The Experts below are selected from a list of 627 Experts worldwide ranked by ideXlab platform
Clyde Carryl - One of the best experts on this subject based on the ideXlab platform.
-
Verifying the Security Characteristics of a Secure Physical Access Control Protocol
International Journal of Reliability Quality and Safety Engineering, 2016Co-Authors: Clyde Carryl, Bassem Alhalabi, Taghi M. Khoshgoftaar, Lofton A. BullardAbstract:Physical Access Control protocols provide a structured method of Controlling the behavior of Physical devices which in many cases are not only remotely located with respect to the Accessing entity, but require the exchange of messages over one or more untrusted networks, such as the internet. Therefore, if it is necessary to prevent unauthorized Access to the Controlled Physical devices, it is essential that the Physical Access Control protocol exhibit certain verifiable security properties. We studied the Universal Physical Access Control System (UPACS) and used the formal protocol verification tool Proverif to verify that it possesses several key security properties. We also conducted a security analysis of the protocol and verified that it was resilient or otherwise invulnerable to several known forms of security attack, including Attacks on User Privacy and Anonymity, Session Key Security Attacks, Password Guessing Attacks, De-Synchronization Attacks, Replay Attacks, Eavesdropping Attacks, Denial-of-S...
-
Verifying the Security Characteristics of a Secure Physical Access Control Protocol
International Journal of Reliability Quality and Safety Engineering, 2016Co-Authors: Clyde Carryl, Bassem Alhalabi, Taghi M. Khoshgoftaar, Lofton A. BullardAbstract:Physical Access Control protocols provide a structured method of Controlling the behavior of Physical devices which in many cases are not only remotely located with respect to the Accessing entity, but require the exchange of messages over one or more untrusted networks, such as the internet. Therefore, if it is necessary to prevent unauthorized Access to the Controlled Physical devices, it is essential that the Physical Access Control protocol exhibit certain verifiable security properties. We studied the Universal Physical Access Control System (UPACS) and used the formal protocol verification tool Proverif to verify that it possesses several key security properties. We also conducted a security analysis of the protocol and verified that it was resilient or otherwise invulnerable to several known forms of security attack, including Attacks on User Privacy and Anonymity, Session Key Security Attacks, Password Guessing Attacks, De-Synchronization Attacks, Replay Attacks, Eavesdropping Attacks, Denial-of-Service Attacks, User and Server Masquerade Attacks, Stolen Verifier Attacks and Stolen Password Attacks.
-
Implementation of the universal Physical Access Control system (UPACS)
2015 Resilience Week (RWS), 2015Co-Authors: Clyde Carryl, Bassem AlhalabiAbstract:The Universal Physical Access Control System (UPACS) is a communication protocol designed to provide secure Access to remote Physical devices over untrusted communication networks, where it could be subjected to eavesdropping, unauthorized modification of its messages, and other forms of tampering by attackers. We created a reference implementation of the UPACS protocol and performed a security analysis designed to determine the protocol's resilience to several known forms of security attack. Our implementation prevented several attempted security attacks, including Privilege Elevation Attacks and unauthorized registration, addition and deletion of Physical device Controller nodes.
-
Formal verification of the universal Physical Access Control system (UPACS)
2015 Resilience Week (RWS), 2015Co-Authors: Clyde Carryl, Bassem Alhalabi, Lofton BullardAbstract:The Universal Access Control System (UPACS) is a communication protocol designed to provide secure Access to remote Physical devices over an untrusted communication network, where it could be subjected to eavesdropping, unauthorized modification of its messages, and other forms of tampering by attackers. We modeled the protocol in the typed Pi Calculus and used the formal protocol verification tool Proverif to examine the protocol's security properties. We issued Proverif queries to determine the ability of the protocol to protect the secrecy of terms used by protocol processes, mask any observable changes in the behavior of the protocol as the terms changed in value, and maintain the correct ordering of and causal relationships between events occurring within protocol sessions. We verified that the protocol satisfies all of its intended reachability, observational equivalence and correspondence properties.
-
BIBE - Universal Physical Access Control System
2014 IEEE International Conference on Bioinformatics and Bioengineering, 2014Co-Authors: Bassem Alhalabi, Clyde CarrylAbstract:With the recent rapid increase in the number of Physical facilities and structures that need to be protected by restricting Physical Access to them, there has been an explosion in the number and type of Physical Access Control systems being deployed to protect them. However, these systems are quite different from each other and there is no common standard that provides for interoperability between the various systems. The number and types of Access devices being employed has grown steadily, but the systems in which they are being used are Physically and technologically incompatible with each other. Consequently, there is renewed interest within the research community in developing a common universal system providing Physical resource Access protection regardless of the type of Physical resource and where it is located. In this article we propose the Universal Physical Access Control System (UPACS) which provides a universal framework for Controlling Access to Physical resources. It provides for the use of a wide variety of Access devices and allows for both onsite and remote Access. We show how it can be used to Control Access to any type of resource, including homes, vehicles and public infrastructure such as street lights and traffic lights and industrial infrastructure such as power plants. We also show how it can be implemented regardless of the location of the owner of the Physical resource and the location of the resource relative to its users.
