The Experts below are selected from a list of 62130 Experts worldwide ranked by ideXlab platform

Keith Mayes - One of the best experts on this subject based on the ideXlab platform.

  • ESORICS (2) - Enhancing Java Runtime Environment for Smart Cards Against Runtime Attacks
    Computer Security -- ESORICS 2015, 2015
    Co-Authors: Raja Naeem Akram, Konstantinos Markantonakis, Keith Mayes
    Abstract:

    Smart cards are mostly deployed in security-critical environments in order to provide a secure and trusted access to the provisioned services. These services are delivered to a cardholder using the Service Provider’s (SPs) Applications on his or her smart card(s). These Applications are at their most vulnerable state when they are executing. There exist a variety of runtime attacks that can circumvent the security checks implemented either by the Respective Application or the runtime environment to protect the smart card platform, user and/or Application. In this paper, we discuss the Java Runtime Environment and a potential threat model based on runtime attacks. Subsequently, we discussed the counter-measures that can be deployed to provide a secure and reliable execution platform, along with an evaluation of their effectiveness, incurred performance-penalty and latency.

  • enhancing java runtime environment for smart cards against runtime attacks
    European Symposium on Research in Computer Security, 2015
    Co-Authors: Raja Naeem Akram, Konstantinos Markantonakis, Keith Mayes
    Abstract:

    Smart cards are mostly deployed in security-critical environments in order to provide a secure and trusted access to the provisioned services. These services are delivered to a cardholder using the Service Provider’s (SPs) Applications on his or her smart card(s). These Applications are at their most vulnerable state when they are executing. There exist a variety of runtime attacks that can circumvent the security checks implemented either by the Respective Application or the runtime environment to protect the smart card platform, user and/or Application. In this paper, we discuss the Java Runtime Environment and a potential threat model based on runtime attacks. Subsequently, we discussed the counter-measures that can be deployed to provide a secure and reliable execution platform, along with an evaluation of their effectiveness, incurred performance-penalty and latency.

  • RFIDSec Asia - Remote attestation mechanism for embedded devices based on physical unclonable functions
    2013
    Co-Authors: Raja Naeem Akram, Konstantinos Markantonakis, Keith Mayes
    Abstract:

    Remote attestation mechanisms are well studied in the highend computing environments; however, the same is not true for embedded devices especially for smart cards. With ever changing landscape of smart card technology and advancements towards a true multiApplication platform, verifying the current state of the smart card is signi cant to the overall security of such proposals. The initiatives proposed by GlobalPlatform Consumer Centric Model (GP-CCM) and User Centric Smart Card Ownership Model (UCOM) enables a user to download any Application as she desire depending upon the authorisation of the Application provider. Before an Application provider issues an Application to a smart card, verifying the current state of the smart card is crucial to the security of the Respective Application. In this paper, we analyse the rationale behind the remote attestation mechanism for smart cards, and the fundamental features that such a mechanism should possess. We also study the applicability of Physical Unclonable Functions (PUFs) for the remote attestation mechanism and propose two algorithms to achieve the stated features of remote attestation. The proposed algorithms are implemented in a test environment to evaluate their performance.

Raja Naeem Akram - One of the best experts on this subject based on the ideXlab platform.

  • ESORICS (2) - Enhancing Java Runtime Environment for Smart Cards Against Runtime Attacks
    Computer Security -- ESORICS 2015, 2015
    Co-Authors: Raja Naeem Akram, Konstantinos Markantonakis, Keith Mayes
    Abstract:

    Smart cards are mostly deployed in security-critical environments in order to provide a secure and trusted access to the provisioned services. These services are delivered to a cardholder using the Service Provider’s (SPs) Applications on his or her smart card(s). These Applications are at their most vulnerable state when they are executing. There exist a variety of runtime attacks that can circumvent the security checks implemented either by the Respective Application or the runtime environment to protect the smart card platform, user and/or Application. In this paper, we discuss the Java Runtime Environment and a potential threat model based on runtime attacks. Subsequently, we discussed the counter-measures that can be deployed to provide a secure and reliable execution platform, along with an evaluation of their effectiveness, incurred performance-penalty and latency.

  • enhancing java runtime environment for smart cards against runtime attacks
    European Symposium on Research in Computer Security, 2015
    Co-Authors: Raja Naeem Akram, Konstantinos Markantonakis, Keith Mayes
    Abstract:

    Smart cards are mostly deployed in security-critical environments in order to provide a secure and trusted access to the provisioned services. These services are delivered to a cardholder using the Service Provider’s (SPs) Applications on his or her smart card(s). These Applications are at their most vulnerable state when they are executing. There exist a variety of runtime attacks that can circumvent the security checks implemented either by the Respective Application or the runtime environment to protect the smart card platform, user and/or Application. In this paper, we discuss the Java Runtime Environment and a potential threat model based on runtime attacks. Subsequently, we discussed the counter-measures that can be deployed to provide a secure and reliable execution platform, along with an evaluation of their effectiveness, incurred performance-penalty and latency.

