The Experts below are selected from a list of 27660 Experts worldwide ranked by ideXlab platform
Cormac J. Sreenan - One of the best experts on this subject based on the ideXlab platform.
-
SENSAPPEAL - Software Update Recovery for Wireless Sensor Networks
Lecture Notes of the Institute for Computer Sciences Social Informatics and Telecommunications Engineering, 2010Co-Authors: Stephen Brown, Cormac J. SreenanAbstract:Updating Software over the network is important for Wireless Sensor Networks in support of scale, remote deployment, feature upgrades, and fixes. The risk of a fault in the Updated code causing system failure is a serious problem. In this paper, we identify a single, critical, symptom loss-of-control, that complements exception-based schemes, and supports failsafe recovery from faults in Software Updates. We present a new Software Update recovery mechanism that uses loss-of-control to provide high-reliability, low energy, Software Updates, including a comparison of optimised-flooding against spanning-tree for determining loss-of-control in a multi-path environment. The solution presented supports a trial phase (with lower latency), and an operational phase (with lower energy). The energy/latency tradeoff of this is shown, and the high-reliability of this Update recovery is demonstrated by analysis and simulation. The results presented control the risk in existing WSN Software Update mechanisms.
-
Software Update Recoveryfor Wireless Sensor Networks
2009Co-Authors: Stephen Brown, Cormac J. SreenanAbstract:Updating Software over the network is important for Wireless Sensor Networks in support of scale, remote deployment, feature upgrades, and fixes. The risk of a fault in the Updated code causing system failure is a serious problem. In this paper, we identify a single, critical, symptom loss-of-control, that complements exception-based schemes, and supports failsafe recovery from faults in Software Updates. We present a new Software Update recovery mechanism that uses loss-ofcontrol to provide high-reliability, low energy, Software Updates, including a comparison of optimised-flooding against spanning-tree for determining loss-of-control in a multi-path environment. The solution presented supports a trial phase (with lower latency), and an operational phase (with lower energy). The energy/latency tradeoff of this is shown, and the high-reliability of this Update recovery is demonstrated by analysis and simulation. The results presented control the risk in existing WSN Software Update mechanisms.
-
a new model for updating Software in wireless sensor networks
IEEE Network, 2006Co-Authors: Stephen Brown, Cormac J. SreenanAbstract:Wireless sensor networks (WSNs) are expected to be deployed for long periods of time, and the nodes are likely to need Software Updates during their lifetime, both for bug fixes and in order to support new requirements. But in many cases the nodes will be inaccessible or too numerous to be physically accessed. This drives the need for "over-the-air" support for Software Updates, and a number of different systems and supporting protocols for performing these Updates have been developed. These systems have addressed the problem in a number of different ways, and meet different requirements. This article consolidates this work by determining an integrated set of necessary WSN Software Update criteria, and presenting a novel model for WSN Software Update systems
Stephen Brown - One of the best experts on this subject based on the ideXlab platform.
-
SENSAPPEAL - Software Update Recovery for Wireless Sensor Networks
Lecture Notes of the Institute for Computer Sciences Social Informatics and Telecommunications Engineering, 2010Co-Authors: Stephen Brown, Cormac J. SreenanAbstract:Updating Software over the network is important for Wireless Sensor Networks in support of scale, remote deployment, feature upgrades, and fixes. The risk of a fault in the Updated code causing system failure is a serious problem. In this paper, we identify a single, critical, symptom loss-of-control, that complements exception-based schemes, and supports failsafe recovery from faults in Software Updates. We present a new Software Update recovery mechanism that uses loss-of-control to provide high-reliability, low energy, Software Updates, including a comparison of optimised-flooding against spanning-tree for determining loss-of-control in a multi-path environment. The solution presented supports a trial phase (with lower latency), and an operational phase (with lower energy). The energy/latency tradeoff of this is shown, and the high-reliability of this Update recovery is demonstrated by analysis and simulation. The results presented control the risk in existing WSN Software Update mechanisms.