Bassem Alhalabi - One of the best experts on this subject based on the ideXlab platform.
-
Verifying the Security Characteristics of a Secure Physical Access Control Protocol
International Journal of Reliability Quality and Safety Engineering, 2016Co-Authors: Clyde Carryl, Bassem Alhalabi, Taghi M. Khoshgoftaar, Lofton A. BullardAbstract:Physical Access Control protocols provide a structured method of Controlling the behavior of Physical devices which in many cases are not only remotely located with respect to the Accessing entity, but require the exchange of messages over one or more untrusted networks, such as the internet. Therefore, if it is necessary to prevent unauthorized Access to the Controlled Physical devices, it is essential that the Physical Access Control protocol exhibit certain verifiable security properties. We studied the Universal Physical Access Control System (UPACS) and used the formal protocol verification tool Proverif to verify that it possesses several key security properties. We also conducted a security analysis of the protocol and verified that it was resilient or otherwise invulnerable to several known forms of security attack, including Attacks on User Privacy and Anonymity, Session Key Security Attacks, Password Guessing Attacks, De-Synchronization Attacks, Replay Attacks, Eavesdropping Attacks, Denial-of-S...
-
Verifying the Security Characteristics of a Secure Physical Access Control Protocol
International Journal of Reliability Quality and Safety Engineering, 2016Co-Authors: Clyde Carryl, Bassem Alhalabi, Taghi M. Khoshgoftaar, Lofton A. BullardAbstract:Physical Access Control protocols provide a structured method of Controlling the behavior of Physical devices which in many cases are not only remotely located with respect to the Accessing entity, but require the exchange of messages over one or more untrusted networks, such as the internet. Therefore, if it is necessary to prevent unauthorized Access to the Controlled Physical devices, it is essential that the Physical Access Control protocol exhibit certain verifiable security properties. We studied the Universal Physical Access Control System (UPACS) and used the formal protocol verification tool Proverif to verify that it possesses several key security properties. We also conducted a security analysis of the protocol and verified that it was resilient or otherwise invulnerable to several known forms of security attack, including Attacks on User Privacy and Anonymity, Session Key Security Attacks, Password Guessing Attacks, De-Synchronization Attacks, Replay Attacks, Eavesdropping Attacks, Denial-of-Service Attacks, User and Server Masquerade Attacks, Stolen Verifier Attacks and Stolen Password Attacks.
-
Implementation of the universal Physical Access Control system (UPACS)
2015 Resilience Week (RWS), 2015Co-Authors: Clyde Carryl, Bassem AlhalabiAbstract:The Universal Physical Access Control System (UPACS) is a communication protocol designed to provide secure Access to remote Physical devices over untrusted communication networks, where it could be subjected to eavesdropping, unauthorized modification of its messages, and other forms of tampering by attackers. We created a reference implementation of the UPACS protocol and performed a security analysis designed to determine the protocol's resilience to several known forms of security attack. Our implementation prevented several attempted security attacks, including Privilege Elevation Attacks and unauthorized registration, addition and deletion of Physical device Controller nodes.
-
Formal verification of the universal Physical Access Control system (UPACS)
2015 Resilience Week (RWS), 2015Co-Authors: Clyde Carryl, Bassem Alhalabi, Lofton BullardAbstract:The Universal Access Control System (UPACS) is a communication protocol designed to provide secure Access to remote Physical devices over an untrusted communication network, where it could be subjected to eavesdropping, unauthorized modification of its messages, and other forms of tampering by attackers. We modeled the protocol in the typed Pi Calculus and used the formal protocol verification tool Proverif to examine the protocol's security properties. We issued Proverif queries to determine the ability of the protocol to protect the secrecy of terms used by protocol processes, mask any observable changes in the behavior of the protocol as the terms changed in value, and maintain the correct ordering of and causal relationships between events occurring within protocol sessions. We verified that the protocol satisfies all of its intended reachability, observational equivalence and correspondence properties.
