nodes (MNs) in any mobility-related signaling. Unfortunately, PMIPv6 still suffers from high packet losses and long Authentication latency during handover. To address these issues, we propose a secure Authentication mechanism and fast handover scheme called SF-PMIPv6 for PMIPv6 networks. The scheme provides low handover latency, supports Local Authentication procedures, resolves the packet loss problem, and deals with out-of-sequence packets. Moreover, SF-PMIPv6 is a robust Authentication scheme that resists various attacks. Our simulation results demonstrate that it provides a better solution than existing schemes.
-
a lightweight mutual Authentication mechanism for network mobility in ieee 802 16e wireless networks
Computer Networks, 2011Co-Authors: Ming-chin ChuangAbstract:Many mobile network nodes (MNNs) in public transport move together as a large-scale mobile network. Therefore, RFC 3963 proposes a network layer solution called network mobility (NEMO) as the basic support protocol for network mobility management. NEMO is designed so that network mobility is transparent to nodes in the mobile network, thereby reducing the signaling overhead. However, NEMO does not specify how Authentication, authorization and accounting (AAA) should be handled, and it inherits the drawbacks of long handoff latency from Mobile IPv6 (MIPv6). In this paper, we develop a lightweight mutual Authentication mechanism (LMAM) with low computational overhead and achieve Local Authentication based on NEMO and the AAA model over IEEE 802.16e networks. Moreover, LMAM can resist various attacks. In addition, we propose an enhanced hierarchical Mobile IPv6 (E-HMIPv6) scheme to reduce intra-domain handoff latency. We then integrate LMAM into E-HMIPv6 without increasing the signaling overhead. Our analysis results show that the integrated scheme, called LE-HMIPv6 outperforms existing schemes in terms of Authentication and handoff latency.
-
APSCC - LMAM: A Lightweight Mutual Authentication Mechanism for Network Mobility in Vehicular Networks
2008 IEEE Asia-Pacific Services Computing Conference, 2008Co-Authors: Ming-chin Chuang, Jeng-farn LeeAbstract:RFC 3963 proposes a protocol, called the network mobility (NEMO) basic support protocol, for network mobility management. It is designed so that network mobility is transparent to nodes inside the mobile network, thereby reducing the signaling overhead. However, NEMO does not specify how Authentication, authorization and accounting (AAA) should be handled. In this paper, we develop a lightweight mutual Authentication mechanism (LMAM) based on NEMO combining with AAA model in vehicular networks with low computation cost and Local Authentication. Moreover, LMAM achieves the following security requirements: replay attack resistance, stolen-verified attack resistance, mutual Authentication to prevent the server spoofing attacks, and session key generation. Our analysis results show that LMAM provides a better solution to the Authentication procedure than existing schemes.