  • RFIDSec Asia - Remote attestation mechanism for embedded devices based on physical unclonable functions
    2013
    Co-Authors: Raja Naeem Akram, Konstantinos Markantonakis, Keith Mayes
    Abstract:

    Remote attestation mechanisms are well studied in the highend computing environments; however, the same is not true for embedded devices especially for smart cards. With ever changing landscape of smart card technology and advancements towards a true multiApplication platform, verifying the current state of the smart card is signi cant to the overall security of such proposals. The initiatives proposed by GlobalPlatform Consumer Centric Model (GP-CCM) and User Centric Smart Card Ownership Model (UCOM) enables a user to download any Application as she desire depending upon the authorisation of the Application provider. Before an Application provider issues an Application to a smart card, verifying the current state of the smart card is crucial to the security of the Respective Application. In this paper, we analyse the rationale behind the remote attestation mechanism for smart cards, and the fundamental features that such a mechanism should possess. We also study the applicability of Physical Unclonable Functions (PUFs) for the remote attestation mechanism and propose two algorithms to achieve the stated features of remote attestation. The proposed algorithms are implemented in a test environment to evaluate their performance.

Konstantinos Markantonakis - One of the best experts on this subject based on the ideXlab platform.

  • ESORICS (2) - Enhancing Java Runtime Environment for Smart Cards Against Runtime Attacks
    Computer Security -- ESORICS 2015, 2015
    Co-Authors: Raja Naeem Akram, Konstantinos Markantonakis, Keith Mayes
    Abstract:

    Smart cards are mostly deployed in security-critical environments in order to provide a secure and trusted access to the provisioned services. These services are delivered to a cardholder using the Service Provider’s (SPs) Applications on his or her smart card(s). These Applications are at their most vulnerable state when they are executing. There exist a variety of runtime attacks that can circumvent the security checks implemented either by the Respective Application or the runtime environment to protect the smart card platform, user and/or Application. In this paper, we discuss the Java Runtime Environment and a potential threat model based on runtime attacks. Subsequently, we discussed the counter-measures that can be deployed to provide a secure and reliable execution platform, along with an evaluation of their effectiveness, incurred performance-penalty and latency.

  • enhancing java runtime environment for smart cards against runtime attacks
    European Symposium on Research in Computer Security, 2015
    Co-Authors: Raja Naeem Akram, Konstantinos Markantonakis, Keith Mayes
    Abstract:

    Smart cards are mostly deployed in security-critical environments in order to provide a secure and trusted access to the provisioned services. These services are delivered to a cardholder using the Service Provider’s (SPs) Applications on his or her smart card(s). These Applications are at their most vulnerable state when they are executing. There exist a variety of runtime attacks that can circumvent the security checks implemented either by the Respective Application or the runtime environment to protect the smart card platform, user and/or Application. In this paper, we discuss the Java Runtime Environment and a potential threat model based on runtime attacks. Subsequently, we discussed the counter-measures that can be deployed to provide a secure and reliable execution platform, along with an evaluation of their effectiveness, incurred performance-penalty and latency.

  • RFIDSec Asia - Remote attestation mechanism for embedded devices based on physical unclonable functions
    2013
    Co-Authors: Raja Naeem Akram, Konstantinos Markantonakis, Keith Mayes
    Abstract:

    Remote attestation mechanisms are well studied in the highend computing environments; however, the same is not true for embedded devices especially for smart cards. With ever changing landscape of smart card technology and advancements towards a true multiApplication platform, verifying the current state of the smart card is signi cant to the overall security of such proposals. The initiatives proposed by GlobalPlatform Consumer Centric Model (GP-CCM) and User Centric Smart Card Ownership Model (UCOM) enables a user to download any Application as she desire depending upon the authorisation of the Application provider. Before an Application provider issues an Application to a smart card, verifying the current state of the smart card is crucial to the security of the Respective Application. In this paper, we analyse the rationale behind the remote attestation mechanism for smart cards, and the fundamental features that such a mechanism should possess. We also study the applicability of Physical Unclonable Functions (PUFs) for the remote attestation mechanism and propose two algorithms to achieve the stated features of remote attestation. The proposed algorithms are implemented in a test environment to evaluate their performance.

J. Zimmermann - One of the best experts on this subject based on the ideXlab platform.

C. Kiesling - One of the best experts on this subject based on the ideXlab platform.