-
Software Update Recoveryfor Wireless Sensor Networks
2009Co-Authors: Stephen Brown, Cormac J. SreenanAbstract:Updating Software over the network is important for Wireless Sensor Networks in support of scale, remote deployment, feature upgrades, and fixes. The risk of a fault in the Updated code causing system failure is a serious problem. In this paper, we identify a single, critical, symptom loss-of-control, that complements exception-based schemes, and supports failsafe recovery from faults in Software Updates. We present a new Software Update recovery mechanism that uses loss-ofcontrol to provide high-reliability, low energy, Software Updates, including a comparison of optimised-flooding against spanning-tree for determining loss-of-control in a multi-path environment. The solution presented supports a trial phase (with lower latency), and an operational phase (with lower energy). The energy/latency tradeoff of this is shown, and the high-reliability of this Update recovery is demonstrated by analysis and simulation. The results presented control the risk in existing WSN Software Update mechanisms.
-
a new model for updating Software in wireless sensor networks
IEEE Network, 2006Co-Authors: Stephen Brown, Cormac J. SreenanAbstract:Wireless sensor networks (WSNs) are expected to be deployed for long periods of time, and the nodes are likely to need Software Updates during their lifetime, both for bug fixes and in order to support new requirements. But in many cases the nodes will be inaccessible or too numerous to be physically accessed. This drives the need for "over-the-air" support for Software Updates, and a number of different systems and supporting protocols for performing these Updates have been developed. These systems have addressed the problem in a number of different ways, and meet different requirements. This article consolidates this work by determining an integrated set of necessary WSN Software Update criteria, and presenting a novel model for WSN Software Update systems
Justin Cappos - One of the best experts on this subject based on the ideXlab platform.
-
chainiac proactive Software Update transparency via collectively signed skipchains and verified builds
USENIX Security Symposium, 2017Co-Authors: Kirill Nikitin, Justin Cappos, Eleftherios Kokoriskogias, Philipp Jovanovic, Nicolas Gailly, Linus Gasser, Ismail Khoffi, Bryan FordAbstract:Software-Update mechanisms are critical to the security of modern systems, but their typically centralized design presents a lucrative and frequently attacked target. In this work, we propose CHAINIAC, a decentralized Software-Update framework that eliminates single points of failure, enforces transparency, and provides efficient verifiability of integrity and authenticity for Software-release processes. Independent witness servers collectively verify conformance of Software Updates to release policies, build verifiers validate the source-to-binary correspondence, and a tamper-proof release log stores collectively signed Updates, thus ensuring that no release is accepted by clients before being widely disclosed and validated. The release log embodies a skipchain, a novel data structure, enabling arbitrarily out-of-date clients to efficiently validate Updates and signing keys. Evaluation of our CHAINIAC prototype on reproducible Debian packages shows that the automated Update process takes the average of 5 minutes per release for individual packages, and only 20 seconds for the aggregate timeline. We further evaluate the framework using real-world data from the PyPI package repository and show that it offers clients security comparable to verifying every single Update themselves while consuming only one-fifth of the bandwidth and having a minimal computational overhead.
-
survivable key compromise in Software Update systems
Computer and Communications Security, 2010Co-Authors: Justin Samuel, Nick Mathewson, Justin Cappos, Roger DingledineAbstract:Today's Software Update systems have little or no defense against key compromise. As a result, key compromises have put millions of Software Update clients at risk. Here we identify three classes of information whose authenticity and integrity are critical for secure Software Updates. Analyzing existing Software Update systems with our framework, we find their ability to communicate this information securely in the event of a key compromise to be weak or nonexistent. We also find that the security problems in current Software Update systems are compounded by inadequate trust revocation mechanisms. We identify core security principles that allow Software Update systems to survive key compromise. Using these ideas, we design and implement TUF, a Software Update framework that increases resilience to key compromise.
-
ACM Conference on Computer and Communications Security - Survivable key compromise in Software Update systems
Proceedings of the 17th ACM conference on Computer and communications security - CCS '10, 2010Co-Authors: Justin Samuel, Nick Mathewson, Justin Cappos, Roger DingledineAbstract:Today's Software Update systems have little or no defense against key compromise. As a result, key compromises have put millions of Software Update clients at risk. Here we identify three classes of information whose authenticity and integrity are critical for secure Software Updates. Analyzing existing Software Update systems with our framework, we find their ability to communicate this information securely in the event of a key compromise to be weak or nonexistent. We also find that the security problems in current Software Update systems are compounded by inadequate trust revocation mechanisms. We identify core security principles that allow Software Update systems to survive key compromise. Using these ideas, we design and implement TUF, a Software Update framework that increases resilience to key compromise.
