The Experts below are selected from a list of 20940 Experts worldwide ranked by ideXlab platform

Kristof Teichel - One of the best experts on this subject based on the ideXlab platform.

Stefan Milius - One of the best experts on this subject based on the ideXlab platform.

  • first results of a formal analysis of the network time Security Specification
    International Workshop on Security, 2015
    Co-Authors: Kristof Teichel, Dieter Sibold, Stefan Milius
    Abstract:

    This paper presents a first formal analysis of parts of a draft version of the Network Time Security Specification. It presents the protocol model on which we based our analysis, discusses the decision for using the model checker ProVerif and describes how it is applied to analyze the protocol model. The analysis uncovers two possible attacks on the protocol. We present those attacks and show measures that can be taken in order to mitigate them and that have meanwhile been incorporated in the current draft Specification.

Dieter Sibold - One of the best experts on this subject based on the ideXlab platform.

Ping Yang - One of the best experts on this subject based on the ideXlab platform.

  • secure abstraction views for scientific workflow provenance querying
    IEEE Transactions on Services Computing, 2010
    Co-Authors: Artem Chebotko, Seunghan Chang, Farshad Fotouhi, Ping Yang
    Abstract:

    Provenance has become increasingly important in scientific workflows and services computing to capture the derivation history of a data product, including the original data sources, intermediate data products, and the steps that were applied to produce the data product. In many cases, both scientific results and the used protocol are sensitive and effective access control mechanisms are essential to protect their confidentiality. In this paper, we propose: 1) a formal scientific workflow provenance model as the basis for querying and access control for workflow provenance; 2) a Security model for fine-grained access control for multilevel provenance and an algorithm for the derivation of a full Security Specification based on inheritance, overriding, and conflict resolution; 3) a formalization of the notion of Security views and an algorithm for Security view derivation; and 4) a formalization of the notion of secure abstraction views and an algorithm for its computation. A prototype called SecProv has been developed, and experiments show the effectiveness and efficiency of our approach.

  • scientific workflow provenance querying with Security views
    Web-Age Information Management, 2008
    Co-Authors: Artem Chebotko, Seunghan Chang, Farshad Fotouhi, Ping Yang
    Abstract:

    Provenance, the metadata that pertains to the derivation history of a data product, has become increasingly important in scientific workflow environments. In many cases, both data products and their provenance can be sensitive and effective access control mechanisms are essential to protect their confidentiality. In this paper, we propose i) a formalization of scientific workflow provenance as the basis for querying and access control; ii) a Security Specification mechanism for provenance at various granularity levels and the derivation of a full Security Specification based on inheritance, overriding, and conflict resolution rules; iii) a formalization of Security views that are derived from a scientific workflow run provenance for different roles of users; and iv) a framework that integrates abstraction views and Security views such that a user can examine provenance at different abstraction levels while respecting the Security policy prescribed for her. We have developed the SecProv prototype to validate the effectiveness of our approach.

  • secure scientific workflow provenance querying with Security views
    2008
    Co-Authors: Artem Chebotko, Seunghan Chang, Farshad Fotouhi, Ping Yang
    Abstract:

    Provenance, the metadata that pertains to the derivation history of a data product starting from its original sources, has become increasingly important in scientific workflow environments. In many cases, both data products and their provenance can be sensitive and effective access control mechanisms are essential to protect their confidentiality. In this paper, we propose i) a formalization of scientific workflow provenance as the basis for querying and access control; ii) a Security Specification mechanism for provenance at various granularity levels and the derivation of a full Security Specification based on inheritance, overriding, and conflict resolution rules; iii) a formalization of Security views that are derived from a scientific workflow run provenance for different roles of users; and iv) a framework that integrates abstraction views and Security views such that a user can examine provenance information at different abstraction levels while respecting the Security policy prescribed for her. We have developed the SecProv prototype to validate the effectiveness of our approach.

Jingde Cheng - One of the best experts on this subject based on the ideXlab platform.

  • a Security Specification library with a schemaless database
    International Conference on Conceptual Structures, 2007
    Co-Authors: Shoichi Morimoto, Jingde Cheng
    Abstract:

    In order to develop highly secure information systems, it is important to make a Security Specification of the systems, although it requires heavy labor. Thus database technologies have been applied to software engineering and information Security engineering for practical reuse of Security Specifications. However, because the Specifications do not have fixed layout, it is difficult to develop a flexible and useful library for the documents with conventional database technologies. Therefore, this paper proposes a Security Specification library with a schemaless native XML database. Users of the library can directly store and manage Security Specifications with any layout. Consequently, the library mitigates the labor for making Security Specifications.

  • a Security Specification verification technique based on the international standard iso iec 15408
    ACM Symposium on Applied Computing, 2006
    Co-Authors: Shoichi Morimoto, Shinjiro Shigematsu, Yuichi Goto, Jingde Cheng
    Abstract:

    This paper proposes a Security Specification verification technique based on the international standard ISO/IEC 15408. We formalized the Security criteria of ISO/IEC 15408 and developed the verification technique of Security Specifications based on the formalized criteria with formal methods. With the technique, one can formally verify whether or not Specifications satisfy the Security criteria of ISO/IEC 15408. Ambiguity and/or oversight about Security in Specifications written in natural language can also be detected.