-
BIBE - Universal Physical Access Control System
2014 IEEE International Conference on Bioinformatics and Bioengineering, 2014Co-Authors: Bassem Alhalabi, Clyde CarrylAbstract:With the recent rapid increase in the number of Physical facilities and structures that need to be protected by restricting Physical Access to them, there has been an explosion in the number and type of Physical Access Control systems being deployed to protect them. However, these systems are quite different from each other and there is no common standard that provides for interoperability between the various systems. The number and types of Access devices being employed has grown steadily, but the systems in which they are being used are Physically and technologically incompatible with each other. Consequently, there is renewed interest within the research community in developing a common universal system providing Physical resource Access protection regardless of the type of Physical resource and where it is located. In this article we propose the Universal Physical Access Control System (UPACS) which provides a universal framework for Controlling Access to Physical resources. It provides for the use of a wide variety of Access devices and allows for both onsite and remote Access. We show how it can be used to Control Access to any type of resource, including homes, vehicles and public infrastructure such as street lights and traffic lights and industrial infrastructure such as power plants. We also show how it can be implemented regardless of the location of the owner of the Physical resource and the location of the resource relative to its users.
Xiaofeng Du - One of the best experts on this subject based on the ideXlab platform.
-
EST - Spatio-temporal Role Based Access Control for Physical Access Control Systems
2013 Fourth International Conference on Emerging Security Technologies, 2013Co-Authors: Emsaieb Geepalla, Behzad Bordbar, Xiaofeng DuAbstract:Due to the large size of the global enterprise and the complexity of job's functions within organisations, managing Physical Access Control (PAC) policies has become a challenging problem. It is therefore, very important to develop Access Control mechanisms that can be deployed by organizations to meet their information security needs. In this paper we first demonstrate that current Access Control models such as Spatio-Temporal Role Based Access Control (STRBAC) are not adequate for representing PAC specifications. We then discuss some of the limitations of the current models, which we highlight by conducting a case study involving the modelling of an Access Control mechanism used by a leading telecommunications company. To overcome such limitations, we present an extension of the STRBAC model which considers the Physical aspects of Access Control systems. The second contribution in this paper is using our earlier method AC2Alloy to analyse PAC specifications using Alloy analyser to ensure the consistency of the specifications.
-
Spatio-temporal Role Based Access Control for Physical Access Control Systems
2013 Fourth International Conference on Emerging Security Technologies, 2013Co-Authors: Emsaieb Geepalla, Behzad Bordbar, Xiaofeng DuAbstract:Due to the large size of the global enterprise and the complexity of job's functions within organisations, managing Physical Access Control (PAC) policies has become a challenging problem. It is therefore, very important to develop Access Control mechanisms that can be deployed by organizations to meet their information security needs. In this paper we first demonstrate that current Access Control models such as Spatio-Temporal Role Based Access Control (STRBAC) are not adequate for representing PAC specifications. We then discuss some of the limitations of the current models, which we highlight by conducting a case study involving the modelling of an Access Control mechanism used by a leading telecommunications company. To overcome such limitations, we present an extension of the STRBAC model which considers the Physical aspects of Access Control systems. The second contribution in this paper is using our earlier method AC2Alloy to analyse PAC specifications using Alloy analyser to ensure the consistency of the specifications.
Lukas Malina - One of the best experts on this subject based on the ideXlab platform.
-
Secure Physical Access Control with strong cryptographic protection
2015 12th International Joint Conference on e-Business and Telecommunications (ICETE), 2015Co-Authors: Jan Hajny, Petr Dzurenda, Lukas MalinaAbstract:This paper is focused on the area of Physical Access Control systems (PACs), particularly on the systems for building Access Control. We show how the application of modern cryptographic protocols, namely the cryptographic proofs of knowledge, can improve the security and privacy protection in practical Access Control systems. We propose a novel scheme SPAC (Secure Physical Access Control) based on modern cryptographic primitives. By employing the proofs of knowledge, the authentication process gets more secure and privacy friendly in comparison to existing schemes without negative influence on the implementation complexity or system performance. In this paper, we describe the weaknesses of existing schemes, show the full cryptographic specification of the novel SPAC scheme including its security proofs and provide benchmarks on off-the-shelf devices used in real commercial systems. Furthermore we show, that the transition from an old insecure system to strong authentication can be easy and cost-effective.
-
SECRYPT - Secure Physical Access Control with strong cryptographic protection
Proceedings of the 12th International Conference on Security and Cryptography, 2015Co-Authors: Jan Hajny, Petr Dzurenda, Lukas MalinaAbstract:This paper is focused on the area of Physical Access Control systems (PACs), particularly on the systems for building Access Control. We show how the application of modern cryptographic protocols, namely the cryptographic proofs of knowledge, can improve the security and privacy protection in practical Access Control systems. We propose a novel scheme SPAC (Secure Physical Access Control) based on modern cryptographic primitives. By employing the proofs of knowledge, the authentication process gets more secure and privacy friendly in comparison to existing schemes without negative influence on the implementation complexity or system performance. In this paper, we describe the weaknesses of existing schemes, show the full cryptographic specification of the novel SPAC scheme including its security proofs and provide benchmarks on off-the-shelf devices used in real commercial systems. Furthermore we show, that the transition from an old insecure system to strong authentication can be easy and cost-effective.