Hewijin Christine Jiau - One of the best experts on this subject based on the ideXlab platform.
-
implementation of nonstop Software Update for client server applications
Computer Software and Applications Conference, 2003Co-Authors: Hewijin Christine JiauAbstract:Many Software systems are established using client-server models. If a program on the server needs to be Updated due to Software maintenance, the service provided by the program will be required to terminate. The clients cannot be served until the Update process is completed. The Update process obviously reduces commercial profit especially for e-commerce systems. Therefore, a nonstop Software Update scheme is needed for high system availability. This paper develops an NSU system to Update general server programs without stopping services. The NSU system can take over the task of old version using a redundant server for updating. The system supports applications with shared variables and maintains data consistency during Software Update. The current implementation is designed for Java programs running on the Linux operating system. Experimental results show that the NSU system incurred less than 1% overhead during normal execution.
-
COMPSAC - Implementation of nonstop Software Update for client-server applications
Proceedings 27th Annual International Computer Software and Applications Conference. COMPAC 2003, 2003Co-Authors: Hewijin Christine JiauAbstract:Many Software systems are established using client-server models. If a program on the server needs to be Updated due to Software maintenance, the service provided by the program will be required to terminate. The clients cannot be served until the Update process is completed. The Update process obviously reduces commercial profit especially for e-commerce systems. Therefore, a nonstop Software Update scheme is needed for high system availability. This paper develops an NSU system to Update general server programs without stopping services. The NSU system can take over the task of old version using a redundant server for updating. The system supports applications with shared variables and maintains data consistency during Software Update. The current implementation is designed for Java programs running on the Linux operating system. Experimental results show that the NSU system incurred less than 1% overhead during normal execution.
-
COMPSAC - Online non-stop Software Update using replicated execution blocks
Proceedings 24th Annual International Computer Software and Applications Conference. COMPSAC2000, 1Co-Authors: Kuo-feng Ssu, Hewijin Christine JiauAbstract:Software updating is an inevitable process in the lifetime of a computer system. Numerous Update mechanisms have been applied to Software products. However, only little attention has been devoted to online nonstop Software updating. Traditional Update utilities typically require programs to stop execution during modifications, and this decreases the availability of the systems. For e-commerce (electronic commerce) companies, improving system availability implies increasing opportunities for greater business profit. Therefore, minimizing the system maintenance time for necessary Software Updates becomes a critical issue. This paper describes an approach to nonstop Software updating. The approach composes a program using two replicated execution blocks. By switching between the execution blocks, the program can be modified without terminating its service. The paper also discusses the system environments that are required in order to support the approach.
Roger Dingledine - One of the best experts on this subject based on the ideXlab platform.
-
survivable key compromise in Software Update systems
Computer and Communications Security, 2010Co-Authors: Justin Samuel, Nick Mathewson, Justin Cappos, Roger DingledineAbstract:Today's Software Update systems have little or no defense against key compromise. As a result, key compromises have put millions of Software Update clients at risk. Here we identify three classes of information whose authenticity and integrity are critical for secure Software Updates. Analyzing existing Software Update systems with our framework, we find their ability to communicate this information securely in the event of a key compromise to be weak or nonexistent. We also find that the security problems in current Software Update systems are compounded by inadequate trust revocation mechanisms. We identify core security principles that allow Software Update systems to survive key compromise. Using these ideas, we design and implement TUF, a Software Update framework that increases resilience to key compromise.
-
ACM Conference on Computer and Communications Security - Survivable key compromise in Software Update systems
Proceedings of the 17th ACM conference on Computer and communications security - CCS '10, 2010Co-Authors: Justin Samuel, Nick Mathewson, Justin Cappos, Roger DingledineAbstract:Today's Software Update systems have little or no defense against key compromise. As a result, key compromises have put millions of Software Update clients at risk. Here we identify three classes of information whose authenticity and integrity are critical for secure Software Updates. Analyzing existing Software Update systems with our framework, we find their ability to communicate this information securely in the event of a key compromise to be weak or nonexistent. We also find that the security problems in current Software Update systems are compounded by inadequate trust revocation mechanisms. We identify core security principles that allow Software Update systems to survive key compromise. Using these ideas, we design and implement TUF, a Software Update framework that increases resilience to key compromise.