-
privacy pac privacy enhanced Physical Access Control
Workshop on Privacy in the Electronic Society, 2014Co-Authors: Jan Hajny, Petr Dzurenda, Lukas MalinaAbstract:The cryptographic privacy-enhancing technologies were originally designed to improve the privacy and digital identity protection in electronic applications, such as cloud services, private Internet databases or communication systems. However, the Access to buildings can be Controlled in a privacy-respecting way too. In this paper, we introduce the privacy-enhanced Physical Access Control system (Privacy-PAC) based on cryptographic attribute-based authentication protocols. Using the Privacy-PAC, it is possible to Control the Physical Access to restricted areas while respecting the privacy of users. Besides the cryptographic design, we also describe the implementation results on the platforms of smart phones and an embedded verification terminal.
-
WPES - Privacy-PAC: Privacy-Enhanced Physical Access Control
Proceedings of the 13th Workshop on Privacy in the Electronic Society - WPES '14, 2014Co-Authors: Jan Hajny, Petr Dzurenda, Lukas MalinaAbstract:The cryptographic privacy-enhancing technologies were originally designed to improve the privacy and digital identity protection in electronic applications, such as cloud services, private Internet databases or communication systems. However, the Access to buildings can be Controlled in a privacy-respecting way too. In this paper, we introduce the privacy-enhanced Physical Access Control system (Privacy-PAC) based on cryptographic attribute-based authentication protocols. Using the Privacy-PAC, it is possible to Control the Physical Access to restricted areas while respecting the privacy of users. Besides the cryptographic design, we also describe the implementation results on the platforms of smart phones and an embedded verification terminal.
Christoph Meinel - One of the best experts on this subject based on the ideXlab platform.
-
Supporting Internet-Based Location for Location-Based Access Control in Enterprise Cloud Storage Solution
Advanced Information Networking and Applications, 2020Co-Authors: Muhammad I. H. Sukmana, Hendrik Graupner, Ankit Chauhan, Kennedy A Torkura, Feng Cheng, Christoph MeinelAbstract:The emergence of the Internet allows the enterprise to implement telework policy in order for the employee to work and Access company file anytime, anywhere. But it raises the challenge for the enterprise to enforce Physical Access Control on enterprise’s files to the employee outside the enterprise network. One of the solutions for the enterprise to enforce Physical Access Control of its files is implementing location-based Access Control (LBAC) model to allow the employee to Access a file at the pre-determined location. We propose an extension of the LBAC model to include Internet-based location as an input for location constraint used for the Access Control decision and authorization where Internet-connected device is mapped into a Physical location using the IP geolocation method. Our approach could be used as an alternative user’s location determination and location verification methods, especially for mobile devices with minimum self-geolocation capability. We implement our proposal into proof-of-concept enterprise cloud storage solution called CloudRAID for Business (CfB) by combining Internet-based geolocation service, delay-based measurement technique, and open source information. Our evaluation’s result shows that our implementation is able to grant user Access Control of the system once the user’s location is in the pre-determined location.
-
AINA - Supporting Internet-Based Location for Location-Based Access Control in Enterprise Cloud Storage Solution
Advanced Information Networking and Applications, 2019Co-Authors: Muhammad I. H. Sukmana, Hendrik Graupner, Ankit Chauhan, Kennedy A Torkura, Feng Cheng, Christoph MeinelAbstract:The emergence of the Internet allows the enterprise to implement telework policy in order for the employee to work and Access company file anytime, anywhere. But it raises the challenge for the enterprise to enforce Physical Access Control on enterprise’s files to the employee outside the enterprise network. One of the solutions for the enterprise to enforce Physical Access Control of its files is implementing location-based Access Control (LBAC) model to allow the employee to Access a file at the pre-determined location. We propose an extension of the LBAC model to include Internet-based location as an input for location constraint used for the Access Control decision and authorization where Internet-connected device is mapped into a Physical location using the IP geolocation method. Our approach could be used as an alternative user’s location determination and location verification methods, especially for mobile devices with minimum self-geolocation capability. We implement our proposal into proof-of-concept enterprise cloud storage solution called CloudRAID for Business (CfB) by combining Internet-based geolocation service, delay-based measurement technique, and open source information. Our evaluation’s result shows that our implementation is able to grant user Access Control of the system once the user’s location is in the pre-determined location.